2.0 Implement and manage storage AZ-104 Practice Quiz

85 exam-style questions covering 18% of the AZ-104 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the Microsoft Azure Administrator practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A production storage account must be updated for configure Azure Storage firewalls and virtual networks. Which administrative action best fits the requirement?
  • A. Set the storage account network access to selected networks and add the required virtual network subnet or trusted public IP range
  • B. Use Azure Monitor without Log Analytics workspaces and store logs only in storage accounts
  • C. Share account access keys via email instead of using SAS tokens with stored access policies
  • D. Use Azure Blob Archive tier for data that needs millisecond retrieval times

Storage account firewall rules restrict access to approved networks while allowing required clients to connect.

A storage-related support ticket requires action for configure Azure Storage firewalls and virtual networks. Which implementation is most appropriate?
  • A. Verify DNS resolution to the private endpoint when clients cannot reach a storage account after public access is disabled
  • B. Disable soft delete in the vault to reduce storage costs
  • C. Remove budget alerts after the first month because spending is expected
  • D. Use Azure Blueprints as a real-time monitoring solution

Private endpoint connectivity depends on clients resolving the storage account name to the private endpoint address.

An audit finding identifies a gap in configure Azure Storage firewalls and virtual networks. What should the administrator change?
  • A. Use VNet peering to provide transitive routing between three VNets through a hub
  • B. Create a private endpoint for the storage account and disable public network access when access must stay on the virtual network
  • C. Regenerate a storage account key to update DNS settings
  • D. Use ZRS in a region where Availability Zones are not yet available

A private endpoint gives the storage account a private IP address and can remove public exposure.

During an Azure Storage review, the team identifies a requirement for configure Azure Storage firewalls and virtual networks. What should be done?
  • A. Use App Service to host a workload that needs full control of the underlying operating system
  • B. Use service endpoints or private endpoints based on the required network isolation model
  • C. Use Azure Storage Explorer to host a static website
  • D. Disable activity logs in production to reduce storage cost

Service endpoints secure traffic from selected subnets, while private endpoints provide private IP-based access to the service.

A production storage account must be updated for create and use shared access signature tokens. Which administrative action best fits the requirement?
  • A. Skip what-if deployments and apply ARM templates directly to production
  • B. Use an account SAS only when access must span service-level operations or multiple storage services
  • C. Delete the storage account to revoke one user's temporary access
  • D. Use Conditional Access only for blocking sign-ins, never for context-aware grants

An account SAS has broader scope and should be used only when that scope is required.

A workload team needs help with configure Azure Storage firewalls and virtual networks. Which Azure administrator action is correct?
  • A. Rely on a storage account name to encrypt data
  • B. Use a CNAME record at the apex (root) of a domain
  • C. Allow trusted Azure services only when the service integration requires it and the exception matches the security requirement
  • D. Use a Network Security Group as a stateful application-layer firewall

Trusted service exceptions should be used deliberately because they allow specific Azure services to bypass network restrictions.

An Azure administrator receives a request involving create and use shared access signature tokens. What should the administrator configure?
  • A. Assign a subscription Owner role to fix packet flow
  • B. Delete the storage account to revoke one user's temporary access
  • C. Create a SAS token with the minimum required permissions, resource scope, start time, expiry time, and allowed protocol
  • D. Treat a private DNS zone as automatically resolvable from any VNet without a link

A SAS should be limited by permission, time, resource, and transport requirements.

An Azure administrator receives a request involving configure Azure Storage firewalls and virtual networks. What should the administrator configure?
  • A. Use Application Insights only for production and skip dev/test environments
  • B. Use ARM templates to install applications on the guest OS
  • C. Use Azure Container Apps without a container image stored anywhere accessible
  • D. Add the client public IP address to the storage firewall when a temporary administrative workstation must access the account

Storage firewall IP rules can allow a known public client address without opening the account to all networks.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/microsoft-az-104/implement-and-manage-storage/

<a href="https://quizbuffet.com/microsoft-az-104/implement-and-manage-storage/">AZ-104 Azure Administrator Implement and manage storage practice quiz on QuizBuffet</a>

Other AZ-104 Domains

← Back to AZ-104 practice test overview

Questions are written against the published AZ-104 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.