EXAM DATE TIME ALLOWED
COURSE TITLE: Microsoft Azure Administrator — Final Review 2026/2027
— / — / —— 90 Minutes
INSTRUCTOR: —
◇
Microsoft AZ-104 — Final Review 2026/2027
Key Concepts & Terminology Quick Assessment
ALL QUESTIONS ARE COMPULSORY
A MULTIPLE CHOICE QUESTIONS (198 Marks)
Choose the single best answer for each question. Write the correct letter in the space provided.
1. Which Azure service orchestrates disaster recovery failover to another region?
A. Azure Backup
B. Azure Site Recovery
C. Azure Migrate
D. Azure Disaster Manager
◆
✦ CORRECT ANSWER: B. Azure Site Recovery
Rationale: Azure Site Recovery orchestrates and automates disaster recovery failover between Azure regions or from on-premises
to Azure.
2. Which NSG rule parameter determines evaluation order?
A. Name
B. Priority
C. Source
D. Protocol
◆
✦ CORRECT ANSWER: B. Priority
Rationale: NSG rules are evaluated by priority number (lowest number = highest priority). Rules with lower numbers are
processed first.
, 3. Which Microsoft Entra feature allows administrators to control how long elevated permissions are
active?
A. Conditional Access
B. Privileged Identity Management (PIM)
C. Access Reviews
D. Dynamic Groups
◆
✦ CORRECT ANSWER: B. Privileged Identity Management (PIM)
Rationale: PIM provides time-bound privileged role activation, requiring justification and approval for elevated permissions.
4. Which Azure Files feature protects against accidental deletion?
A. Blob versioning
B. Soft delete
C. Azure Backup
D. Snapshots
◆
✦ CORRECT ANSWER: B. Soft delete
Rationale: Soft delete retains deleted file shares and their contents for a configurable retention period, allowing recovery.
5. Which tool helps identify network routing and latency issues?
A. Azure Monitor
B. Azure Network Watcher
C. Azure Advisor
D. Azure Sentinel
◆
✦ CORRECT ANSWER: B. Azure Network Watcher
Rationale: Network Watcher provides tools like connection monitor, next hop, and packet capture to diagnose network issues.
, 6. Which Azure Storage feature allows restricting access to specific IP ranges?
A. Shared Access Signatures
B. Storage account firewalls
C. Azure AD authentication
D. Private Endpoints
◆
✦ CORRECT ANSWER: B. Storage account firewalls
Rationale: Storage account firewall settings restrict network access to specified IP ranges and virtual networks.
7. Which governance feature prevents changes across all child resources?
A. Delete lock
B. Read-only lock
C. Azure Policy
D. Role assignment
◆
✦ CORRECT ANSWER: B. Read-only lock
Rationale: Read-only locks prevent all modifications across the resource and its children while allowing read operations.
8. Which Azure governance feature prevents both deletion and modification of a resource?
A. Delete lock
B. Read-only lock
C. CanNotDelete lock
D. Azure Policy Deny effect
◆
✦ CORRECT ANSWER: B. Read-only lock
Rationale: Read-only locks prevent both deletion and modification. Users can only read the resource.