[Dec 05, 2023] AZ-140 Exam Dumps PDF Guaranteed Success with Accurate & Updated Questions
Pass AZ-140 Exam - Real Test Engine PDF with 178 Questions
NEW QUESTION # 51
Which role should you assign to Operator2 to meet the technical requirements?
- A. Desktop Virtualization Session Host Operator
- B. Desktop Virtualization Host Pool Contributor
- C. Desktop Virtualization User Session Operator
- D. Desktop Virtualization Contributor
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/rbac
Topic 1, Contoso. Ltd
Existing Infrastructure
Active Directory
The network contains an on-premises Active Directory domain named contoso.com and an Azure Active Directory (Azure AD) tenant. One of the domain controllers runs as an Azure virtual machine and connects to a virtual network named VNET1. All internal name resolution is provided by DNS server that run on the domain controllers.
The on-premises Active Directory domain contains the organizational units (OUs) shown in the following table.
The on-premises Active Directory domain contains the users shown in the following table.
The Azure AD tenant contains the cloud-only users shown in the following table.
Existing Infrastructure. Network Infrastructure
All the Azure virtual networks are peered. The on-premises network connects to the virtual networks.
All servers run Windows Server 2019. All laptops and desktop computers run Windows 10 Enterprise.
Since users often work on confidential documents, all the users use their computer as a client for connecting to Remote Desktop Services (RDS).
In the West US Azure region, you have the storage accounts shown in the following table.
Existing Infrastructure. Remote Desktop Infrastructure
Contoso has a Remote Desktop infrastructure shown in the following table.
Requirements
Planned Changes
Contoso plans to implement the following changes:
Implement FSLogix profile containers for the Paris offices.
Deploy a Windows Virtual Desktop host pool named Pool4.
Migrate the RDS deployment in the Seattle office to Windows Virtual Desktop in the West US Azure region.
Requirements. Pool4 Configuration
Pool4 will have the following settings:
Host pool type: Pooled
Max session limit: 7
Load balancing algorithm: Depth-first
Images: Windows 10 Enterprise multi-session
Virtual machine size: Standard D2s v3
Name prefix: Pool4
Number of VMs: 5
Virtual network: VNET4
Requirements. Technical Requirements
Contoso identifies the following technical requirements:
Before migrating the RDS deployment in the Seattle office, obtain the recommended deployment configuration based on the current RDS utilization.
For the Windows Virtual Desktop deployment in the Montreal office, disable audio output in the device redirection settings.
For the Windows Virtual Desktop deployment in the Seattle office, store the FSLogix profile containers in Azure Storage.
Enable Operator2 to modify the RDP Properties of the Windows Virtual Desktop deployment in the Montreal office.
From a server named Server1, convert the user profile clicks to the FSLogix profile containers.
Ensure that the Pool1 virtual machines only run during business hours.
Use the principle of least privilege.
NEW QUESTION # 52
You have a Azure Virtual Desktop deployment.
In Azure Advisor, you discover the following recommendation related to Azure Virtual Desktop:
* Impact Medium
* Description: No validation environment enabled
* Potential Benefit Ensure business continuity through AVD service deployments
* Impacted Resource:' Host Pool
What can you validate by implementing the recommendations?
- A. Capacity requirements of the session hosts
- B. Security settings of Azure Virtual Desktop
- C. Preview features for Azure Virtual Desktop
- D. Azure Site Recovery failover of the session hosts
Answer: D
Explanation:
Validation environments are used to test and validate Azure Virtual Desktop deployments before they are made available to users. This can include testing the capacity of the session hosts, the performance of the deployment, and the configuration of security settings. By implementing a validation environment, you can ensure that the Azure Virtual Desktop deployment is working correctly and that there are no issues that could impact business continuity. This can help to ensure a smooth user experience and minimize downtime.
NEW QUESTION # 53
You have a Windows Virtual Desktop host pool that has a max session limit of 15. Disconnected sessions are signed out immediately.
The session hosts for the host pool are shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/set-up-scaling-script
NEW QUESTION # 54
You have an Azure subscription that contains the resources shown in the following table.
You create a recovery services vault named Vault1.
Which resources can you back up using Azure Backup to Vault1?
- A. AVDVM-0 and share1 only
- B. AVDVM-0, Image1 and Image2 only
- C. AVDVM-0. share1 and Image1 only
- D. AVDVM-0 only
- E. AVDVM-0. share1. Image1 and Image2
Answer: A
Explanation:
https://docs.microsoft.com/en-us/azure/backup/backup-overview#what-can-i-back-up Operational backup of blobs is a local backup solution. So the backup data isn't transferred to the Backup vault
NEW QUESTION # 55
You have an Azure Virtual Desktop deployment that contains an Azure compute gallery. The Azure compute gallery contains an image definition named Definitions Definitionl contains the following image versions:
* 1.0.0
* 1.1.0
* 1.2.0
You need to ensure that when a virtual machine is created from the Azure compute gallery, the 1.1.0 image version is used by default.
What should you do?
- A. Select Exclude from latest for image version 1.0.0.
- B. Apply a lock to image version 1.1.0.
- C. Apply a tag named default to image version 1.1.0.
- D. Select Exclude from latest for image version 1.2.0. Most Voted
Answer: D
Explanation:
Exclude from latest. You can keep a version from being used as the latest image version. https://learn.microsoft.com/en-us/azure/virtual-machines/shared-image-galleries?tabs=azure-cli
Topic 1, Litware, Inc
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.
All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.
Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Windows Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.
Optimize the custom virtual machine images for the Windows Virtual Desktop session hosts.
Use PowerShell to automate the addition of virtual machines to the Windows Virtual Desktop host pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Windows Virtual Desktop connections from the Boston and Chennai offices.
Minimize latency of the Windows Virtual Desktop host authentication in each Azure region.
Minimize how long it takes to sign in to the Windows Virtual Desktop session hosts.
Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Windows Virtual Desktop apps.
Force users to reauthenticate if their Windows Virtual Desktop session lasts more than eight hours.
Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Windows Virtual Desktop session hosts and Microsoft 365.
Explicitly allow traffic between the Windows Virtual Desktop session hosts and the Windows Virtual Desktop infrastructure.
Use built-in groups for delegation.
Delegate the management of app groups to CloudAdmin1, including the ability to publish app groups to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups.
Minimize administrative effort to manage network security.
Use the principle of least privilege.
Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a Windows Virtual Desktop host pool.
Minimize how long it takes to provision the Windows Virtual Desktop session hosts based on the custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.
NEW QUESTION # 56
You have a Azure Virtual Desktop host pool that contains live session hosts. The session hosts run Windows
10 Enterprise multi-session.
You need to prevent users from accessing the internet from Azure Virtual Desktop sessions. The session hosts must be allowed to access all the required Microsoft services.
Solution: You configure the RDP Properties of the host pool.
Does This meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
Topic 1, Litware, Inc
Case study
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the button to return to the question.
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.
All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.
Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
* Deploy Windows Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office.
* Implement FSLogix profile containers.
* Optimize the custom virtual machine images for the Windows Virtual Desktop session hosts.
* Use PowerShell to automate the addition of virtual machines to the Windows Virtual Desktop host pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
* Minimize network latency of the Windows Virtual Desktop connections from the Boston and Chennai offices.
* Minimize latency of the Windows Virtual Desktop host authentication in each Azure region.
* Minimize how long it takes to sign in to the Windows Virtual Desktop session hosts.
Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
* Enforce Azure MFA when accessing Windows Virtual Desktop apps.
* Force users to reauthenticate if their Windows Virtual Desktop session lasts more than eight hours.
Requirements. Security Requirements
Litware identifies the following security requirements:
* Explicitly allow traffic between the Windows Virtual Desktop session hosts and Microsoft 365.
* Explicitly allow traffic between the Windows Virtual Desktop session hosts and the Windows Virtual Desktop infrastructure.
* Use built-in groups for delegation.
* Delegate the management of app groups to CloudAdmin1, including the ability to publish app groups to users and user groups.
* Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups.
* Minimize administrative effort to manage network security.
* Use the principle of least privilege.
Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
* Use PowerShell to generate the token used to add the virtual machines as session hosts to a Windows Virtual Desktop host pool.
* Minimize how long it takes to provision the Windows Virtual Desktop session hosts based on the custom virtual machine images.
* Whenever possible, preinstall agents and apps in the custom virtual machine images.
NEW QUESTION # 57
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have the following:
A Microsoft 365 E5 tenant
An on-premises Active Directory domain
A hybrid Azure Active Directory (Azure AD) tenant
An Azure Active Directory Domain Services (Azure AD DS) managed domain
An Azure Virtual Desktop deployment
The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune.
You need to configure the security settings for the Microsoft Edge browsers on the personal desktops.
Solution: You configure a configuration profile in Intune.
Does this meet the goal?
- A. No
- B. Yes
Answer: B
Explanation:
Reference:
https://docs.microsoft.com/en-us/mem/intune/fundamentals/azure-virtual-desktop
NEW QUESTION # 58
You have an Azure Virtual Desktop deployment that contains the resources shown in the following table.


Answer:
Explanation:
NEW QUESTION # 59
You are planning the deployment of Pool4.
What will be the maximum number of users that can connect to Pool4, and how many session hosts are needed to support five concurrent user sessions? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 60
Your company has the offices shown in the following table.
The company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1.
Users connect to a Windows Virtual Desktop deployment named WVD1. WVD1 contains session hosts that have public IP addresses from the 52.166.253.0/24 subnet.
Contoso.com has a conditional access policy that has the following settings:
Name: Policy1
Assignments:
Users and groups: User1
Cloud apps or actions: Windows Virtual Desktop
Access controls:
Grant: Grant access, Require multi-factor authentication
Enable policy: On
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa
NEW QUESTION # 61
You need to configure the virtual machines that have the Pool1 prefix. The solution must meet the technical requirements.
What should you use?
- A. a Windows Virtual Desktop automation task
- B. Azure Automation
- C. Virtual machine auto-shutdown
- D. Service Health in Azure Monitor
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/logic-apps/create-automation-tasks-azure-resources
NEW QUESTION # 62
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Windows Virtual Desktop host pool named Pool1 that is integrated with an Azure Active Directory Domain Services (Azure AD DS) managed domain.
You need to configure idle session timeout settings for users that connect to the session hosts in Pool1.
Solution: From the Azure portal, you modify the Session behavior settings in the RDP Properties of Pool1.
Does that meet the goal?
- A. Yes
- B. No
Answer: B
NEW QUESTION # 63
-
You have an Azure Virtual Desktop personal host pool. Each session host in the pool that has an operating system disk and a data disk.
You need to back up the session host data disks.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Create a Recovery Services vault.
2 - Grant permission for the vault.
3 - Create a backup policy and configure a backup.
NEW QUESTION # 64
Your company has a main office and two branch offices. Each office connects directly to the internet. The router in each branch office is configured as an endpoint for the following VPNs:
* A VPN connection to the main office
* A site-to-site VPN to Azure
The routers in each branch office have the Quality of Service (QoS) rules shown in the following table.
Users in the branch office report slow responses and connection errors when they attempt to connect to Windows Virtual Desktop resources.
You need to modify the QoS rules on the branch office routers to improve Windows Virtual Desktop performance.
For which rule should you increase the bandwidth allocation?
- A. Rule2
- B. Rule3
- C. Rule1
- D. Rule4
Answer: B
Explanation:
Explanation
https://docs.microsoft.com/en-us/azure/virtual-desktop/safe-url-list
Any Remote Desktop clients you use must have access to the following URLs:
Remote Desktop clients
Address Outbound TCP port
*.wvd.microsoft.com 443
*.servicebus.windows.net 443
go.microsoft.com 443
aka.ms 443
docs.microsoft.com 443
privacy.microsoft.com 443
query.prod.cms.rt.microsoft.com 443
NEW QUESTION # 65
Your network contains an on-premises Active Directory domain named contoso.com that syncs to an Azure Active Directory (Azure AD) tenant.
You have an Azure subscription that contains an Azure Virtual Desktop host pool.
You create an Azure Storage account named storage1.
You need to use FSLogix profile containers in storage1 to store user profiles for a group named Group1. The solution must use the principle of least privilege.
What should you include in the solution? To answer, select the appropriate options in the answer area.
Answer:
Explanation:
Explanation
Text Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-ad-ds-enable
https://docs.microsoft.com/en-us/azure/virtual-desktop/create-file-share
NEW QUESTION # 66
You have an Azure Virtual Desktop deployment.
You need to monitor the deployment by using the Azure Virtual Desktop Insights solution in Azure Monitor.
What should you use as the Diagnostic settings destination for the host pool?
- A. Storage account
- B. Event hub
- C. Log Analytics workspace
Answer: C
NEW QUESTION # 67
You have an Azure subscription named Subscription1 that contains the users shown in the following table.
Subscription1 contains the Azure Virtual Desktop host pools shown in the following table.
Subscription1 contains the Azure Virtual Desktop application groups shown in the following table.
You perform the role assignments shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Answer:
Explanation:
Explanation
Yes, No, Yes
NEW QUESTION # 68
-
You have an Azure Virtual Desktop deployment that contains the resources shown in the following table.
You need to perform the following configurations:
* Enable a managed identity for App1.
* Enable Clipboard redirection for App1.
On which resources should you perform the configurations? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 69
You have a Windows Virtual Desktop deployment.
You need to ensure that all the connections to the managed resources in the host pool require multi-factor authentication (MFA).
Which two settings should you modify in a conditional access policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa
NEW QUESTION # 70
You have an Azure Active Directory Domain Services (Azure AD D5) domain named contoso.com.
You have an Azure Storage account named storage1. Storage1 hosts a file share named share1 that has share and file system permissions configured. Share1 is configured to use contoso.com for authentication, You create an Azure Virtual Desktop host pool named Pool1. Pool1 contains two session hosts that use the Windows 10 multi-session + Microsoft 365 Apps image.
You need to configure an FSLogix profile container for Pool1.
What should you do next?
- A. Install the FSLogix agent on the session hosts of Pool1.
- B. Configure the Profiles setting for the session hosts of Pool1.
- C. From storage1, set Allow shared key access to Disabled.
- D. Generate a shared access signature (SAS) key for storage1.
Answer: B
NEW QUESTION # 71
You have an Azure subscription that contains a hybrid Azure Active Directory (Azure AD) tenant and two domain-joined Azure virtual machines. The virtual machines run Windows Server 2019 and contain managed disks.
You plan to deploy an Azure Virtual Desktop host pool that will use a Storage Spaces Direct Scale-Out File Server to host user profiles.
You need to ensure that the virtual machines can host the Storage Spaces Direct deployment. The solution must meet the following requirements:
* Ensure that the user profiles are available if a single server falls.
* Minimize administrative effort.
What should you do? To answer, select the appropriate options In the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 72
......
Get New AZ-140 Certification Practice Test Questions Exam Dumps: https://ucertify.examprepaway.com/Microsoft/braindumps.AZ-140.ete.file.html