AZ-104 — Frequently Asked Questions

Community-vetted answers to 51 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

Organizing Azure Storage Content with Hierarchical Namespaces

Cont2 is listed under 'Planned Changes,' meaning it does not exist in the current environment. Exam answers rely on existing resources unless stated otherwise.

Yes, Azure Files shares (like share1 and share2) support a directory structure similar to traditional file systems, allowing for organized content.

Which Azure Resources Can You Associate a Public IP Address To?

A VPN gateway's public IP is assigned when the gateway is created and cannot be changed later, so an existing VPN gateway cannot accept a new standalone public IP.

Azure associates public IP addresses with the VM's network interface (NIC1), not with the virtual machine resource itself, so you must attach IP1 to NIC1.

How Do You Keep VM1-to-Storage1 Traffic Off the Internet?

That setting only filters which VNets and IP addresses may reach the storage account's public endpoint. Allowed traffic still leaves the VNet for the public endpoint, so it can traverse the internet.

No. A shared access signature is a time-limited authorization credential; it grants access but does not change the network path, so packets still use the storage account's public endpoint.

It assigns a private IP from your VNet to the storage service, and name resolution returns that private IP so VM1 talks to storage1 entirely over the virtual network and Microsoft backbone.

How to Route VM1-to-Storage1 Traffic Across the Microsoft Backbone?

An NSG only allows or denies traffic; it does not alter the path. A private endpoint is needed to give storage1 a private IP in the VNet and keep traffic on the Microsoft backbone.

No. Virtual WAN is for hub-and-spoke network transit and branch connectivity, not for privately accessing a PaaS storage account. A private endpoint is the correct service.

How to Bulk Import Entra Users into Dynamic Groups by Department?

Dynamic groups automatically add or remove members based on attributes like department, eliminating manual updates and minimizing administrative effort.

No, Microsoft Entra bulk import only supports CSV files. XML is not a supported format for creating multiple users.

How Do You Rotate Azure Storage Account Access Keys Automatically?

A Recovery Services vault stores backup items and recovery points for VMs, files and workloads. It has no key-management API, so it cannot regenerate storage account access keys on a schedule.

No. Lifecycle management policies only transition or delete blobs in the account based on age or last-access time; the account's key1 and key2 values are untouched.

How to Limit Entra Guest Invitations to fabrikam.com?

Tenant restrictions and Microsoft cloud settings in Cross-tenant access control resource access or B2B with other Microsoft clouds, not the domains that can receive guest invitations.

It lets you allow or deny B2B invitations by domain; selecting 'Allow invitations only to the specified domains' and adding fabrikam.com enforces the requirement.

Which roles grant blob access and support RBAC conditions?

Conditions can only be added to role assignments containing blob, queue or table data actions. Owner and Storage Account Contributor are management-plane roles without blob data actions, so no condition can be attached.

It only covers Azure Backup backup/restore and read operations on the storage account, not general container and blob access, and it does not support RBAC conditions.

How Do You Warn Users When a SAS Exceeds Seven Days?

Alert rules act on metrics, activity logs or log queries and notify action groups asynchronously; they cannot display an interactive warning to the person generating the SAS, which the SAS expiry policy does.

Enabled warns the user but still allows the longer SAS to be created; Required blocks creation of any SAS whose expiry exceeds the configured interval.

Does Storage Account Key Operator Service Role Allow Listing and Regenerating Keys?

No. It only grants listkeys and regeneratekey on the storage account; reading blob or file data requires a data-plane role such as Storage Blob Data Reader.

It can manage the account, but it is far broader than required; the key operator role follows least privilege for listing and regenerating keys only.

Which Azure Storage Account Can Be Converted to ZRS?

Geo-redundant replication is not a supported source for a ZRS conversion; the account must first be changed to LRS, so storage2 does not qualify directly in this question.

Premium block blob and premium file share accounts do support ZRS, but a premium page-blob account does not — check the account type shown in the table before assuming a premium account qualifies.

Reader and Data Access Role for Storage Key Regeneration?

It grants read access and lists keys but lacks Microsoft.Storage/storageAccounts/regeneratekey/action, so key rotation is not permitted.

Assign the Storage Account Key Operator Service Role, which includes both listkeys and regeneratekey actions.

Which ADatum Virtual Machines Can Azure Disk Encryption Encrypt?

Their disk and VM configurations are listed among the scenarios ADE does not support, such as unsupported disk types or Write Accelerator-enabled sizes, so ADE cannot be enabled on them.

No. Microsoft's ADE documentation lists Basic-tier VMs and VMs created with the classic deployment method as unsupported scenarios, one of the rules that narrows this case study to VM2 and VM3.

Which VMs Can Be Backed Up to Recovery Services Vault1?

Because a Recovery Services vault can protect only VMs in its own Azure region; VM2 and VMB are in a different region than Vault1.

No. Azure Backup region affinity depends on the VM's location, not its resource group, so being in a different resource group does not block protection.

How to Ensure NGINX Is Available on VMSS VMs from an ARM Template?

It only uploads a DSC configuration to Azure Storage and does not apply it to the VMSS instances. You need an extension that actually executes configuration on each VM.

Yes, the DSC extension is a valid alternative, but the question only offers the publish cmdlet, not the extension itself. The Custom Script Extension remains the best listed answer.

Which Azure Services Automatically Scale a Container?

ACI runs containers quickly but has no native autoscaling; scaling requires external orchestration or scripts, so it is not a valid recommendation here.

Yes. App Service autoscale rules apply to App Service plans, including plans hosting containerized web apps, making it a valid answer alongside Container Apps.

Does Assigning AcrPull to ACR-Tasks-Network Meet the Goal?

ACR-Tasks-Network is not the identity deploying the container instance; AcrPull must be granted to the principal that actually pulls image1 from Registry1.

The identity used by the container instance or deployment process, such as its managed identity or service principal, must have AcrPull on Registry1.

Does a Dedicated Data Endpoint Fix ACI Deployment from Registry1?

It only changes the registry's data-plane endpoint for restricted or private network scenarios. It supplies no credentials, so Azure Container Instances still fails to authenticate and pull image1 from Registry1.

Enable the Registry1 admin user and pass the username/password to the container instance, or assign a service principal or managed identity the AcrPull role so ACI can authenticate.

Does Moving VM1 to Another Subscription Move It to a New Host?

A subscription move only changes the resource's management boundary and ARM template scope; the VM keeps running on its current Azure host, so it does not trigger a redeployment.

Use the Redeploy option in the VM's Help section (or az vm redeploy), which stops, moves, and restarts the VM on a new Azure node.

How Do You Resize VM1 When the Target Azure VM Size Is Unavailable?

The current host cluster may not stock that SKU; deallocation releases VM1's hardware so Azure can place it on a cluster that offers the size.

No. Availability set configuration affects resiliency and management, not the host cluster's SKU inventory, so it cannot make the intended size appear.

Does Enabling ACR Admin User Meet Container Instance Deployment Goal?

The Azure portal automatically uses the registry's admin credentials to pull the image when you select an Azure Container Registry image for a container instance.

No, CLI deployments require explicit --registry-username and --registry-password; enabling the admin user alone does not pass credentials.

Configuring Network Access for Azure Storage Accounts

Private Endpoints require the client to be connected to a Virtual Network. Your home office typically lacks a direct VNet connection, making IP-based firewall rules via Public Network Access the simpler solution.

No. IAM (Access Control) manages permissions for who can perform actions on the data. Network settings control which devices/IPs can establish a connection to the storage account.

Azure Route Table Next Hop Types

Virtual network gateway is for S2S/VNet peering gateways. It doesn't accept arbitrary IP next hops for general route table entries.

An NVA is a third-party device like a firewall or load balancer deployed in Azure, which requires a Virtual appliance next hop type.

Azure Route Table Association Scope

Route tables define how traffic leaves a subnet. Since a NIC belongs to a specific subnet, it inherits the routes defined at the subnet level automatically.

Yes. NSGs can be applied to both subnets and individual NICs to filter traffic, whereas route tables are exclusively subnet-level objects for directing traffic paths.

Maximum VMs in Azure Subnet /25

Azure reserves the first 4 IPs and the last IP (gateway) in every subnet, leaving 123 usable IPs out of 128 total.

A /25 subnet uses 7 bits for hosts (32-25), resulting in 2^7 = 128 total addresses.

Ready to practice?

Access 100 AZ-104 questions with instant feedback and detailed explanations.

View AZ-104 Practice Questions →

← Back to AZ-104 Microsoft Azure Administrator study guide