Validates skills in managing AZURE subscriptions, virtual networks, storage, and VMs. A core AZURE operations certification.
Microsoft Entra ID, RBAC, Azure Policy, Subscriptions & Governance, Management Groups
Azure Storage Accounts, Azure Blob Storage, Azure Files, Storage Security, Azure Backup
Azure Virtual Machines, Azure Container Instances, Azure Kubernetes Service, Azure App Service, VM Scale Sets
Azure Virtual Network, NSG, Azure Load Balancer, Azure DNS, VNet Peering
Azure Monitor, Azure Alerts, Log Analytics, Azure Advisor, Azure Service Health
Try real exam-style questions from the free sample set. Each answer comes with a full explanation.
A company operates a web application on Azure App Service, and the application needs private access to a database on a virtual machine deployed inside a VNet.
Which feature should be configured on the Web App to meet this requirement without exposure through the public internet?
Answer: A. VNet Integration
The critical requirement in this scenario is that the Azure App Service web app needs to access a VM database inside a VNet privately and outbound. VNet Integration is a feature that allows App Service to access resources within a VNet outbound through a delegated subnet, enabling direct connection to a VM database without going through the public internet.
Once VNet Integration is enabled, App Service can communicate directly with VMs, databases, and other services in the VNet's private IP address space through the delegated subnet. This is an outbound-direction private connectivity feature (App Service → VNet). Private Endpoint, in contrast, is for inbound private access to App Service from external clients — the direction is opposite.
For the AZ-104 exam, directionality is the key for App Service networking questions. App Service needs outbound access to VNet → select VNet Integration. External needs inbound private access to App Service → select Private Endpoint. Service Endpoint is for VNet-to-Azure PaaS connections, and Application Gateway is for inbound traffic distribution and WAF.
An Azure administrator at a company wants to visually monitor the entire organization's network health from a single view and review the network topology together with key metrics.
Which Azure monitoring tool BEST meets these requirements?
Answer: B. Azure Network Watcher
This question tests whether you can select the tool that simultaneously meets 'single-view visual monitoring,' 'network topology,' and 'key metrics.' Azure Network Watcher is a dedicated network monitoring service that provides a single dashboard displaying network components such as VNets, NSGs, and load balancers alongside a topology view and metrics through Network Insights. The other options support only specific aspects and cannot meet all three requirements simultaneously.
Azure Network Watcher is an Azure-dedicated network service that integrates network monitoring, diagnostics, and logging. Key features include the Topology view for visualizing network structure, Network Insights for a single dashboard of the entire subscription's network health, Connection Monitor for continuous monitoring of connectivity between endpoints, and IP Flow Verify for diagnosing whether traffic is allowed or blocked by NSG rules.
When you see the keywords 'topology' and 'single view,' select Azure Network Watcher. Azure Monitor Metrics specializes in resource performance number graphs, Azure Log Analytics is a KQL query-based log analysis tool, and Azure Activity Log records subscription-level management activity history — none of these provide topology visualization.
An Azure administrator has assigned the Storage Blob Data Owner role to a specific user and configured an RBAC condition that applies ONLY to Blob write operations. This condition is set to allow writes only to specific container names.
What is the EXPECTED outcome when this user attempts to read a Blob in a container NOT specified in the condition?
Answer: B. Read access allowed
A user has the Storage Blob Data Owner role with a write condition configured, and attempts to read a Blob in a container not specified in the condition. The core characteristic of Azure RBAC Conditions is that they apply selectively only to specific actions, not to the entire role assignment. Since the condition is configured only for write operations, it does not apply to read operations at all. The Storage Blob Data Owner role includes Blob read, write, delete, and container management permissions, and permissions granted by the role remain fully effective for operations without conditions.
RBAC Conditions operate by "narrowing the allowed scope." That is, conditions do not allow more than what the existing role permits, but they do not affect operations other than those for which a condition is set. Even if a write condition restricts writes to specific containers, it does not independently apply to the read permissions of the same role. Therefore, the user can read Blobs in any container, including containers not specified in the condition.
On the exam, questions testing the selective action application of RBAC Conditions appear frequently. To restrict read permissions, you must add an independent condition for read operations separately from the write condition. When the combination "condition applies only to write" + "read attempt" appears, remember that reads without a condition are permitted as granted by the role.
An IT team at a company wants to manage Custom Security Attributes in Microsoft Entra ID. According to the security policy, attribute definition tasks and attribute assignment tasks must be performed by different people.
Which role can ONLY perform attribute definition (creation and modification) and cannot perform assignments?
Answer: C. Attribute Definition Administrator
This question tests whether you can identify the role that implements the principle of separation of duties for managing Custom Security Attributes in Microsoft Entra ID. The role that can only perform attribute definition (creation and modification) without the ability to assign is Attribute Definition Administrator, while the role that can only perform assignments is Attribute Assignment Administrator. The two roles are clearly separated so that one role does not include the other's permissions.
In Microsoft Entra ID, Custom Security Attributes are key-value pairs defined by organizations to assign business-specific metadata to Entra ID objects (users, applications, etc.). Attribute Definition Administrator manages the attribute schema by creating attribute sets and adding, modifying, or deactivating attribute definitions, but cannot assign values to actual objects. Attribute Assignment Administrator, conversely, only has permissions to assign or remove already-defined attributes to objects. Global Administrator holds both permissions and therefore becomes an incorrect answer in separation of duties scenarios.
Exam questions test the distinction between Attribute Definition Administrator and Attribute Assignment Administrator. When you see keywords for definition (creation, modification, deactivation), choose Definition Administrator; when you see keywords for assignment (value assignment, removal), choose Assignment Administrator. Even if Global Administrator appears as an option, it is incorrect when separation of duties requirements are specified.
An Azure administrator at a company wants to diagnose a problem where two virtual machines within the same VNet cannot communicate on a specific port.
Which diagnostic tool in Azure Network Watcher should be used to quickly verify whether NSG rules are allowing that traffic?
Answer: B. IP Flow Verify
To select the correct answer, you first need to understand the difference between Azure Network Watcher's IP Flow Verify and other diagnostic tools. IP Flow Verify immediately checks whether a specified 5-tuple (source IP, source port, destination IP, destination port, protocol) traffic is allowed or denied based on the NSG rules applied to a virtual machine's network interface, and returns which NSG rule made the determination. Since it simulates NSG rules without sending actual packets, rapid diagnosis is possible.
Azure Network Watcher provides several network diagnostic tools. IP Flow Verify is specialized for immediately checking whether NSG rules allow or deny traffic. Connection Monitor continuously monitors connectivity status and latency between two endpoints, Packet Capture captures and analyzes actual network packets from a VM, and NSG Flow Logs records all traffic flows through NSGs for post-event analysis.
The keyword 'immediately verify whether NSG rules allow/deny specific traffic' maps to IP Flow Verify; 'continuous connection monitoring' maps to Connection Monitor; 'analyze actual packet content' maps to Packet Capture; 'review records of traffic passing through NSG' maps to NSG Flow Logs.
The Microsoft Azure Administrator (AZ-104) exam consists of 50 questions with a 100-minute time limit.
The passing score for the AZ-104 exam is 700 out of 1000.
The AZ-104 sample set (20 questions with full explanations) is free. The full bank of 270+ questions is available with a CloudMasterIT subscription.
The AZ-104 certification is valid for 1 years after passing. Recertification is required after that.