πŸ”

AZ-140 β€” questions

Page 4 of 11 Β· 218 total questions.

Topic 3 Β· Question 107

You have an Azure Virtual Desktop deployment that contains five session hosts. You have users that work from offices in Seattle and Vancouver. The users connect to the session hosts over the internet. You need to ensure that the users can connect to the session hosts from only the Seattle and Vancouver offices. What should you use?

  • AConditional Access (correct answer)
  • BRDP Shortpath
  • Ca network security group (NSG)
  • DAzure Firewall
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Conditional Access

Explanation

Conditional Access enforces access policies based on user, device, location, and risk signals.

Topic 3 Β· Question 108

You have an Azure subscription that contains two users named User1 and User2 and the Microsoft Entra groups shown in the following table. You have an Azure Virtual Desktop host pool named Pool1 that contains two session hosts named Host1 and Host2. The session hosts use FSLogix user profiles. Host1 contains the local groups shown in the following table. Host2 contains the local groups shown in the following table. User1 connects to Pool and modifies his desktop. User1 reports that when he reconnects to Pool, the desktop modifications fail to appear. You need to ensure that User1 sees the modified desktop when he connects to Pool. The solution must minimize the impact on other user profiles. What should you do?

Exhibit 1 for question 108Exhibit 2 for question 108Exhibit 3 for question 108
  • AAdd User1 to both FSLogix Profile Include list groups.
  • BRemove Group2 from both FSLogix Profile Exclude list groups.
  • CRemove User1 from Group3. (correct answer)
  • DRemove Group3 from Group2.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Remove User1 from Group3.

Topic 3 Β· Question 112

Your on-premises network contains an Active Directory Domain Services (AD DS) domain named corp.contoso.com. The domain contains two users named User1 and User2. You have a Microsoft Entra tenant named contoso.com that contains a user named User3 and syncs with corp.contoso.com. The sync status of the users is shown in the following table. You have an Azure Virtual Desktop deployment that contains Microsoft Entra joined session hosts. You create an Azure Storage account that has the following configurations: β€’ Name: storage1 β€’ Kind: FileStorage β€’ File share: share1 β€’ Microsoft Entra Kerberos: Enabled You need to implement FSLogix profile containers on share1. For which users can you implement a profile container?

Exhibit 1 for question 112
  • AUser1 only
  • BUser2 only (correct answer)
  • CUser1 and User2 only
  • DUser2 and User3 only
  • EUser1, User2, and User3
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: User2 only.

Topic 3 Β· Question 113 Β· Select all that apply

You have an Azure subscription that contains an Azure Virtual Desktop deployment and a Microsoft Entra Domain Services domain. The deployment contains 10 session hosts that are joined to the domain. You plan to deploy FSLogix profile containers and store the containers in Azure. You need to configure storage for the containers. The solution must ensure that you can assign share permissions to Microsoft Entra accounts. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • AFrom the Data storage settings of the storage account, enable an identity source. (correct answer)
  • BAttach a new virtual disk to each session host.
  • CFrom the Configuration settings of the storage account, select Default to Microsoft Entra authorization in the Azure portal.
  • DCreate a premium file shares storage account. (correct answer)
  • ECreate a premium block blobs storage account.
Reveal answer & explanation
Correct answer: A, D

The correct answer is A, D. Option A: From the Data storage settings of the storage account, enable an identity source. Option D: Create a premium file shares storage account.

Explanation

An Azure Storage Account is the container that groups blob, file, queue, and table storage with unified access control.

Topic 3 Β· Question 114 Β· Select all that apply

Case study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question. Overview - Northwind Traders is a manufacturing company based in New York City. Existing Environment - Identity Environment - The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com. Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant. Virtual Machines - The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations: β€’ Generation: 1 β€’ Disk size: 2 TB β€’ Disk format: VHDX β€’ Disk type: Dynamically expanding Cloud Services - Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses. The company has an Azure subscription that contains the resources shown in the following table. Both subscriptions are linked to the Microsoft Entra tenant. Requirements - Planned Changes - Northwind Traders identifies the following planned changes: β€’ Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain. β€’ Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure. β€’ The Azure Virtual Desktop deployment will provide access to a custom app named App1. Performance Requirements - Northwind Traders identifies the following performance requirements: β€’ Each Azure Virtual Desktop session host must support 15 user sessions. β€’ Each new user session must be assigned to a single session host until the maximum session limit is reached for that host. Application Requirements - Northwind Traders identifies the following application requirements: β€’ Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop. β€’ App1 requires a desktop resolution of 1280 x 1024. β€’ Administrative effort must be minimized. Disaster Recovery Requirements - Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment: β€’ Minimize outages if an Azure region fails. β€’ Minimize the recovery time objective (RTO). β€’ Minimize administrative effort in the event of a failover. Security Requirements - Northwind Traders identifies the following security requirements: β€’ When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only. β€’ When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app. β€’ All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint. β€’ The client version and operating system used to connect to the session hosts must be logged. β€’ The solution must follow the principle of least privilege. Networking Requirements - The Azure Virtual Desktop session hosts must be able to access the resources on the on-premises network. User Profile Requirements - Northwind Traders identifies the following user profile requirements: β€’ Users must be able to access share1 by using their Microsoft Entra account. β€’ Azure Virtual Desktop user profiles must be managed by using FSLogix. β€’ All user profiles must be stored in share1. Which two actions should you perform to meet the security requirements for Defender for Endpoint? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Exhibit 1 for question 114
  • AAdd a Defender for Endpoint onboarding script to VM1 and run the script at first startup. (correct answer)
  • BUse a Group Policy Object (GPO) to run an on boarding script from a shared location. (correct answer)
  • CCreate an app attach image for the Azure Virtual Desktop deployment.
  • DRun a Defender for Endpoint onboarding script on VM1 before generalizing the VM1 source image.
Reveal answer & explanation
Correct answer: A, B

The correct answer is A, B. Option A: Add a Defender for Endpoint onboarding script to VM1 and run the script at first startup. Option B: Use a Group Policy Object (GPO) to run an on boarding script from a shared location. By spanning multiple Availability Zones / adding redundancy, this option provides the high availability and resilience required.

Topic 3 Β· Question 119

You have an Azure subscription that contains an Azure Virtual Desktop session host named VM1. You plan to deploy an app named App1 that will process Personally Identifiable Information (PII) data. You need to ensure that App1 is deployed to a confidential virtual machine. The solution must minimize administrative effort. What should you do?

  • AOn VM1, enable Azure Disk Encryption for the operating system disk. Install App1 on the operating system disk.
  • BDeploy a new virtual machine and install App1. (correct answer)
  • COn VM1, enable File Integrity Monitoring (FIM) and install App1.
  • DOn VM1, attach a new data disk and enable BitLocker Drive Encryption (BitLocker). Install App1 on the new disk.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Deploy a new virtual machine and install App1.

Explanation

An Azure Virtual Machine provides full control of the OS when you need to run custom or legacy workloads.

Topic 4 Β· Question 120

You have an Azure Virtual Desktop deployment. You publish a RemoteApp named AppVersion1. You need AppVersion1 to appear in the Remote Desktop client as Sales Contact Application. Which PowerShell cmdlet should you use?

  • ANew-AzADApplication
  • BUpdate-AzWvdApplicationGroup
  • CRegister-AzWvdApplicationGroup
  • DUpdate-AzWvdApplication (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Update-AzWvdApplication.

Topic 4 Β· Question 121

You have an Azure Virtual Desktop deployment that contains the following: β€’ A host pool named Pool1 β€’ Two session hosts named Host1 and Host2 β€’ An application group named RemoteAppGroup1 that contains a RemoteApp named App1 You need to prevent users from copying and pasting between App1 and their local device. What should you do?

  • ACreate an AppLocker policy.
  • BModify the locks of RemoteAppGroup1.
  • CAssign the Desktop Virtualization Reader role for Pool1 to the users.
  • DModify the RDP Properties of Pool1. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Modify the RDP Properties of Pool1.

Topic 4 Β· Question 123

You have an Azure Virtual Desktop host pool that contains two session hosts. The Microsoft Teams client is installed on each session host. You discover that only the Microsoft Teams chat and collaboration features work. The calling and meeting features are disabled. You need to ensure that users can set the calling and meeting features from within Microsoft Teams. What should you do?

  • AInstall the Remote Desktop WebRTC Redirector Service.
  • BConfigure Remote audio mode in the RDP Properties. (correct answer)
  • CInstall the Teams Meeting add-in for Outlook.
  • DConfigure audio input redirection.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Configure Remote audio mode in the RDP Properties.

Topic 4 Β· Question 124

You have an Azure Virtual Desktop host pool that contains 20 Windows 10 Enterprise multi-session hosts. Users connect to the Azure Virtual Desktop deployment from computers that run Windows 10. You plan to implement FSLogix Application Masking. You need to deploy Application Masking rule sets. The solution must minimize administrative effort. To where should you copy the rule sets?

  • Athe FSLogix profile container of each user
  • BC:\Program Files\FSLogix\Apps\Rules on every Windows 10 computer
  • CC:\Program Files\FSLogix\Apps\Rules on every session host (correct answer)
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: C:\Program Files\FSLogix\Apps\Rules on every session host.

Topic 4 Β· Question 125

You have an Azure Virtual Desktop host pool named Pool1. You are troubleshooting an issue for a Remote Desktop client that stopped responding. You need to restore the default Remote Desktop client settings and unsubscribe from all workspaces. Which command should you run?

  • Amsrdcw (correct answer)
  • Bresetengine
  • Cmstsc
  • Dresetpluginhost
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: msrdcw.

Topic 4 Β· Question 126

Your network contains an on-premises Active Directory domain and an Azure Virtual Desktop deployment. The computer accounts for all the session hosts are in an organizational unit (OU) named WVDHostsOU. All user accounts are in an OU named CorpUsers. A domain administrator creates a Group Policy Object (GPO) named Policy1 that only contains user settings. The administrator links Policy1 to WVDHostsOU. You discover that when users sign in to the session hosts, none of the settings from Policy1 are applied. What should you configure to apply GPO settings to the users when they sign in to the session hosts?

  • Aloopback processing (correct answer)
  • BFSLogix profiles
  • Cmandatory Roaming User Profiles
  • Drestricted groups
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: loopback processing.

Topic 4 Β· Question 127

You have an Azure Virtual Desktop deployment. You need to provide external users with access to the deployment. The external users have computers that run Windows 10 Pro and Windows 10 Enterprise. The users do not have the ability to install applications. What should you recommend that the users use to connect to the deployment?

  • AMicrosoft Edge (correct answer)
  • BRemoteApp and Desktop Connection
  • CRemote Desktop Manager
  • DRemote Desktop Connection
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Microsoft Edge.

Topic 4 Β· Question 128

You network contains an on-premises Active Directory domain. The domain contains a universal security group named AVDusers. You have a hybrid Azure Active Directory (Azure AD) tenant. AVDusers syncs to Azure AD. You have an Azure Virtual Desktop host pool that contains four Windows 10 Enterprise multi-session hosts. You need to ensure that only the members of AVDusers can establish Azure Virtual Desktop sessions to the host pool. What should you do?

  • AAssign AVDusers to an Azure role scoped to each host pool.
  • BOn each session host, add AVDusers to the local Remote Desktop Users group.
  • CAssign AVDusers to an Azure role scoped to the session hosts.
  • DAssign AVDusers to an application group. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Assign AVDusers to an application group.

Topic 4 Β· Question 129

You deploy multiple Azure Virtual Desktop session hosts that have only private IP addresses. You need to ensure that administrators can initiate an RDP session to the session hosts by using the Azure portal. What should you implement?

  • ARemote Desktop Connection Broker (RD Connection Broker)
  • BAzure Application Gateway
  • CAzure Bastion (correct answer)
  • DRemote Desktop Session Host (RD Session Host)
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Azure Bastion

Explanation

Azure Bastion provides secure RDP/SSH access to VMs through the portal without exposing public IPs.

Topic 4 Β· Question 130 Β· Select all that apply

You have an Azure Virtual Desktop host pool named Pool1. Pool1 contains session hosts that have a third-party application named App1. App1 is published by using a RemoteApp group. A new MSI-based version of App1 is installed each month to each host. The name of the executable file is different for each version of App1. You need to automate the process of making a new version of App1 available via RemoteApp. The process must ensure that the user experience remains the same when launching the application from the Windows Desktop client. Which two cmdlets should you run? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • ARemove-AzWvdApplication (correct answer)
  • BNew-AzWvdApplication (correct answer)
  • CNew-AzWvdApplicationGroup
  • DNew-AzWvdMsixPackage
  • ENew-AzRoleAssignment
  • FRemove-AzWvdMsixPackage
Reveal answer & explanation
Correct answer: A, B

The correct answer is A, B. Option A: Remove-AzWvdApplication Option B: New-AzWvdApplication.

Topic 4 Β· Question 131

You have an Azure Virtual Desktop deployment. You need to recommend a solution to run containerized applications without installing the applications on the session hosts. What should you include in the recommendation?

  • AEXE applications
  • BMSI packages
  • CAPPX app packages
  • DMSIX app packages (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: MSIX app packages.

Topic 4 Β· Question 133

You have an Azure Virtual Desktop host pool named Pool1 that contains three session hosts. The session hosts are configured to use FSLogix profiles. On a management computer, you create an Application Masking rule and assignment files. You need to apply Application Masking to the session hosts in Pool1. What should you do?

  • AGenerate a registration token.
  • BInstall the FSLogix agent on the session hosts in Pool1.
  • CCompile the rule and assignment files.
  • DCopy the files to the session hosts in Pool1. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Copy the files to the session hosts in Pool1.

Topic 4 Β· Question 134

You have an Azure Virtual Desktop deployment. The session hosts are joined to an on-premises Active Directory domain named contoso.com. You need to limit user sessions to three hours. What should you configure?

  • Aa Group Policy Object (GPO) in contoso.com. (correct answer)
  • Bthe properties of the workspace
  • Cthe RDP Properties of a host pool
  • Djust-in-time (JIT) VM access
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: a Group Policy Object (GPO) in contoso.com.

Topic 4 Β· Question 137

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have the following: β€’ A Microsoft 365 E5 tenant β€’ An on-premises Active Directory domain β€’ A hybrid Azure Active Directory (Azure AD) tenant β€’ An Azure Active Directory Domain Services (Azure AD DS) managed domain β€’ An Azure Virtual Desktop deployment The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune. You need to configure the security settings for the Microsoft Edge browsers on the personal desktops. Solution: You create and configure a Group Policy Object (GPO) in the on-premises domain. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Showing questions 61–80 of 218 Β· Page 4 of 11