exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 5 question 60 discussion

Actual exam question from Microsoft's AZ-104
Question #: 60
Topic #: 5
[All AZ-104 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You assign a built-in policy definition to the subscription.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
STH
Highly Voted 4 years, 7 months ago
there is no such built-in policy (yet), that is why we need a custom one
upvoted 86 times
ScreamingHand
3 years, 8 months ago
Exactly. I will memorise ALL of the built-in policies to ensure I am well prepared for the MS exam.
upvoted 107 times
MrMacro
3 years, 2 months ago
lol... too funny.
upvoted 8 times
...
urbanmonk
1 year, 4 months ago
lol, We need this kind of humor here because iterating over these questions is no child's play
upvoted 6 times
...
Lazylinux
2 years, 8 months ago
I can lend U the Blue Book Bill Gates gave me, it contains Summary bullet points style of All MS Technologies
upvoted 17 times
...
...
DodgyD
4 years, 1 month ago
Not sure what you are referring to ..There are many Built-in Policy Definitions for you to choose from. Sorting by Category will help you locate what you need.. https://docs.microsoft.com/en-us/azure/governance/policy/samples/built-in-policies I'd say ans: B, too - as a custom policy would be required for specific ports.
upvoted 6 times
d0bermannn
3 years, 7 months ago
agreed, if there is no device drivers [for winmodem for example], write it yourself [true unixway] ))
upvoted 1 times
...
...
I
4 years ago
I cannot agree you more!
upvoted 4 times
...
Indy429
1 year, 2 months ago
My god these trick questions everywhere. It's more about comprehensive reading and paying attention to silly details rather than focusing on actual solutions on these exam questions. Ridiculous.
upvoted 10 times
...
...
mlantonis
Highly Voted 3 years, 9 months ago
Correct Answer: B - No You need to use a custom policy definition, because there is not a built-in policy. Resource policy definition used by Azure Policy enables you to establish conventions for resources in your organization by describing when the policy is enforced and what effect to take. By defining conventions, you can control costs and more easily manage your resources. Reference: https://docs.microsoft.com/en-us/azure/azure-policy/policy-definition https://docs.microsoft.com/en-us/azure/governance/policy/samples/built-in-policies
upvoted 59 times
...
[Removed]
Most Recent 5 months, 1 week ago
Selected Answer: B
B is correct You configure a custom policy definition, and then you assign the policy to the subscription.
upvoted 1 times
...
blejzer2
7 months, 2 weeks ago
Today in exam , is B.
upvoted 2 times
...
tashakori
11 months, 3 weeks ago
No is right
upvoted 1 times
...
majerly
2 years, 5 months ago
Today in exam , is B
upvoted 6 times
...
favela
2 years, 5 months ago
Answer is B passed today score 900
upvoted 6 times
...
EmnCours
2 years, 6 months ago
Selected Answer: B
there is no such built-in policy (yet), that is why we need a custom one
upvoted 2 times
...
Lazylinux
2 years, 8 months ago
Selected Answer: B
I Luv Honey Because it is B Nothing relates to the solution no such thing in NSG
upvoted 2 times
...
EleChie
2 years, 8 months ago
Correct Answer B: NO We need to use a custom policy definition, because there is no such a built-in policy.
upvoted 1 times
...
AubinBakana
3 years, 6 months ago
I would have answered A here. Thank heavens I have spent time going through these. So there's no such a built-in role huh?! :)
upvoted 4 times
Sharathjogi
3 years, 1 month ago
Me too...
upvoted 2 times
...
...
Adebowale
3 years, 6 months ago
Hello STH, Well done for the clarification
upvoted 1 times
...
ZUMY
4 years ago
Sorry ignore previous No is answer when NSG is created the default NSG rule will NOT permit any traffic between 2 different VNETs . unless you peer the networks or create VPN gateway
upvoted 3 times
...
ZUMY
4 years ago
No is correct! when NSG is created the default NSG rule will NOT permit any traffic between 2 different VNETs So i think that the answer to All Q in this series is YES. unless you peer the networks or create VPN gateway
upvoted 2 times
...
toniiv
4 years ago
Answer B. is correct. You need to create a custom policy
upvoted 4 times
...
janshal
4 years, 1 month ago
again, when NSG is created the default NSG rule will NOT permit any traffic between 2 different VNETs So i think that the answer to All Q in this series is YES. unless you peer the networks or create VPN gateway between them, they will NOT be able to Talk to each other
upvoted 3 times
Laurent_Byanjira
4 years, 1 month ago
AllowVNetInBound ALLOWVNETINBOUND Priority Source Source ports Destination Destination ports Protocol Access 65000 VirtualNetwork 0-65535 VirtualNetwork 0-65535 Any Allow I think you are not right. This default rule will allow Vnet to communicate by default
upvoted 1 times
...
...
oooMooo
4 years, 2 months ago
You need to use a custom policy definition.
upvoted 11 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago