Question 31

A company connects their on-premises network by using Azure VPN Gateway. The on-premises environment includes three VPN devices that separately tunnel to the gateway by using Border Gateway Protocol (BGP).
A new subnet should be unreachable from the on-premises network.
You need to implement a solution.
Solution: Scale the gateway to Generation2.
Does the solution meet the goal?
  • Question 32

    A company has an Azure point-to-site virtual private network (VPN) that uses certificate-based authentication.
    A user reports that the following error message when they try to connect to the VPN by using a VPN client on
    a Windows 11 machine:
    A certificate could not be found
    You need to resolve the issue.
    Which three actions should you perform?
  • Question 33

    A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
    An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
    Error getting auth token
    You need to resolve the issue.
    Solution: Use a global administrator account that is not federated to configure Azure AD Connect.
    Does the solution meet the goal?
  • Question 34

    A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables
    backups for the VM by using the Azure portal.
    The company reports that the Azure VM backup job is failing.
    You need to troubleshoot the issue.
    Solution: Install the VM guest agent by using administrative permissions.
    Does the solution meet the goal?
  • Question 35

    A customer has an Azure subscription. Microsoft Defender for servers is enabled for the subscription. The customer has not configured network security groups.
    The customer configures a resource group named RG1 that contains the following resources:
    * A virtual machine named VM1.
    * A network interface named NIC1 that is attached to VM1.
    The customer grants a user named Admin1 the following permission for RG1: Microsoft.Security/locations/jitNetworkAccessPolicies/write.
    Admin1 reports that the JIT VM access pane in the Azure portal does not show any entries. When you view the same pane, VM1 appears on the Unsupported tab.
    You need to ensure that Admin1 can enable just-in-time (JIT) VM access for VM1. The solution must adhere to the principle of least privilege.
    Which three actions should you recommend be performed in sequence?
    To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.