AZ-104 practice questions

20 free AZ-104 practice questions with answers and explanations, covering identities and governance, storage, compute, virtual networking, and monitoring and backup. AZ-104 is scenario-heavy, so each question asks what you'd actually configure.

Study the full AZ-104 course, free to start.

AZ-104 exam at a glance

Skills measured from 17 April 2026

Official AZ-104 study guide on Microsoft Learn

20 free AZ-104 practice questions

Manage Azure identities and governance

Question 1. An organisation wants sign-ins that look risky, such as a leaked credential or an anonymous IP address, to force a password change automatically, and it wants administrators to hold their roles only while they are activated. Which licence covers both requirements?

  1. Microsoft Entra ID Free with security defaults enabled
  2. Microsoft 365 Business Standard
  3. Microsoft Entra ID P1
  4. Microsoft Entra ID P2
Show answer

Answer: D, Microsoft Entra ID P2. Microsoft Entra ID Protection supplies user risk and sign-in risk policies, and Privileged Identity Management supplies permanent and temporary administrators with an activation workflow. Both are P2 capabilities. P1 covers Conditional Access, self-service password reset with writeback and full multifactor authentication, but neither risk-based policies nor Privileged Identity Management. Security defaults on the Free tier enforce multifactor authentication for everyone but cannot make a decision based on risk. Microsoft 365 Business Standard is a productivity plan and adds neither capability.

Question 2. An administrator tries to move a virtual machine to another resource group and the operation fails with MissingMoveDependentResources. What does this mean in practice?

  1. The virtual machine is running and must be deallocated before it can be moved
  2. The destination resource group is in a different region from the source
  3. The destination subscription is not registered for the Microsoft.Compute resource provider
  4. Resources the virtual machine depends on, such as its managed disks, network interface, public IP address and virtual network, are neither already in the destination nor included in the move request
Show answer

Answer: D, Resources the virtual machine depends on, such as its managed disks, network interface, public IP address and virtual network, are neither already in the destination nor included in the move request. A move request has to carry every resource the moved resource depends on unless those dependencies already exist in the destination. Moving a virtual machine can involve seven resource types across three providers: virtualMachines and disks, networkInterfaces, publicIPAddresses, networkSecurityGroups and virtualNetworks, and storageAccounts. The virtual machine does not have to be stopped, and a move never changes region, so neither of those is the cause. An unregistered resource provider is a genuine failure mode but it returns a different error stating the subscription is not registered for the resource type.

Question 3. A project team must be able to create, resize and delete virtual machines in their own resource group, while the central networking team remains the only group able to change the virtual network those machines connect to. Which assignment fits?

  1. Contributor for the project team on the resource group holding the virtual machines
  2. Virtual Machine Contributor for the project team on the resource group holding the virtual machines, with the virtual network kept in a resource group they have no assignment on
  3. Owner for the project team on the resource group holding the virtual machines
  4. Contributor for the project team at subscription scope, with a Read-only lock applied to the virtual network
Show answer

Answer: B, Virtual Machine Contributor for the project team on the resource group holding the virtual machines, with the virtual network kept in a resource group they have no assignment on. Virtual Machine Contributor grants precisely the virtual machine and disk management the team needs and explicitly does not grant management access to the virtual network the machines are connected to, so keeping the network in a separate resource group completes the separation. Contributor or Owner on that resource group would work only while the network lives elsewhere, and Owner adds delegation nobody asked for. Contributor at subscription scope reaches the network wherever it is, and the Read-only lock proposed to compensate would also block the networking team, who are supposed to be able to change it.

Question 4. An administrator applies a Read-only lock to a production storage account during a change freeze. An application team then reports that a deployment pipeline has started failing when it tries to retrieve the storage account keys. What is happening?

  1. The Read-only lock blocks listing the account keys, because List Keys is handled by a POST request and locks prevent POST requests to the Resource Manager API
  2. The Read-only lock has rotated the account keys, so the pipeline is presenting stale values
  3. The lock has removed the pipeline's service principal from the storage account's role assignments
  4. The lock has disabled shared key authorisation on the storage account
Show answer

Answer: A, The Read-only lock blocks listing the account keys, because List Keys is handled by a POST request and locks prevent POST requests to the Resource Manager API. Microsoft documents this case specifically: a read-only lock on a storage account prevents users from listing the account keys, because the List Keys operation is a POST request and locks prevent POST from reaching the Resource Manager API. It is the classic example of a lock blocking something that does not look like a modification. Locks never change the resource itself, so no key is rotated, no role assignment is removed and no account setting is altered. If the pipeline must keep working through the freeze, either have it authenticate with Microsoft Entra credentials and a data plane role instead of account keys, or use CanNotDelete rather than Read-only.

Implement and manage storage

Question 5. You are configuring object replication between two general-purpose v2 accounts and the portal will not let you create the replication policy. Which combination of features has to be enabled first?

  1. The change feed on the destination account and blob versioning on the source account
  2. Blob soft delete on both the source and the destination accounts
  3. The change feed on both the source and the destination accounts
  4. The change feed on the source account and blob versioning on both accounts
Show answer

Answer: D, The change feed on the source account and blob versioning on both accounts. Object replication has exactly two prerequisites and they are asymmetric, which is what makes the other options tempting. The change feed is required on the source account only, because that is the log the service reads to discover which write and delete operations have to be copied. Blob versioning is required on both accounts, because the replicated state includes previous versions as well as the current one. Soft delete has nothing to do with it. Once a policy exists you cannot disable versioning on either account until it is removed.

Question 6. A 4 GB blob in the archive tier is needed for an urgent legal request and has to be readable within the hour. Which approach gives you the best chance of meeting that?

  1. Add a lifecycle policy rule with an action that moves the blob to the hot tier
  2. Call Set Blob Tier or Copy Blob with the rehydration priority set to high
  3. Change the storage account's default access tier from cool to hot
  4. Call Copy Blob with standard rehydration priority, which is quicker than Set Blob Tier
Show answer

Answer: B, Call Set Blob Tier or Copy Blob with the rehydration priority set to high. High-priority rehydration is prioritised over standard requests and often completes in under an hour for an object under 10 GB, which is the only option that fits the deadline. A lifecycle management policy can never rehydrate an archived blob, so that option cannot work at all. The account default access tier only decides the tier of blobs that have no explicitly set tier, and does nothing for an explicitly archived blob. Standard priority takes up to 15 hours regardless of whether you use Copy Blob or Set Blob Tier; the choice between those two affects early deletion fees, not speed.

Question 7. Your security standard forbids any application from holding a storage account key, and Shared Key authorisation is being disallowed on the account. An application still has to hand short-lived download links for individual blobs to end users. Which kind of token can it issue?

  1. An account SAS scoped to Blob Storage
  2. A service SAS created against a stored access policy
  3. An ad hoc service SAS with a one-hour expiry
  4. A user delegation SAS
Show answer

Answer: D, A user delegation SAS. An account SAS and a service SAS are both signed with an account access key, so issuing either requires the application to hold that key, and both stop working once Shared Key authorisation is disallowed. That rules out the first three options regardless of how the token is scoped or how short its expiry is. A user delegation SAS is signed with a user delegation key obtained using Microsoft Entra credentials, so no account key is involved; the principal requesting the key needs the generateUserDelegationKey action, which the Storage Blob Delegator role carries.

Question 8. A user overwrote a spreadsheet on an Azure file share this morning and wants yesterday's copy back. Soft delete is enabled on the storage account with a 30-day retention period, and share snapshots are taken nightly. What recovers the file?

  1. Undelete the file share, which restores it to its state before the overwrite
  2. Browse to last night's share snapshot and restore that single file from it
  3. Extend the soft delete retention period so that it covers the overwrite
  4. Restore the container from container soft delete
Show answer

Answer: B, Browse to last night's share snapshot and restore that single file from it. Soft delete for Azure Files operates at the file share level only. It recovers a share that was deleted, and it has nothing to say about a single file that was overwritten inside a share that still exists, so neither undeleting nor changing the retention period helps here. A share snapshot is a read-only point-in-time copy of the share from which you can restore an individual file or folder, which is exactly the requirement. Container soft delete is a Blob Storage feature and does not apply to file shares at all.

Deploy and manage Azure compute resources

Question 9. After every deployment a colleague has to open the portal to find the new storage account's primary blob endpoint so they can paste it into an application configuration. What should you add to the template so the deployment hands it back?

  1. A variable that concatenates the account name with blob.core.windows.net
  2. A parameter with a default value holding the expected endpoint
  3. A second template linked from the first that reads the account
  4. An entry in the outputs section whose value uses the reference function against the storage account
Show answer

Answer: D, An entry in the outputs section whose value uses the reference function against the storage account. The outputs section exists precisely for values that are only known once the deployment has run, and the reference function reads the runtime state of a deployed resource, so referencing the storage account and returning its primaryEndpoints gives the real value, shown in the portal's deployment history and returned by the command line. A variable built by string concatenation guesses the endpoint rather than reading it, which breaks the moment the endpoint format or the cloud changes. A parameter is an input, so a default value is just a hardcoded guess supplied before the resource exists. A linked template is for breaking a large deployment into parts and adds a whole file to solve something one output line covers.

Question 10. A three-instance web tier must keep serving requests if an entire datacentre in its region is lost. The region supports availability zones. What should you deploy?

  1. A three-instance availability set with three fault domains and five update domains
  2. Three virtual machines in the same availability set behind a Basic load balancer
  3. Three virtual machines pinned one to each of three availability zones, behind a Standard load balancer with a zone-redundant frontend
  4. Three virtual machines in one zone, with the region's paired region configured for failover
Show answer

Answer: C, Three virtual machines pinned one to each of three availability zones, behind a Standard load balancer with a zone-redundant frontend. Availability zones are the only one of these that survives the loss of a datacentre, because each zone is one or more physically separate datacentres with independent power, cooling and networking, and every enabled region has at least three. Spreading three machines across three zones also gives three fault domains and three update domains for free. An availability set, however many fault domains it has, spreads machines across racks inside one datacentre, so a datacentre-level event takes all of them. A Basic load balancer is not zone-aware and would be a single point of failure regardless. Putting all three in one zone and relying on the paired region is a disaster recovery answer, not an availability answer, and involves a failover rather than staying up.

Question 11. A deployment pipeline runs on an Azure virtual machine and must pull images from a private registry unattended, with no credential stored anywhere in the pipeline. Which authentication method should you configure?

  1. The registry's admin account, using the second password so the first can be rotated
  2. A service principal with the AcrPull role and its password held in the pipeline's variables
  3. A managed identity on the virtual machine, granted the AcrPull role on the registry
  4. az acr login run on a schedule to keep the cached token fresh
Show answer

Answer: C, A managed identity on the virtual machine, granted the AcrPull role on the registry. A managed identity is the only option here with no credential to store: the platform issues and rotates it, the virtual machine authenticates as itself, and the identity is granted a registry role through Azure role-based access control. A service principal is a legitimate headless option and supports role-based access control, but it has a password that has to live somewhere and expires after a year by default, which is what the question rules out. The admin account is disabled by default, has no role-based access control, gives full push and pull to a single shared identity, and Microsoft recommends it only for testing. Running az acr login on a schedule does not help because that token is an individual identity's, valid for three hours, and still requires a signed-in user.

Question 12. An App Service app must connect to an Azure SQL database that only accepts traffic from one subnet in a virtual network. The app itself should remain reachable on its public hostname. What should you configure?

  1. A private endpoint for the app in that subnet
  2. Regional virtual network integration for the app, with the integration subnet allowed on the database
  3. Access restrictions on the app allowing only the database's address range
  4. Hybrid Connections from the app to the database server and port
Show answer

Answer: B, Regional virtual network integration for the app, with the integration subnet allowed on the database. This is an outbound problem, and virtual network integration is the outbound feature: it places the back end of the app in a subnet in a virtual network in the same region so outbound calls originate from that subnet, which is what a service endpoint or a firewall rule on the database can then allow. It also leaves the app's inbound public hostname untouched, which the question requires. A private endpoint is inbound only, controlling who can reach the app, not what the app can reach. Access restrictions filter requests coming in to the app and have nothing to do with its outbound calls. Hybrid Connections is for reaching a host and port in a network not connected to Azure, which is not the case for a resource sitting inside an Azure virtual network.

Implement and manage virtual networking

Question 13. You are asked to peer a virtual network using 10.0.0.0/16 with a partner team's virtual network using 10.0.128.0/17, and the peering fails. What has to happen before it can succeed?

  1. A user-defined route has to be added in each virtual network pointing at the other
  2. Both virtual networks have to be moved into the same resource group
  3. One of the two virtual networks has to be re-addressed so the ranges no longer overlap
  4. Gateway transit has to be enabled on one side of the peering
Show answer

Answer: C, One of the two virtual networks has to be re-addressed so the ranges no longer overlap. 10.0.128.0/17 sits entirely inside 10.0.0.0/16, so the address spaces overlap, and peering creation fails outright when that is true. No setting makes an overlapping peering work: one side has to be re-addressed, which means deleting any existing peering, changing the address space and creating the peering again. Peered virtual networks do not need to share a resource group, a subscription or even a tenant. Gateway transit and user-defined routes are configured on a peering that already exists and cannot bring one into being.

Question 14. You have written an outbound rule allowing TCP 443 from an application subnet to a partner's address range, and the application can reach the partner successfully. A colleague asks you to add a matching inbound rule so the replies are not dropped. What should you tell them?

  1. That an inbound rule is required, because network security group rules are evaluated per direction
  2. That no inbound rule is needed, because network security groups are stateful and a flow record permits the return traffic
  3. That an inbound rule is required, but only if the partner ever initiates a connection of its own
  4. That no inbound rule is needed, because the AllowInternetOutBound default rule covers both directions
Show answer

Answer: B, That no inbound rule is needed, because network security groups are stateful and a flow record permits the return traffic. Network security groups are stateful. A flow record is created for an allowed connection and the return traffic is permitted on the strength of it, so you never write a mirror rule for replies. Rules are indeed evaluated per direction, but that governs which rules apply rather than whether replies need one. An inbound rule would be needed only if the partner initiated a connection to you, which is a different requirement from the one described. AllowInternetOutBound is an outbound rule and does not apply to inbound traffic in any sense.

Question 15. A hub virtual network holds a VPN gateway with a site-to-site connection to the on-premises datacentre. Two spoke virtual networks are peered to the hub, and machines in the spokes must reach on-premises servers without a gateway being deployed in either spoke. Which settings do you apply?

  1. Enable Traffic forwarded from remote virtual network on the hub side of each peering and nothing else
  2. Enable Virtual network gateway or Route Server on the hub side of each peering, and Remote virtual network gateway or Route Server on the spoke side
  3. Enable Remote virtual network gateway or Route Server on the hub side of each peering, and Virtual network gateway or Route Server on the spoke side
  4. Peer the two spokes to each other as well, so the gateway becomes reachable transitively
Show answer

Answer: B, Enable Virtual network gateway or Route Server on the hub side of each peering, and Remote virtual network gateway or Route Server on the spoke side. Gateway transit has a giving side and a taking side and the two are not interchangeable. The network that owns the gateway sets Virtual network gateway or Route Server, offering it; the network that wants to use it sets Remote virtual network gateway or Route Server. Reversing them configures each spoke to offer a gateway it does not have. Traffic forwarding controls whether non-originating traffic is accepted from the peer and is not what shares a gateway. Peering the spokes to each other achieves nothing, because peering is not transitive and neither spoke has a gateway to share in any case.

Question 16. A single public entry point has to send requests for /images to one pool of servers and requests for /api to another, with TLS terminated at the entry point so the backend servers do not carry the encryption cost. Which service should you use?

  1. Azure Application Gateway
  2. Azure Load Balancer with two load-balancing rules on different frontend ports
  3. Azure Traffic Manager with a weighted routing method
  4. Azure Load Balancer with session persistence set to Client IP
Show answer

Answer: A, Azure Application Gateway. Routing on the URL path is a layer 7 decision and requires the service to read the HTTP request, which is what Application Gateway does and what Azure Load Balancer, operating at layer 4, cannot do at all. TLS termination at the entry point is likewise an Application Gateway capability. Load Balancer with two rules would require clients to connect to two different ports, which is a different design rather than an answer to this one. Traffic Manager directs clients at the domain level using DNS and cannot see a path either. Session persistence controls which instance a client returns to, not which pool a path is sent to.

Monitor and maintain Azure resources

Question 17. You manage 60 storage accounts spread across three subscriptions. Leadership wants a single view this afternoon showing which accounts are seeing the worst end-to-end latency and the most client throttling errors. What is the least configuration that gets you there?

  1. Create a diagnostic setting on each storage account sending AllMetrics to a shared Log Analytics workspace, then query the AzureMetrics table
  2. Enable the Azure Monitor Agent on a virtual machine in each subscription and use VM insights to collect the storage metrics
  3. Create a Connection monitor test group in Network Watcher with each storage account endpoint as a destination
  4. Open Monitor, select Insights then Storage accounts, and set the subscription and storage account filters on the Overview workbook
Show answer

Answer: D, Open Monitor, select Insights then Storage accounts, and set the subscription and storage account filters on the Overview workbook. Storage insights needs nothing enabled and nothing configured, because Azure collects storage metrics by default. Opening it and setting the filters gives availability, end-to-end and server latency, transaction counts and error types across accounts immediately, for up to 200 accounts at once. Diagnostic settings sending AllMetrics to a workspace is a real technique and would eventually produce the same figures, but it means creating 60 settings, it only collects from the moment it is switched on so there is no history this afternoon, and it costs ingestion. VM insights monitors machines, not storage accounts. Connection monitor measures reachability and round-trip time to an endpoint, which is a network question rather than a storage latency and throttling question, and it would need agents deployed first.

Question 18. Azure Backup raises an alert whenever a backup job fails, and those alerts appear in the portal, but nobody receives an email. You look for an alert rule to attach an action group to and find none. What is the correct way to get these alerts emailed to the operations distribution list?

  1. Create a log search alert rule against the vault's diagnostic data in a Log Analytics workspace and attach an action group to it
  2. Create a metric alert rule on the vault's backup health metric and attach an action group to it
  3. Turn on the vault's classic alert notification settings and enter the distribution list address
  4. Create an alert processing rule scoped to the vault with the apply action group action, pointing at an action group that has an email notification
Show answer

Answer: D, Create an alert processing rule scoped to the vault with the apply action group action, pointing at an action group that has an email notification. Built-in Azure Monitor alerts for Azure Backup are generated by the service itself, not by an alert rule you created, so there is nothing to attach an action group to. Alert processing rules exist precisely for alert sources that do not let you specify action groups, and adding one with the apply action group action routes those already-fired alerts to email, SMS, a webhook or anything else an action group supports. The log search alert would work but only if the vault is already sending diagnostics to a workspace, and it creates a second alert alongside the one the service already raises. A metric alert on backup health is a genuine and useful technique, particularly for alerting on success rather than failure, but again it creates a new alert rather than routing the existing one. Classic alerts are the older solution, do not appear alongside Azure Monitor alerts, and are on a deprecation path, so building on them now is the wrong direction.

Question 19. An audit requires you to prove annually that production data could be recovered in a different region, without waiting for Microsoft to declare a regional disaster and without disrupting production. The Recovery Services vault protecting that data was created with zone-redundant storage and has been backing up machines for six months. What must you do?

  1. Enable Cross Region Restore on the existing vault and run the restore drill into the paired region
  2. Create a new geo-redundant Recovery Services vault, configure backup there, enable Cross Region Restore and allow up to 48 hours before the items appear in the secondary region
  3. Enable Cross Subscription Restore on the existing vault and restore into a subscription located in the other region
  4. Change the vault's storage replication type from zone-redundant to geo-redundant on the Backup Configuration blade, then enable Cross Region Restore
Show answer

Answer: B, Create a new geo-redundant Recovery Services vault, configure backup there, enable Cross Region Restore and allow up to 48 hours before the items appear in the secondary region. Cross Region Restore is what the audit is describing, because it lets you restore from the secondary region at any time rather than only during a declared outage, which is precisely how a compliance drill is run. It is supported only on a vault using geo-redundant storage, and a zone-redundant vault that already has backups configured cannot be changed to geo-redundant, so the honest answer is a new vault. Expect up to 48 hours after enabling before the backup items become available in the secondary region, which matters when the drill is scheduled. Cross Subscription Restore moves a restore between subscriptions in the same tenant and says nothing about region. Changing the replication type on a vault with configured backups is not possible, which is the trap in the last option.

Question 20. A regional incident forced a failover of 12 virtual machines to the secondary region three days ago, and you committed that failover at the time. The primary region has now been healthy for 24 hours and the business wants the workload back there with the smallest possible outage. What is the correct sequence?

  1. Disable replication on the machines in the secondary region, then enable replication in the opposite direction and fail over again
  2. Run a test failover to the primary region, then Commit it
  3. Change the recovery point on the Essentials page to one taken before the incident, then fail back
  4. Confirm the status reads Failover committed, run Re-Protect to reverse the replication direction, let the initial and delta replication complete, then fail over to the primary region and commit
Show answer

Answer: D, Confirm the status reads Failover committed, run Re-Protect to reverse the replication direction, let the initial and delta replication complete, then fail over to the primary region and commit. Re-Protect is the supported route and it does exactly what is needed: it reverses the direction so the secondary region replicates back to the primary, creating any resources it needs in the primary region as part of the operation, and it sends an initial copy followed by deltas. Only once that delta replication is current is the failback a short operation, which is what makes the outage small. It requires the status to be Failover committed, hence the first clause of the answer. Disabling and re-enabling replication would work eventually but throws away the existing relationship and forces a full initial replication with no delta catch-up, which is a longer outage for no benefit. A test failover proves nothing here and cannot be committed, since commit applies to a real failover. Changing the recovery point is only possible before a failover is committed, and committing deletes the remaining recovery points precisely so that this cannot be done afterwards.

A 6-week AZ-104 study plan

Frequently asked questions

How hard is AZ-104?

It's an associate-level exam aimed at people who administer Azure, and it expects hands-on familiarity with the portal, PowerShell and the Azure CLI. Networking and the detailed differences between storage options are where most candidates need extra time.

How long should I study for AZ-104?

Most people studying part-time plan six to eight weeks. If you don't use Azure at work, add time for hands-on practice in a free or pay-as-you-go subscription.

Are these real AZ-104 exam questions?

No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.

Is CertBuddi free?

You can enrol free with no card. Free accounts get the opening modules of every course; Pro (£9.99 a month, or £79.99 a year) unlocks every module, the full timed mock exam and an adaptive study plan.

How should I use these practice questions?

Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.

CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.