πŸ”

AZ-140 β€” questions

Page 5 of 11 Β· 218 total questions.

Topic 4 Β· Question 138

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have the following: β€’ A Microsoft 365 E5 tenant β€’ An on-premises Active Directory domain β€’ A hybrid Azure Active Directory (Azure AD) tenant β€’ An Azure Active Directory Domain Services (Azure AD DS) managed domain β€’ An Azure Virtual Desktop deployment The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune. You need to configure the security settings for the Microsoft Edge browsers on the personal desktops. Solution: You configure a configuration profile in Intune. Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 4 Β· Question 139

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have the following: β€’ A Microsoft 365 E5 tenant β€’ An on-premises Active Directory domain β€’ A hybrid Azure Active Directory (Azure AD) tenant β€’ An Azure Active Directory Domain Services (Azure AD DS) managed domain An Azure Virtual Desktop deployment The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune. You need to configure the security settings for the Microsoft Edge browsers on the personal desktops. Solution: You configure a compliance policy in Intune. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 140

You have an Azure Virtual Desktop deployment that contains multiple host pools. You need to create a PowerShell script to sign users out of a specific session host before you perform a maintenance task. Which PowerShell module should you load in the script?

  • AAz.Automation
  • BAz.Compute
  • CAz.Maintenance
  • DAz.DesktopVirtualization (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Az.DesktopVirtualization.

Topic 4 Β· Question 141

You have an on-premises network and an Azure subscription. The subscription contains the following: β€’ A virtual network β€’ An Azure Firewall instance β€’ An Azure Virtual Desktop host pool The virtual network connects to the on-premises network by using a site-to-site VPN. You need to ensure that only users from the on-premises network can connect to the Azure Virtual Desktop managed resources in the host pool. The solution must minimize administrative effort. What should you configure?

  • Aa conditional access policy (correct answer)
  • Ban Azure Firewall rule
  • Ca network security group (NSG) rule
  • Da user-defined route
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: a conditional access policy

Explanation

Conditional Access enforces access policies based on user, device, location, and risk signals.

Topic 4 Β· Question 142 Β· Select all that apply

You have an Azure Virtual Desktop deployment that uses Microsoft 365 cloud services including Microsoft Teams. Users use the Remote Desktop client to connect to the deployment from computers that run Windows 10. You need to support audio and video in Azure Virtual Desktop and provide the users with access to Microsoft Teams calling and meeting features. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • AInstall the Microsoft Teams WebSocket Service on the Windows 10 computers
  • BConfigure the IsWVDEnvironment registry key on the Windows 10 computers
  • CConfigure the IsWVDEnvironment registry key on the virtual machines (correct answer)
  • DInstall the Microsoft Teams desktop app on the Windows 10 computers
  • EInstall the Microsoft Teams WebSocket Service on the virtual machines (correct answer)
  • FInstall the Microsoft Teams desktop app on the virtual machines (correct answer)
Reveal answer & explanation
Correct answer: C, E, F

The correct answer is C, E, F. Option C: Configure the IsWVDEnvironment registry key on the virtual machines Option E: Install the Microsoft Teams WebSocket Service on the virtual machines Option F: Install the Microsoft Teams desktop app on the virtual machines

Explanation

An Azure Virtual Machine provides full control of the OS when you need to run custom or legacy workloads.

Topic 4 Β· Question 143

You have an Azure Virtual Desktop host pool named Pool1 that contains three session hosts. The session hosts are configured to use FSLogix profile containers. You need to configure Cloud Cache on the session hosts. What should you do?

  • AAdd a VHDLocations entries to the Windows registry
  • BRemove VHDLocations entries from the Windows registry (correct answer)
  • CUninstall the FSLogix agent
  • DConfigure FSLogix Office Container
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Remove VHDLocations entries from the Windows registry.

Topic 4 Β· Question 144

You have an Azure Virtual Desktop deployment. You implement FSLogix profile containers. You need to ensure that the FSLogix profile containers are not used for specific users. What should you do?

  • AModify the local groups on each session host (correct answer)
  • BApply an Application Masking rule to each session host
  • CApply an AppLocker policy to each session host
  • DModify the RDP Properties of the host pool
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Modify the local groups on each session host.

Topic 4 Β· Question 146

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have the following: β€’ A Microsoft 365 E5 tenant β€’ An on-premises Active Directory domain β€’ A hybrid Azure Active Directory (Azure AD) tenant β€’ An Azure Active Directory Domain Services (Azure AD DS) managed domain β€’ An Azure Virtual Desktop deployment The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune. You need to configure the security settings for the Microsoft Edge browsers on the personal desktops. Solution: You configure a Group Policy Object (GPO) in the Azure AD DS managed domain. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 147

You have an Azure Virtual Desktop deployment and the users shown in the following table. All the users plan to use a web browser to access Azure Virtual Desktop resources. Which users can connect to Azure Virtual Desktop by using their preferred browser?

  • AUser2 only
  • BUser1 only (correct answer)
  • CUser1, User2, and User3
  • DUser2 and User3 only
  • EUser1 and User2 only
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: User1 only.

Topic 4 Β· Question 148

Your on-premises network contains 20 Windows 10 devices. You have an Azure Virtual Desktop deployment. You need to deploy the Microsoft Remote Desktop client (MSRDC) to the devices. The MSRDC must be available to everyone who sign in to the devices. What should you do?

  • AInstall the MSRDC by using msiexec.exe and the ALLUSERS=1 command line option. (correct answer)
  • BInstall the MSRDC by using msiexec.exe and the ALLUSERS=2 command line option.
  • CInstall the MSRDC by using msiexec.exe and the MSIINSTALLPERUSER=1 command line option.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Install the MSRDC by using msiexec.exe and the ALLUSERS=1 command line option.

Topic 4 Β· Question 149

Your network contains an on-premises Active Directory domain named contoso.com. You have an Azure subscription that contains the resources shown in the following table. You need to create a share that will host FSLogix profiles for AVDPool1. The solution must meet the following requirements: * Maximize read and write performance for the profiles. * Control access to the SMB share by using the users and groups stored in contoso.com. Which account should you use to host the share?

  • AAccount1 (correct answer)
  • BAccount2
  • CAccount3
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Account1.

Topic 4 Β· Question 150

Your network contains an on-premises Active Directory domain named contoso.com that syncs to an Azure Active Directory (Azure AD) tenant. You have an Azure Virtual Desktop host pool named Pool1 that has the following settings: * Host pool name: Pool1 * Host pool type: Personal * Number of VMs: 3 The session hosts have the following configurations: * Image used to create the virtual machines: Windows 10 Enterprise8 * Virtual machines domain-joined to: On-premises contoso.com domain You need to ensure that you can use Microsoft EndPoint Manager to manage security updates on the session hosts. What should you do?

  • AChange Host pool type to Pooled and specify Load balancing algorithm as Depth-first.
  • BChange Host pool type to Pooled and specify Load balancing algorithm as Breadth-first.
  • CCreate Windows 10 Enterprise multi-session images.
  • DConfigure the session hosts as hybrid Azure AD-joined. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Configure the session hosts as hybrid Azure AD-joined.

Explanation

Azure Active Directory (Microsoft Entra ID) provides identity, single sign-on, and conditional access.

Topic 4 Β· Question 152

You have an Azure Virtual Desktop deployment that contains a host pool. The host pool contains 15 session hosts. All the sessions hosts have FSLogix installed. You need to configure the path to where the user profiles are stored. The solution must minimize administrative effort. Which registry setting should you use?

  • AVHDLocations (correct answer)
  • BCCDLocations
  • CProfileDirSDDL
  • DFlipFlopProfileDirectoryName
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: VHDLocations.

Topic 4 Β· Question 153 Β· Select all that apply

You have an Azure Virtual Desktop deployment that contains a host pool. The host pool contains 10 session hosts. The session hosts are configured by using a custom image and ephemeral disks. You need to deploy Microsoft OneDrive for Business. Which two actions should you perform for each session host? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • AInstall FSLogix. (correct answer)
  • BInstall the OneDrive sync app by using the per-machine installation option. (correct answer)
  • CImplement Application Masking.
  • DInstall the OneDrive sync app by using the per-user installation option.
  • EDeploy an MSIX app attach package.
Reveal answer & explanation
Correct answer: A, B

The correct answer is A, B. Option A: Install FSLogix. Option B: Install the OneDrive sync app by using the per-machine installation option.

Topic 4 Β· Question 154

You have an Azure Virtual Desktop deployment that contains a session host named Host1. You need to configure Windows Defender Firewall to allow inbound network traffic for RDP Shortpath on Host1. Which program in the C:\Windows\System32 folder should you specify in the inbound firewall rule?

  • ARdpshell.exe
  • BSvchost.exe (correct answer)
  • CRaserver.exe
  • DMstsc.exe
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Svchost.exe.

Topic 4 Β· Question 162

You have an Azure Virtual Desktop deployment that contains two host pools named Pooll and Pool2. Pool1 contains 10 session hosts and supports 100 concurrent users. Pool2 contains two session hosts and supports 20 concurrent users. You need to recommend an Azure Virtual Desktop update solution that meets the following requirements: β€’ All service updates must be tested before reaching general availability. β€’ Testing must have a minimal impact on the organization. β€’ No new host pools can be created. What should you include in the recommendation?

  • AFrom the properties of Pool1, enable the validation environment.
  • BFrom the properties of Pool2, enable the validation environment. (correct answer)
  • CFrom the properties of Pool1, assign a scaling plan.
  • DFrom the properties of Pool2, assign a scaling plan.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: From the properties of Pool2, enable the validation environment.

Topic 4 Β· Question 165

You have an Azure Virtual Desktop deployment. You plan to create the host pools shown in the following table. You plan to provide external users with access to the session hosts. You need to ensure that connections to Azure Virtual Desktop are licensed by using per-user access pricing. To which host pools will per-user access pricing apply?

Exhibit 1 for question 165
  • APool1 only
  • BPool4 only
  • CPool1 and Pool2 only (correct answer)
  • DPool1 and Pool4 only
  • EPool3 and Pool4 only
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Pool1 and Pool2 only.

Topic 4 Β· Question 166

You have an Azure Virtual Desktop deployment. You need to add a new application for a RemoteApp application group. The application must be available only during a user session. What should you use as an application source?

  • AFSLogix Profile Container
  • Bfile path
  • Cstart menu
  • Dapp attach (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: app attach.

Topic 4 Β· Question 167

You have an Azure subscription that contains an Azure Virtual Desktop deployment. The deployment contains a host pool named Pool. Users access the deployment by using the Windows client for Azure Virtual Desktop. You need to ensure that the users must reauthenticate every eight hours. The solution must minimize administrative effort. What should you do?

  • AFrom the Microsoft Entra admin center, create a Conditional Access policy. (correct answer)
  • BFrom the Microsoft Entra admin center, configure the User settings.
  • CDefine Pool1 as a validation environment.
  • DFor each session host, configure just-in-time (JIT) VM access.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: From the Microsoft Entra admin center, create a Conditional Access policy.

Explanation

Conditional Access enforces access policies based on user, device, location, and risk signals.

Topic 4 Β· Question 168

You have an Azure Virtual Desktop host pool named Pool1. All the session hosts in Pool1 are assigned private IP addresses only. You need to ensure that administrators can connect remotely to the session hosts. The solution must ensure that the administrators can connect to the session hosts by using Azure Command-Line Interface (CLI) and the Remote Desktop client for Windows. What should you include in the solution?

  • AAzure Application Gateway WAF_v2
  • BAzure Front Door Standard
  • CAzure Bastion Standard (correct answer)
  • DAzure Application Gateway Standard_v2
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Azure Bastion Standard

Explanation

Azure Bastion provides secure RDP/SSH access to VMs through the portal without exposing public IPs.

Showing questions 81–100 of 218 Β· Page 5 of 11