AZ-104 Practice Test 1 – 50 Questions and Answers (Azure Administrator, Updated August 2026)

AZ-104 Practice Test 1: 50 Updated Questions and Answers for Azure Administrator

·

Practice AZ-104 questions aligned with the Microsoft Azure Administrator skills measured as of April 17, 2026. This updated test covers Azure identities and governance, storage, compute, virtual networking, monitoring, backup, and recovery. Select your answers, review the explanations, and track your progress in the Learning Dashboard.

Exam: AZ-104Questions: 50Recommended score: 70%+Time: 90 minutes

Before you start

This practice test includes single-choice, multiple-response, and true/false questions. When a question requires more than one answer, the question text tells you exactly how many answers to choose.

AZ-104 practice test questions

Question 1: A guest user redeemed a B2B invitation with the wrong identity provider. You must let the user redeem again with a different identity while preserving the existing object ID, group memberships, and app assignments. What should you do?

The correct answer is Reset the guest user's redemption status and send a new invitation.

Resetting redemption lets the guest redeem with a different email or identity provider while retaining the same directory object, group memberships, and app assignments. Deleting and recreating the account would require rebuilding those relationships.

Related Microsoft Learn topic

Reset guest redemption status

Question 2: Every member of the Finance group must receive the same Microsoft product license, including users added later. Which approach requires the least ongoing administration?

The correct answer is Assign the license to the Finance group.

Group-based licensing automatically applies assigned licenses to group members and removes repetitive per-user administration. New members receive the license through their group membership.

Related Microsoft Learn topic

Learn about Microsoft Entra groups

Question 3: You want to pilot self-service password reset with one Microsoft Entra group before enabling it tenant-wide. Which SSPR setting should you configure?

The correct answer is Selected, and choose the pilot group.

The Selected option enables SSPR for a chosen group, allowing a controlled pilot. After validation, the setting can be changed to All for a tenant-wide rollout.

Related Microsoft Learn topic

Enable Microsoft Entra self-service password reset

Question 4: Your organization must block new Azure resources from being deployed outside approved regions. Which Azure Policy effect should you use?

The correct answer is Deny.

The Deny effect prevents a resource request that violates the policy rule from succeeding. Audit records non-compliance but does not block deployment.

Related Microsoft Learn topic

Azure Policy definition effects

Question 5: You need to package several related Azure Policy definitions and assign them as one compliance objective. What should you create?

The correct answer is An initiative definition.

An Azure Policy initiative groups multiple policy definitions into a single overarching objective. The initiative can then be assigned and evaluated as one unit.

Related Microsoft Learn topic

Create and manage Azure Policy definitions and initiatives

Question 6: A Modify policy assignment marks existing resources as non-compliant. You need the policy to correct those existing resources. What should you create?

The correct answer is A remediation task.

A remediation task applies Modify operations or a DeployIfNotExists deployment to existing non-compliant resources. The policy assignment uses a managed identity to perform the required changes.

Related Microsoft Learn topic

Remediate non-compliant Azure resources

Question 7: You want a notification before current spending trends are expected to exceed an Azure budget. Which type of threshold should you configure?

The correct answer is A forecasted cost threshold.

Forecasted budget alerts use predicted spending to warn that a budget is likely to be exceeded. Actual cost alerts trigger only after accrued cost reaches the configured threshold.

Related Microsoft Learn topic

Create and manage Azure budgets

Question 8: Which actions are supported for managing Microsoft Entra external users? Choose 2 answers.

The correct answers are Bulk invite B2B collaboration users by using a CSV file and Resend an invitation that has not yet been redeemed.

Microsoft Entra supports bulk B2B invitations and allows administrators to resend invitations that remain unredeemed. The resource tenant does not manage passwords for identities homed in an external provider.

Related Microsoft Learn topic

Add Microsoft Entra B2B collaboration users

Question 9: Which statements about Azure tags are correct? Choose 2 answers.

The correct answers are Azure Policy can be used to apply inherited tag values and Sensitive information should not be stored in tags.

Resources do not automatically inherit subscription or resource-group tags, but Azure Policy can apply or enforce tag values. Tags are stored as plain text and must not contain secrets or sensitive data.

Related Microsoft Learn topic

Use tags to organize Azure resources

Question 10: Which cost-saving opportunities can Azure Advisor identify? Choose 2 answers.

The correct answers are Underutilized virtual machines that can be resized or shut down and Unattached managed disks that might no longer be required.

Azure Advisor analyzes resource utilization and can recommend rightsizing or shutting down underutilized VMs. It also identifies unattached disks that continue to generate cost.

Related Microsoft Learn topic

Azure Advisor cost recommendations

Question 11: If an Azure RBAC role is assigned to a Microsoft Entra group, members of that group receive the permissions from the role assignment.

The correct answer is True.

Azure roles can be assigned to Microsoft Entra groups. Group members receive the assigned permissions, which simplifies access management compared with individual role assignments.

Related Microsoft Learn topic

Azure role-based access control overview

Question 12: A ReadOnly management lock on a storage account prevents authorized users from modifying or deleting blob data through data-plane operations.

The correct answer is False.

Azure management locks apply to control-plane operations through Azure Resource Manager. They do not protect blob, queue, table, or file data from authorized data-plane operations.

Related Microsoft Learn topic

Lock Azure resources

Question 13: A storage account must accept traffic through its public endpoint only from Subnet1. Which configuration should you use?

The correct answer is Enable the Microsoft.Storage service endpoint on Subnet1 and add a storage firewall virtual network rule.

A virtual network rule authorizes the selected subnet at the storage firewall, and the service endpoint provides the subnet identity to Azure Storage. The portal can enable the endpoint automatically when the subnet is selected.

Related Microsoft Learn topic

Azure Storage firewall and virtual network rules

Question 14: An Azure application uses a managed identity and must read, create, and update blobs without using account keys. Which role should you assign to the identity?

The correct answer is Storage Blob Data Contributor.

Storage Blob Data Contributor grants read and write access to blob data through Microsoft Entra authorization. Management-plane roles such as Storage Account Contributor do not by themselves grant blob data access.

Related Microsoft Learn topic

Authorize access to Azure Storage data

Question 15: You need one standard storage account that supports blobs, files, queues, and tables. Which account type should you create?

The correct answer is General-purpose v2 (StorageV2).

A standard general-purpose v2 account supports Blob Storage, Azure Files, Queue Storage, and Table Storage. The premium account types are optimized for specific services.

Related Microsoft Learn topic

Overview of Azure storage accounts

Question 16: Your security team must control the lifecycle and rotation of the key that protects data in a storage account. What should you configure?

The correct answer is A customer-managed key stored in Azure Key Vault or Managed HSM.

Customer-managed keys let the organization control key access, rotation, and revocation. Azure Storage supports storing these keys in Azure Key Vault or Azure Key Vault Managed HSM.

Related Microsoft Learn topic

Customer-managed keys for Azure Storage encryption

Question 17: A user accidentally overwrites one file in an Azure file share. You need to restore only that file to an earlier point in time. What should you use?

The correct answer is An Azure Files share snapshot.

A file share snapshot is a read-only point-in-time copy of an Azure file share. It supports restoring an individual file without replacing the entire share.

Related Microsoft Learn topic

Use Azure Files share snapshots

Question 18: Which identity sources can provide identity-based authentication for Azure Files over SMB? Choose 2 answers.

The correct answers are On-premises Active Directory Domain Services and Microsoft Entra Kerberos.

Azure Files supports AD DS, Microsoft Entra Domain Services, or Microsoft Entra Kerberos as the identity source for SMB authentication. Only one identity source can be configured per storage account.

Related Microsoft Learn topic

Azure Files identity-based authentication

Question 19: Which methods can securely authorize AzCopy data transfers without embedding a storage account key in a script? Choose 2 answers.

The correct answers are Sign in with a Microsoft Entra identity that has the required data role and Use a SAS token limited to the required resource, permissions, and time.

AzCopy supports Microsoft Entra authentication and SAS-based authorization. Both approaches avoid placing a full-access storage account key in automation.

Related Microsoft Learn topic

Authorize AzCopy with a user identity

Question 20: Azure Files share soft delete can restore an individual deleted file without restoring the file share.

The correct answer is False.

Azure Files soft delete protects a deleted file share as a whole. To restore individual files, use share snapshots or Azure Backup item-level restore.

Related Microsoft Learn topic

Soft delete for Azure file shares

Question 21: When blob versioning is enabled, overwriting an existing block blob preserves the previous state as an earlier version.

The correct answer is True.

With blob versioning enabled, a write creates a new current version and changes the former current state into a previous version. That version can be used to recover from an accidental overwrite.

Related Microsoft Learn topic

Blob versioning

Question 22: A Bicep file must create a new Azure resource group. Which target scope and Azure CLI deployment command should you use?

The correct answer is targetScope = 'subscription' and az deployment sub create.

Resource groups are subscription-level resources, so the Bicep file targets the subscription scope. The corresponding Azure CLI command is az deployment sub create.

Related Microsoft Learn topic

Create resource groups with Bicep

Question 23: A new VM size is not available on the hardware cluster currently hosting a running virtual machine. What should you do before resizing the VM?

The correct answer is Stop and deallocate the virtual machine.

Deallocation allows Azure to place the VM on a different hardware cluster that supports the requested size. Resizing is disruptive and can also affect temporary disk data and dynamic public IP addresses.

Related Microsoft Learn topic

Change the size of a virtual machine

Question 24: You need to move an Azure virtual machine and its dependent resources to another Azure region with dependency validation and an orchestrated move process. Which service should you use?

The correct answer is Azure Resource Mover.

Azure Resource Mover coordinates cross-region moves for supported resources and validates dependencies before the move. It provides a managed prepare, initiate, commit, and cleanup workflow.

Related Microsoft Learn topic

Azure Resource Mover overview

Question 25: An Azure Container Instances container group runs a batch task. The container should restart after a failed execution but remain terminated after a successful execution. Which restart policy should you configure?

The correct answer is OnFailure.

The OnFailure policy restarts the container when its process fails but leaves the container group terminated after a successful completion. This behavior is suitable for retryable batch processing.

Related Microsoft Learn topic

Azure Container Instances restart policies

Question 26: You are configuring a custom backup for an Azure App Service app. Which destination and authorization method are required?

The correct answer is An Azure Storage account that supports SAS-based authorization.

App Service custom backup stores backup data in Azure Storage and currently uses SAS-based authorization. Managed identity authentication is not supported for this backup and restore path.

Related Microsoft Learn topic

Back up and restore an Azure App Service app

Question 27: A production Virtual Machine Scale Set must apply model updates in batches while maintaining a configured number of healthy instances. Which upgrade policy mode should you use?

The correct answer is Rolling.

Rolling upgrade mode updates scale-set instances in batches and supports health-based controls. It is designed for production workloads that must retain availability during updates.

Related Microsoft Learn topic

Virtual Machine Scale Sets upgrade policy modes

Question 28: An App Service connection string must remain with the staging slot and must not move during a slot swap. What should you configure?

The correct answer is Deployment slot setting.

Marking an app setting or connection string as a deployment slot setting makes it sticky to that slot. Sticky settings do not move when the slot content is swapped.

Related Microsoft Learn topic

Set up staging environments in Azure App Service

Question 29: Which statements about Azure availability sets are correct? Choose 2 answers.

The correct answers are They distribute VMs across fault domains and update domains and Two or more VMs should be deployed in the set for workload redundancy.

Availability sets reduce correlated hardware and planned-maintenance failures by spreading VMs across fault and update domains. Their domain settings cannot be changed after creation.

Related Microsoft Learn topic

Azure availability sets overview

Question 30: Which commands can deploy a Bicep file at resource-group scope? Choose 2 answers.

The correct answers are az deployment group create and New-AzResourceGroupDeployment.

Azure CLI uses az deployment group create for resource-group deployments. Azure PowerShell uses New-AzResourceGroupDeployment for the same scope.

Related Microsoft Learn topic

Deploy Bicep files with Azure CLI

Question 31: Unless disk deletion options are explicitly configured, what can happen to managed disks after their Azure VM is deleted? Choose 2 answers.

The correct answers are The disks can remain as unattached resources and continue generating charges and A retained compatible disk can be attached to another VM.

Managed disks can outlive the VM and remain billable until explicitly deleted. Retaining the disk protects data and allows it to be attached or used to create another compatible VM.

Related Microsoft Learn topic

Delete a VM and attached resources

Question 32: In Azure App Service, scaling out increases the number of instances, while scaling up changes the compute resources available to each instance.

The correct answer is True.

Scale out adds instances to distribute workload horizontally. Scale up changes the App Service plan tier or size to provide more CPU, memory, or features per instance.

Related Microsoft Learn topic

Scale up an Azure App Service app

Question 33: Azure Container Instances provides customers with a full Kubernetes control plane and requires them to manage Kubernetes worker nodes.

The correct answer is False.

Azure Container Instances runs containers without requiring customers to provision or manage virtual machines or Kubernetes nodes. AKS is the Azure service for a managed Kubernetes control plane.

Related Microsoft Learn topic

Azure Container Instances overview

Question 34: You need to determine whether an NSG permits or denies a specific TCP flow to a virtual machine and identify the matching rule. Which Network Watcher tool should you use?

The correct answer is IP flow verify.

IP flow verify tests a five-tuple flow against the effective NSG rules for a VM network interface. It reports whether access is allowed or denied and identifies the rule responsible.

Related Microsoft Learn topic

Azure Network Watcher IP flow verify

Question 35: A subnet route table contains routes for 10.1.0.0/16 and 10.1.2.0/24. Traffic is sent to 10.1.2.10. Which route does Azure select first?

The correct answer is The 10.1.2.0/24 route because it has the longest matching prefix.

Azure routing selects the most specific matching address prefix before considering route-source preference. A /24 route is more specific than a /16 route for 10.1.2.10.

Related Microsoft Learn topic

Azure virtual network traffic routing

Question 36: All VMs in a subnet need scalable outbound internet connectivity through a predictable public IP address, without accepting unsolicited inbound connections. What should you associate with the subnet?

The correct answer is Azure NAT Gateway.

NAT Gateway provides managed outbound connectivity for resources in associated subnets by using configured public IP addresses or prefixes. It does not provide unsolicited inbound connectivity.

Related Microsoft Learn topic

Azure NAT Gateway overview

Question 37: A hub virtual network has a VPN gateway. A peered spoke must use that gateway for on-premises connectivity. Which peering configuration is required?

The correct answer is Enable gateway transit on the hub peering and use remote gateways on the spoke peering.

The hub advertises its VPN or ExpressRoute gateway by allowing gateway transit. The spoke consumes the shared gateway by enabling Use remote gateways on its peering.

Related Microsoft Learn topic

Azure virtual network peering

Question 38: A line-of-business application must be load balanced across VMs and reachable only from the virtual network and connected on-premises networks. Which frontend should you configure?

The correct answer is An internal Azure Load Balancer with a private frontend IP.

An internal load balancer uses a private frontend IP from the virtual network and does not expose the application directly to the internet. It can serve clients in Azure and connected on-premises networks.

Related Microsoft Learn topic

Azure Load Balancer components

Question 39: You created a public Azure DNS zone for contoso.com. What must you do at the domain registrar to delegate the domain to Azure DNS?

The correct answer is Replace the domain's name-server records with the Azure DNS name servers assigned to the zone.

Delegation occurs in the parent DNS zone through NS records. The registrar must reference all Azure DNS name servers assigned to the Azure DNS zone.

Related Microsoft Learn topic

Delegate a domain to Azure DNS

Question 40: Which statements describe Standard SKU public IP addresses? Choose 2 answers.

The correct answers are They use static allocation and They are secure by default and require an NSG rule to allow inbound traffic to a VM.

Standard public IP addresses use static allocation. When used with a VM, inbound traffic is closed by default and must be explicitly permitted with an NSG.

Related Microsoft Learn topic

Public IP addresses in Azure

Question 41: Which NSG constructs help avoid maintaining long lists of individual IP addresses? Choose 2 answers.

The correct answers are Service tags for Azure service address ranges and Application security groups for groups of VM network interfaces.

Service tags represent Microsoft-managed IP ranges for Azure services. Application security groups let NSG rules target sets of VM network interfaces by application role instead of IP address.

Related Microsoft Learn topic

Azure network security groups overview

Question 42: If NSGs are associated with both a VM's subnet and its network interface, inbound traffic must be allowed by both NSGs to reach the VM.

The correct answer is True.

For inbound traffic, Azure evaluates the subnet NSG and then the network-interface NSG. A deny at either layer blocks the flow.

Related Microsoft Learn topic

How Azure network security groups filter traffic

Question 43: Enabling autoregistration on an Azure Private DNS virtual network link automatically creates DNS records for private endpoints in that virtual network.

The correct answer is False.

Private DNS autoregistration manages records for virtual machines in the linked virtual network. Private endpoints normally use a private DNS zone group or explicitly managed DNS records.

Related Microsoft Learn topic

Azure Private DNS autoregistration

Question 44: CPU usage follows different daily and weekly patterns, and a fixed alert threshold creates excessive noise. Which Azure Monitor alert threshold should you use?

The correct answer is A dynamic threshold.

Dynamic thresholds learn historical metric behavior and calculate adaptive boundaries for unusual deviations. They reduce the need to maintain a static threshold for changing seasonal patterns.

Related Microsoft Learn topic

Azure Monitor dynamic thresholds

Question 45: You need to filter, aggregate, and correlate log records collected from many Azure resources in one workspace. Which tool and query language should you use?

The correct answer is Log Analytics with Kusto Query Language (KQL).

Log Analytics is the Azure portal tool for querying Azure Monitor Logs. KQL supports filtering, summarizing, joining, and visualizing records across the selected workspace scope.

Related Microsoft Learn topic

Use Log Analytics

Question 46: You need to protect Azure VMs located in West Europe by using Azure Backup. Where should you create their Recovery Services vault?

The correct answer is In West Europe, the same region as the protected VMs.

A Recovery Services vault used for Azure VM backup must be in the same region as the protected data source. Deploy separate vaults for data sources in different regions.

Related Microsoft Learn topic

Create a Recovery Services vault

Question 47: During an Azure VM restore, you want Azure Backup to create managed disks from the recovery point so you can inspect and customize the VM configuration before deployment. Which restore option should you select?

The correct answer is Restore disks.

The Restore disks option creates disks from the selected recovery point and provides a template for VM creation. This gives you control over the final VM configuration before deployment.

Related Microsoft Learn topic

Restore Azure VMs by using Azure Backup

Question 48: During an Azure Site Recovery failover, you want the lowest recovery point objective by processing all data already sent to Site Recovery before creating the target VM. Which recovery point should you select?

The correct answer is Latest.

The Latest option processes all data already sent to Site Recovery before the target VM is created, providing the lowest RPO. Latest processed starts faster but uses the most recent recovery point that has already been processed.

Related Microsoft Learn topic

Fail over Azure VMs to a secondary region

Question 49: A single Azure Monitor metric alert rule can monitor multiple resources when the resources are of the same type and are in the same Azure region.

The correct answer is True.

Multi-resource metric alerts can monitor multiple resources of the same type in the same region. This reduces the number of alert rules needed for large environments.

Related Microsoft Learn topic

Monitor multiple metric time series with one alert rule

Question 50: Before backing up Azure VMs to a Recovery Services vault, you must create and attach a separate storage account to hold the backup data.

The correct answer is False.

Azure Backup and the Recovery Services vault manage the storage used for vault backup data. You select the vault storage redundancy, but you do not provide a separate storage account for Azure VM backups.

Related Microsoft Learn topic

Create and configure a Recovery Services vault

References

Use these Microsoft Learn resources to review the concepts covered in this updated AZ-104 practice test.

Comments