Summer Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

AZ-303 Questions and Answers

Note! Following AZ-303 Exam is Retired now. Please select the alternative replacement for your Exam Certification. The new exam code is AZ-305

AZ-303 Questions and Answers

Question # 6

You have an Azure subscription that contains an Azure LogAnalytics workspace. You have a resource group that contains 100 virtual machines. The virtual machines run Linux. You need to collect events from the virtual machines to the Log Analytics workspace. Which type of data source should you configure in the workspace?

A.

Syslog

B.

Linux performance counters

C.

custom fields

Full Access
Question # 7

Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question inthis section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Active Directory (Azure AD) tenant named contoso.com.

A user named Admin1 attempts to create an access reviewfrom the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin1 discovers that all the other Identity Governance settings are available.

Admin1 is assigned the User administrator, Compliance administrator, and Security administrator roles.

You need to ensure that Admin1 can create access reviews in contoso.com.

Solution: You create an access package.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 8

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your company is deploying an on-premises application named Appl. Users will access App1 by using a URL of https://app1.contoso.com. You register App1 in Azure Active Directory (Azure AD) and publish Appl by using the Azure AD Application Proxy. You need to ensure that Appl appears in the My Apps portal for all the users.

Solution: You create an offer for App1 and publish the offer to Azure Marketplace.

A.

Yes

B.

No

Full Access
Question # 9

You plan to migrate WebApp1 to Azure.

You need to implement the AKS cluster that will host WebApp1. The solution must meet thedeployment requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Full Access
Question # 10

You need to configure Azure AD Seamless SSO for Fabrikam. The solution must meet the authentication and authorization requirements.

What should you install first?

A.

the Azure AD Connect provisioning agent on SERVER1

B.

the Azure AD Connect provisioning agent on DC1

C.

Azure AD Connect in staging mode on SERVER1

D.

an Azure AD Connect primary server on SERVER1

Full Access
Question # 11

You migrate WebApp1 to Azure.

You need toconfigure the AKS cluster to enable WebApp1 to access KV1. The solution must meet the authentication and authorization requirements.

What should you do?

A.

Configure Azure role-based access control (Azure R8AQ for KubernetesAuthorization.

B.

Configure a pod-managed identity.

C.

Implement pod security policies.

D.

Implement the Secrets Store CSl Driver.

Full Access
Question # 12

You create and publish the BP1 blueprint.

You need to ensure that you can use BP1 to configure permissions for RG1. The solution must meet the authentication and authorization requirements.

What should you do?

A.

Add a read-only resource lock to Sub1.

B.

Assign an Azure role-based access control (Azure RBAC) role to Sub1.

C.

Assign an Azure role-based access control (Azure RBAC) role to BP1.

D.

Select the Read Only blueprint lock mode for the BP1 assignment.

Full Access
Question # 13

You need to deploy resources to RG1 by using the existing ARM templates. The solution must meet the deployment requirements.

What should you modify in the templates, and which cmdlet should you run to deploy the resources?

Full Access
Question # 14

You need to recommend a solution to provide KV1 with access to the on-premises network of Litware. The solution must meet the security requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Full Access
Question # 15

: 291

Note: This question is part ofseries of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Cosmos DB database that contains a container named Container1. The partition key for Container1 is set to /day. Container1 contains the items shown in the following table.

You need to programmatically query Azure Cosmos DB and retrieve item1 and item2 only.

Solution: You run the following query.

You set the EnableCrossPartitionQuery property to True.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 16

You need to ensure that the NoSQL data is encrypted. The solution must meet the security requirements.

What should you do first?

A.

Upgrade storage2 to StorageV2 (general purpose v2).

B.

Create a new general-purpose v2 storage account.

C.

Create a new Azure Blob storage account.

D.

Modify the Encryption settings of storage2.

Full Access
Question # 17

You need to ensure that you can implement Azure AD Seamless SSO for Fabrikam. The solution must meet the following requirements:

  • Support the planned changes.
  • Meet the authentication and authorization requirements.

What should you do?

A.

Create a new Azure AD tenant namedfabrikam.com

B.

From the Fabrikam forest, configure an additional UPN suffix ofLitware.com.

C.

From the Fabrikam forest, configure all users to have a UPN suffixofLitware.com.

D.

From theLitware.comtenant, add a custom domain named fabrikam com.

Full Access
Question # 18

You need to ensure that the virtual machine disks are encrypted. The solution must meet the security requirements.

Which three actions should you perform in Sub1 in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 19

You have an Azure Active Directory (Azure AD)tenant that contains the user groups shown in the following table.

You enable self-service password reset (SSPR) for Group1.

You configure the Notifications settings as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE:Each correct selection is worth one point.

Full Access
Question # 20

You have an Azure Kubernetes Service (AKS) cluster named Cluster1 in a resource group named RG1.

An administrator plans to manage Clus1 from an Azure AD-joineddevice.

You need to ensure that the administrator can deploy the YAML application manifest file for a container application.

You install the Azure CLI on the device.

Which command should you run next?

A.

kubectl get nodes

B.

az aksinstall-cli

C.

kubectl apply –f app1.yaml

D.

az aks get-credentials --resource-group RG1 --name Clus1

Full Access
Question # 21

: 299

You Wave an Acme Directory forest named contoso.com.

Youinstall and configure Azure AD Connect to use password hath synchronization as the single sign-on (SSO) method Staging mode is enabled

You review the synchronization results and discover that the Synchronization Service Manager does not display any sync jobs.

You need to ensure that the synchronization completes successfully.

What should you do?

A.

From Synchronization Service Manager, run a full import

B.

From Azure PowerShell, run Start-AdSyncCycle -PolicyType initial.

C.

Run Azure AD Connect and setthe SSO method to Pass-through Authentication

D.

Run Azure AD Connect and disable staging mode.

Full Access
Question # 22

Note: This question is part of series of questions that present the same scenario. Each question in the seriescontains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a server named Server1 that runs Windows Server 2019. Server1 is a container host.

You are creating a Dockerfile to build a container image.

You need to add a file named File1.txt from Server1 to a folder named C:\Folder1 in the container image.

Solution: You add the following line to the Dockerfile.

COPY File1.txt /Folder1/

You then build the container image.

Does this meet the goal?

A.

Yes

B.

No

Full Access