The Microsoft AZ-104 Microsoft Azure Administrator Exam is part of the Azure Administrator Associate certification track. It is designed for IT professionals who manage Azure services, including networking, compute, identity, governance, storage, and monitoring. This exam matters for candidates who want to validate practical cloud administration skills and prove they can handle day-to-day Azure operations.
| # | Exam Topics | Sub-Topics | Approximate Weightage (%) |
|---|---|---|---|
| 1 | Implement and manage virtual networking | Virtual networks and subnets; Network security groups; DNS and routing; Private access and connectivity | 25% |
| 2 | Deploy and manage Azure compute resources | Virtual machines; VM availability and scaling; App Service basics; Container and compute deployment | 20% |
| 3 | Manage Azure identities and governance | Microsoft Entra ID users and groups; Role-based access control; Subscriptions and management groups; Policy and locks | 20% |
| 4 | Implement and manage storage | Storage accounts; Blobs, files, queues, and tables; Access tiers and replication; Storage security and access control | 20% |
| 5 | Monitor and maintain Azure resources | Azure Monitor; Alerts and metrics; Log Analytics and diagnostics; Backup and resource health | 15% |
This exam tests more than memorization. Candidates must show practical knowledge of Azure administration, understand how services work together, and apply the right configuration choices in real scenarios. It also checks your ability to solve operational tasks efficiently and maintain secure, reliable cloud resources.
QA4Exam.com offers an Exam PDF with actual questions and answers plus an Online Practice Test for the Microsoft AZ-104 exam. These materials help you study with real exam simulation, so you can get familiar with the question style and pressure before test day.
The questions are updated to stay relevant, and the verified answers help you check your understanding quickly. The practice test also supports time management practice, which is important when you want to finish confidently and pass on your first attempt.
With focused preparation and repeated practice, you can strengthen weak areas and improve your readiness for the Microsoft Azure Administrator Exam.
The exam is for IT professionals who want to validate their ability to manage Azure resources and earn the Azure Administrator Associate certification.
It can be challenging because it tests practical Azure administration skills across networking, compute, identity, storage, and monitoring.
Braindumps alone are not the best approach. You should use them with practice and hands-on understanding to improve your chances of passing.
Hands-on experience is strongly recommended because the exam focuses on real administrative tasks and practical Azure decision-making.
QA4Exam.com dumps are useful for question practice and answer review, but combining them with broader study and practice is the most effective way to prepare.
The Online Practice Test helps you simulate the exam, manage time, review verified answers, and identify weak areas before the real test.
QA4Exam.com provides an Exam PDF with questions and answers and an Online Practice Test for interactive preparation.
You need to implement a backup solution for App1 after the application is moved.
What should you create first?
A Recovery Services vault is a logical container that stores the backup data for each protected resource, such as Azure VMs. When the backup job for a protected resource runs, it creates a recovery point inside the Recovery Services vault.
Scenario:
There are three application tiers, each with five virtual machines.
Move all the virtual machines for App1 to Azure.
Ensure that all the virtual machines for App1 are protected by backups.
You have an Azure subscription.
You plan to create an Azure container registry named ContReg1.
You need to ensure that you can push and pull signed images for ContReg1. What should you do for ContReg1?
To push and pull signed container images in Azure Container Registry (ACR), you must enable content trust. Content trust integrates with Docker Notary and allows image publishers to sign images and consumers to verify those signatures during pull operations.
The other options do not meet the requirement:
Add a token controls authentication, not image signing
Enable encryption with customer-managed keys protects data at rest, not image signatures
Create a connected registry supports edge/replication scenarios, not signing
You have an Azure subscription that contains the virtual networks shown in the following table.

The subscription contains the virtual machines shown in the following table.

All The virtual machines have only private IP addresses.
You deploy an Azure Bastion host named Bastion1 to VNet1.
To which virtual machines can you connect through Bastion1 ?
Azure Bastion provides secure and seamless RDP/SSH access to virtual machines directly through the Azure portal, without requiring a public IP address on the target VMs. Bastion is deployed per virtual network (VNet) and enables connectivity only to virtual machines within that same VNet.
In the scenario:
Bastion1 is deployed in VNet1.
VM1 is connected to VNet1.
VM2 is connected to VNet2.
VM3 is connected to VNet3.
Even though VNet1, VNet2, and VNet3 are peered, Azure Bastion access does not traverse VNet peering connections. Microsoft explicitly states:
''Azure Bastion provides RDP/SSH access to virtual machines only within the virtual network in which it is deployed. Bastion does not support access to virtual machines in peered virtual networks.''
Therefore, Bastion1 can only provide session connectivity to VM1, which is directly connected to VNet1. VM2 (VNet2) and VM3 (VNet3) cannot be reached through Bastion1 even though peering exists, since Bastion connectivity is restricted to its host VNet.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
Solution: On Dev, you assign the Logic App Operator role to the Developers group.
Does this meet the goal?
The Logic App Operator role only grants the ability to read, enable, disable, and run logic apps. It does not grant the ability to create logic apps. To create logic apps, you need to assign the Logic App Contributor role or a higher-level role such as Owner or Contributor. Then, Reference: [Built-in roles for Azure resources] [Azure Logic Apps permissions and access control]
You plan to create an Azure virtual machine named VM1 that will be configured as shown in the following exhibit.
The planned disk configurations for VM1 are shown in the following exhibit.




You need to ensure that VM1 can be created in an Availability Zone.
Which two settings should you modify? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
https://docs.microsoft.com/en-us/azure/site-recovery/move-azure-vms-avset-azone https://docs.microsoft.com/en-us/azure/virtual-machines/windows/create-portal-availability-zone https://docs.microsoft.com/en-us/azure/virtual-machines/manage-availability https://docs.microsoft.com/en-us/azure/availability-zones/az-overview#availability-zones
Full Exam Access, Actual Exam Questions, Validated Answers, Anytime Anywhere, No Download Limits, No Practice Limits
Get All 477 Questions & Answers