ACTUAL EXAM 400 QUESTIONS WITH DETAILED VERIFIED ANSWERS
(100% CORRECT ANSWERS) /A+ GRADE ASSURED
Azure Subscriptions govern... - (correct answer) - Access to resources within a subscription
- Cost through quotas and Tagging
- The resources that are allowed in an environment
Azure Subscription - (correct answer) - A logical unit of Azure linked to an Azure Account
- An identity in Azure AD
Azure AD - (correct answer) - An identity provider for Azure
- Provides Authentication to resources in an Azure Subscription
How to obtain an Azure Subscription - (correct answer) - Free trial
- Pay-as-you-go/Web Direct
- Visual Studio/MSDN subscriptions
- Microsoft Resellers
- Cloud Solution Provider
- MS Open Licensing
- Enterprise Agreements
Default Account used to sign up for Azure - (correct answer) Is set as both the Account Admin and
the Service Admin.
Service Admins and Co-Admins have - (correct answer) The same access as a user assigned the
Azure RBAC Owner role at the subscription scope
Classic Subscription Admins - (correct answer) - Have full access to an Azure Subscription
- Can manage resources through the Azure Portal, Resource Manager API ( PowerShell and CLI), and
the classic deployment model APIs
Account Administrator - (correct answer) - Limit 1 per Azure Account
Can:
- Access Account Center
- Create & Cancel subscriptions
- Change Billing for Subscriptions
- Change Service Admin
- More
Service Administrator - (correct answer) - Limit 1 per Azure Subscription
- Authorized to access the Azure Management Portal for all subscriptions in the account
- Same as the Account Admin by default when a subscriptions is created.
Co-Administrator - (correct answer) Same as the Service Admin, but cannot change the association
of subscriptions to Azure directories
Azure RBAC roles - (correct answer) - can be used to grant rights to principals including Service
and User principals
- More flexible than classic administrator roles
- Allow for more fin-grained access management
, - Recommended
Azure RBAC roles - 2 - (correct answer) - Have more than 70 built-in roles
4 Foundational Roles:
- Owner
- Contributor
- Reader
- User Access Administrator
Owner Role - (correct answer) - Full access to all resources
- Can delegate access to others
- The Service Admin and Co-admins are assigned this role at the subscription scope
- Applies to all resource types
Contributor Role - (correct answer) - Create and manage all types of Azure resources
- Cannot gran access to others
- Applies to all resource types
Reader Role - (correct answer) - View Azure resources
- Applies to all resource types
User Access Administrator - (correct answer) - Manages user access to Azure resources
Azure RBAC roles - 3 - (correct answer) - Only the Azure Portal, and the ARM APIs support this.
- Only Exist in Azure Resource Manager
- Users, Groups, or Service Principals assigned to this cannot use classic deployment APIs when only
assigned to this
Azure RBAC Scopes - (correct answer) - Subscription, Resource Group, or a Resource
- Inherited from Parent Source
Management Groups - (correct answer) - Can be used to apply RBAC to a subscription
- Allow you to apply Governance across subscriptions including RBAC and Azure Policy
Management Groups - 2 - (correct answer) - Allow Subscrptions to be organized in a multi-level
hierarchy
Provide:
- Reduced Overhead: no need to apply governance on every subscription
- Enforcement: Company admins can apply governance at the group level that encompasses multiple
Subscriptions. Governance is applied to existing and new subscriptions. Outside of Subscriptions
Admins Control
- Reporting: Standard tier SKU for Azure Policy provides reports of compliance; with Management
Groups, that reporting can span multiple subscriptions
Management Group - 3 - (correct answer) - Form a Hierarchy up to 6 levels deep (including root and
subscription levels)
- Can only have 1 parent, but multiple children
Root Management Group - (correct answer) - Associated with Azure AD tenant which is then
associated with a subscription
- Cannot be moved or deleted