Home Exams Roadmap Resources Board Pricing
Home › Certifications › Azure certifications › AZ-104

Azure Administrator AZ-104 Practice Test

Validates skills in managing AZURE subscriptions, virtual networks, storage, and VMs. A core AZURE operations certification.

Exam at a glance

Exam time
100 minutes
Exam questions
50
Passing score
700/1000
Valid for
1 years
Practice questions on CloudMasterIT
270

Exam domains and weighting

  • Manage Azure identities and governance — 25%

    Microsoft Entra ID, RBAC, Azure Policy, Subscriptions & Governance, Management Groups

  • Implement and manage storage — 20%

    Azure Storage Accounts, Azure Blob Storage, Azure Files, Storage Security, Azure Backup

  • Deploy and manage Azure compute resources — 25%

    Azure Virtual Machines, Azure Container Instances, Azure Kubernetes Service, Azure App Service, VM Scale Sets

  • Implement and manage virtual networking — 17%

    Azure Virtual Network, NSG, Azure Load Balancer, Azure DNS, VNet Peering

  • Monitor and maintain Azure resources — 13%

    Azure Monitor, Azure Alerts, Log Analytics, Azure Advisor, Azure Service Health

Free AZ-104 sample questions

Try real exam-style questions from the free sample set. Each answer comes with a full explanation.

  1. A company operates a web application on Azure App Service, and the application needs private access to a database on a virtual machine deployed inside a VNet.

    Which feature should be configured on the Web App to meet this requirement without exposure through the public internet?

    • A. VNet Integration
    • B. Private Endpoint
    • C. Service Endpoint
    • D. Azure Application Gateway
    Show answer and explanation

    Answer: A. VNet Integration

    The critical requirement in this scenario is that the Azure App Service web app needs to access a VM database inside a VNet privately and outbound. VNet Integration is a feature that allows App Service to access resources within a VNet outbound through a delegated subnet, enabling direct connection to a VM database without going through the public internet.

    Once VNet Integration is enabled, App Service can communicate directly with VMs, databases, and other services in the VNet's private IP address space through the delegated subnet. This is an outbound-direction private connectivity feature (App Service → VNet). Private Endpoint, in contrast, is for inbound private access to App Service from external clients — the direction is opposite.

    For the AZ-104 exam, directionality is the key for App Service networking questions. App Service needs outbound access to VNet → select VNet Integration. External needs inbound private access to App Service → select Private Endpoint. Service Endpoint is for VNet-to-Azure PaaS connections, and Application Gateway is for inbound traffic distribution and WAF.

  2. An Azure administrator at a company wants to visually monitor the entire organization's network health from a single view and review the network topology together with key metrics.

    Which Azure monitoring tool BEST meets these requirements?

    • A. Azure Monitor Metrics
    • B. Azure Network Watcher
    • C. Azure Log Analytics
    • D. Azure Activity Log
    Show answer and explanation

    Answer: B. Azure Network Watcher

    This question tests whether you can select the tool that simultaneously meets 'single-view visual monitoring,' 'network topology,' and 'key metrics.' Azure Network Watcher is a dedicated network monitoring service that provides a single dashboard displaying network components such as VNets, NSGs, and load balancers alongside a topology view and metrics through Network Insights. The other options support only specific aspects and cannot meet all three requirements simultaneously.

    Azure Network Watcher is an Azure-dedicated network service that integrates network monitoring, diagnostics, and logging. Key features include the Topology view for visualizing network structure, Network Insights for a single dashboard of the entire subscription's network health, Connection Monitor for continuous monitoring of connectivity between endpoints, and IP Flow Verify for diagnosing whether traffic is allowed or blocked by NSG rules.

    When you see the keywords 'topology' and 'single view,' select Azure Network Watcher. Azure Monitor Metrics specializes in resource performance number graphs, Azure Log Analytics is a KQL query-based log analysis tool, and Azure Activity Log records subscription-level management activity history — none of these provide topology visualization.

  3. An Azure administrator has assigned the Storage Blob Data Owner role to a specific user and configured an RBAC condition that applies ONLY to Blob write operations. This condition is set to allow writes only to specific container names.

    What is the EXPECTED outcome when this user attempts to read a Blob in a container NOT specified in the condition?

    • A. Read access denied
    • B. Read access allowed
    • C. Write-only allowed, read not possible
    • D. Condition reconfiguration required
    Show answer and explanation

    Answer: B. Read access allowed

    A user has the Storage Blob Data Owner role with a write condition configured, and attempts to read a Blob in a container not specified in the condition. The core characteristic of Azure RBAC Conditions is that they apply selectively only to specific actions, not to the entire role assignment. Since the condition is configured only for write operations, it does not apply to read operations at all. The Storage Blob Data Owner role includes Blob read, write, delete, and container management permissions, and permissions granted by the role remain fully effective for operations without conditions.

    RBAC Conditions operate by "narrowing the allowed scope." That is, conditions do not allow more than what the existing role permits, but they do not affect operations other than those for which a condition is set. Even if a write condition restricts writes to specific containers, it does not independently apply to the read permissions of the same role. Therefore, the user can read Blobs in any container, including containers not specified in the condition.

    On the exam, questions testing the selective action application of RBAC Conditions appear frequently. To restrict read permissions, you must add an independent condition for read operations separately from the write condition. When the combination "condition applies only to write" + "read attempt" appears, remember that reads without a condition are permitted as granted by the role.

  4. An IT team at a company wants to manage Custom Security Attributes in Microsoft Entra ID. According to the security policy, attribute definition tasks and attribute assignment tasks must be performed by different people.

    Which role can ONLY perform attribute definition (creation and modification) and cannot perform assignments?

    • A. Attribute Assignment Administrator
    • B. Global Administrator
    • C. Attribute Definition Administrator
    • D. Security Administrator
    Show answer and explanation

    Answer: C. Attribute Definition Administrator

    This question tests whether you can identify the role that implements the principle of separation of duties for managing Custom Security Attributes in Microsoft Entra ID. The role that can only perform attribute definition (creation and modification) without the ability to assign is Attribute Definition Administrator, while the role that can only perform assignments is Attribute Assignment Administrator. The two roles are clearly separated so that one role does not include the other's permissions.

    In Microsoft Entra ID, Custom Security Attributes are key-value pairs defined by organizations to assign business-specific metadata to Entra ID objects (users, applications, etc.). Attribute Definition Administrator manages the attribute schema by creating attribute sets and adding, modifying, or deactivating attribute definitions, but cannot assign values to actual objects. Attribute Assignment Administrator, conversely, only has permissions to assign or remove already-defined attributes to objects. Global Administrator holds both permissions and therefore becomes an incorrect answer in separation of duties scenarios.

    Exam questions test the distinction between Attribute Definition Administrator and Attribute Assignment Administrator. When you see keywords for definition (creation, modification, deactivation), choose Definition Administrator; when you see keywords for assignment (value assignment, removal), choose Assignment Administrator. Even if Global Administrator appears as an option, it is incorrect when separation of duties requirements are specified.

  5. An Azure administrator at a company wants to diagnose a problem where two virtual machines within the same VNet cannot communicate on a specific port.

    Which diagnostic tool in Azure Network Watcher should be used to quickly verify whether NSG rules are allowing that traffic?

    • A. Connection Monitor
    • B. IP Flow Verify
    • C. Packet Capture
    • D. NSG Flow Logs
    Show answer and explanation

    Answer: B. IP Flow Verify

    To select the correct answer, you first need to understand the difference between Azure Network Watcher's IP Flow Verify and other diagnostic tools. IP Flow Verify immediately checks whether a specified 5-tuple (source IP, source port, destination IP, destination port, protocol) traffic is allowed or denied based on the NSG rules applied to a virtual machine's network interface, and returns which NSG rule made the determination. Since it simulates NSG rules without sending actual packets, rapid diagnosis is possible.

    Azure Network Watcher provides several network diagnostic tools. IP Flow Verify is specialized for immediately checking whether NSG rules allow or deny traffic. Connection Monitor continuously monitors connectivity status and latency between two endpoints, Packet Capture captures and analyzes actual network packets from a VM, and NSG Flow Logs records all traffic flows through NSGs for post-event analysis.

    The keyword 'immediately verify whether NSG rules allow/deny specific traffic' maps to IP Flow Verify; 'continuous connection monitoring' maps to Connection Monitor; 'analyze actual packet content' maps to Packet Capture; 'review records of traffic passing through NSG' maps to NSG Flow Logs.

Practice the full free sample set

Three ways to study

  • Practice modeSee the explanation right after each answer, so you learn as you go.
  • Study modeReview questions and explanations at your own pace, with no timer.
  • Exam modeA timed, randomized set that mirrors the real exam conditions.

Frequently asked questions

How many questions are on the AZ-104 exam?

The Microsoft Azure Administrator (AZ-104) exam consists of 50 questions with a 100-minute time limit.

What is the passing score for AZ-104?

The passing score for the AZ-104 exam is 700 out of 1000.

Is the AZ-104 practice test free?

The AZ-104 sample set (20 questions with full explanations) is free. The full bank of 270+ questions is available with a CloudMasterIT subscription.

How long is the AZ-104 certification valid?

The AZ-104 certification is valid for 1 years after passing. Recertification is required after that.

Study guides

  • The Complete Azure AZ-104 Exam Guide
  • Identity and Governance
  • Storage Management Complete Guide
  • Virtual Machines and Deployment Automation
  • Mastering Azure Containers and App Service
  • VNet, NSG, DNS, and Load Balancer Explained for Beginners
  • Official exam guide

Related certifications

  • Azure Developer AZ-204 Practice Test
  • AWS Developer Associate Practice Exam (DVA-C02)
  • AWS CloudOps Engineer Associate Practice Exam (SOA-C03)
  • Google Associate Cloud Engineer Practice Exam (ACE)
  • Google Cloud Digital Leader Practice Exam (CDL)
  • AWS Solutions Architect Professional Practice Exam (SAP-C02)