Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

AZ-104 Practice Questions

Updated 8 min read
Key takeaway

These original AZ-104 practice questions teach administrator decisions across identity, storage, compute, networking, and monitoring.

  • They are not Microsoft secure exam questions, a full-length mock, or a score predictor.
  • Choose the best response before reading each explanation, then identify the clue that rules out the nearest alternative.
On this page6 sections
  1. How to use this set
  2. Review the decision pattern
  3. What each domain question asks you to notice
  4. How to learn from wrong answers
  5. How this set relates to the exam
  6. A final self-check

How to use this set

Answer each question before reading its rationale. Write down the scenario’s required outcome, the Azure control that addresses it, and the reason the closest alternative fails. These questions are original examples for learning and do not reproduce Microsoft’s secure items or claim to match the live exam’s item mix. Microsoft does not publish a fixed AZ-104 question count or list of exams that include labs. Use the set as a short diagnostic, then study the official outline and practice tasks that remain unfamiliar.

Question 1: least-privilege data access

A web application running on an Azure virtual machine must read blobs from one storage account. The team wants to avoid storing a long-lived password in application settings. Which approach best fits the requirement?

  1. Enable a managed identity for the workload and grant it the required blob data role at the narrowest suitable scope.
  2. Assign the VM identity Owner at the subscription scope.
  3. Create a user account and save its password in the application configuration.
  4. Apply a resource lock to the storage account.
Answer: A. A managed identity lets the workload authenticate without a stored long-lived secret, and a blob data role addresses the needed data-plane operation. Scope the permission narrowly. Owner is unnecessarily broad and is a management role, not a targeted data permission. A stored user password creates credential-management risk. A lock helps protect resources from deletion or modification; it does not grant read access.
Question 2: governance versus permissions

A company must prevent administrators from deploying virtual machines in a region that its policy prohibits. Which Azure capability most directly evaluates and enforces the allowed configuration?

  1. Azure Policy.
  2. An Azure RBAC role assignment.
  3. A resource tag.
  4. Azure Service Health.
Answer: A. Azure Policy can audit or deny resource configurations that do not meet organizational rules. RBAC determines who can perform management actions; it does not express the allowed location policy by itself. A tag adds metadata and does not enforce a region constraint. Service Health reports Azure issues and maintenance, not resource deployment compliance.
Question 3: storage resilience

A storage workload must remain available if a single availability zone in its primary region fails. The requirement does not include recovery from accidental deletion. Which decision principle should guide the administrator?

  1. Choose a supported zone-resilient redundancy option that meets the stated failure boundary, and configure separate recovery protection only if the deletion requirement calls for it.
  2. Use locally redundant storage because it automatically survives every zone failure.
  3. Choose the most expensive geo-redundant option because it always replaces backups.
  4. Apply a resource lock and treat the data as protected from all failures.
Answer: A. The scenario names a zone failure, so select an available redundancy option that spans the needed zone boundary. Exact options depend on service and region. Replication and backup address different risks; the question does not require deletion recovery. Locally redundant storage is not a universal zone-resilience guarantee. Geo-replication does not automatically replace backup, and a resource lock protects resource operations rather than every data-loss event.
Question 4: private connectivity and DNS

An application should reach a supported Azure service through a private endpoint. The endpoint exists, but the application still resolves the service name to a public address. Which area should the administrator investigate first?

  1. Private DNS resolution and the network path to the endpoint.
  2. The subscription’s billing profile.
  3. A resource lock on the application VM.
  4. Azure Advisor recommendations.
Answer: A. Private endpoint connectivity depends on network reachability and correct name resolution. If the application resolves a public address, check the private DNS zone, links, records, and client resolution path. Billing, a VM resource lock, and Advisor recommendations do not address the immediate name-resolution symptom.
Question 5: platform incident or workload signal

Users report that a managed Azure service is unavailable in a region. The administrator wants to know whether Microsoft has reported a platform issue or planned maintenance relevant to the subscription. Which tool is the most direct source?

  1. Azure Service Health.
  2. Azure Policy.
  3. A storage lifecycle rule.
  4. A VM extension.
Answer: A. Azure Service Health provides information about service issues and planned maintenance relevant to the customer. Azure Monitor can help inspect signals from a workload, but the question asks about Microsoft-reported platform status. Policy governs resource configuration. Lifecycle rules manage data over time. A VM extension configures guest or resource behavior.
Question 6: narrow human permission

A contractor must restart virtual machines only in the project resource group. The contractor must not manage networking or change subscription settings. What should the administrator consider first?

  1. Assign a suitable role that includes the required restart action at the resource-group scope, and verify the role’s permissions.
  2. Assign Owner at the subscription scope.
  3. Add the contractor as a billing account administrator.
  4. Apply a tag naming the contractor.
Answer: A. The requested actions and scope should determine the role assignment. Check whether the role includes the needed restart action and whether the resource-group scope is sufficiently narrow. Owner at subscription scope grants far more authority. Billing administration is unrelated to restarting VMs. A tag records metadata but does not authorize actions.

Review the decision pattern

Across the set, the important clue is the requested outcome. Data access points to the identity and data role; enforcing configuration points to Policy; zone resilience concerns storage redundancy; a private endpoint issue can involve DNS; Azure platform issues point to Service Health; and a scoped human action calls for an appropriate role at a narrow scope. Many options may be useful in a real environment, but the question asks which action directly addresses one requirement.

The distractors are plausible because they are real Azure features. A lock is valuable, but it does not grant data access. RBAC is central to administration, but it is not a policy engine for every configuration constraint. Monitor and Service Health both support operations, but they observe different types of conditions. Learn the boundary of each service, not just its name.

What each domain question asks you to notice

Identity and governance scenarios often ask who can do what and where. Write the principal, role, and scope. If the workload needs a data operation, check for a data-plane permission rather than assuming a management role is enough. If the goal is to restrict configuration, consider Policy. If the concern is accidental resource deletion, consider a lock. These are adjacent controls with different jobs.

Storage scenarios usually include an access, availability, performance, or recovery condition. State the failure boundary and recovery objective before choosing. A requirement to survive a local or zone failure is not the same as restoring deleted data. A redundancy choice may not meet retention needs, and a backup policy may not provide immediate availability.

Compute questions connect a workload to its image, size, storage, identity, network, availability, maintenance, and monitoring. Do not focus only on whether a VM can be created. Ask if the design meets the stated access and resilience requirements. A deployment may succeed while leaving the workload unreachable or overexposed.

Networking questions are easier when you trace source to destination. Check address ranges, name resolution, routes, filtering, and endpoint behavior. If a name resolves incorrectly, changing an NSG may not solve it. If traffic is blocked, confirm the effective rule and direction. If access control fails, distinguish network reachability from authorization.

Operations questions ask how to observe, respond, maintain, or recover. Identify the signal source and the response. An alert may notify a team; a backup supports recovery; Service Health reports platform events; and Monitor helps inspect telemetry. Verify the recovery procedure rather than assuming a configured policy will meet every objective.

How to learn from wrong answers

If you missed a question, do not simply memorize the letter. Record the clue you missed and the boundary between the correct answer and the strongest distractor. For Question 4, the clue was that the service name still resolved publicly, so DNS was part of the issue. For Question 6, the decisive constraints were only restart VMs and only one resource group. Those phrases narrow the scope and authority.

Create a variation after each miss. Change the workload identity to a human user, change the resource-group boundary to one storage account, or change a zone-failure requirement to accidental deletion. Then ask whether the answer changes. This tests whether you understand the decision rather than recognize the original wording.

If you guessed correctly, mark the item for review. A lucky answer can hide a gap. Explain why each incorrect choice fails, then consult Microsoft’s current documentation when service behavior is unclear. Use the public study guide to confirm that the task belongs to the current exam scope.

How this set relates to the exam

These six items are not a full practice exam and do not reproduce Microsoft’s secure questions. Microsoft’s typical exam range is 40 to 60 questions, but the exact AZ-104 count varies. The role-based exam may include case studies and labs, and Microsoft does not publish the exam-specific mix in advance. This set teaches selected concepts with written scenarios; it does not simulate live Azure configuration.

Microsoft’s Practice Assessment is a separate official resource, but it does not model the full length or complexity of the secure exam. Do not use the score from this short set or another provider as a prediction of Microsoft’s scaled result. Passing requires 700 on the 1,000-point scale, and a raw conversion is not published.

A final self-check

Before moving on, explain each answer in your own words. Name the requested outcome, the control that directly addresses it, and the risk or mismatch in the alternatives. Then make at least one new scenario for each domain. If you can change a requirement and adjust your answer for a clear reason, you are practicing the flexible judgment the AZ-104 outline expects.

Common questions

Are these official AZ-104 questions?

No. They are original learning examples and do not reproduce Microsoft’s secure exam.

Do these questions predict a pass?

No. Six items are not a full exam and do not use Microsoft’s scaled scoring method.

How many AZ-104 questions are on the live exam?

Microsoft does not publish a fixed count for AZ-104; its typical range across exams is 40 to 60, with the exact number varying.

What should I do after missing an item?

Write down the requirement, the deciding distinction, and why the closest alternative fails; then practice a changed scenario.