AZ-140問題一発合格させる問題集はMicrosoft Certified認定で!
AZ-140練習テストPDF試験材料
質問 # 75
You have an Azure Virtual Desktop host pool named Pool1, an application named App1, and an Azure file share named Share1.
You need to ensure that you can publish App1 to Pool1 by using MSIX app attach.
Which four actions should you perform in sequence before you publish App1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
正解:
解説:
1 - Generate a signing certificate.
2 - Create an MSIX package.
3 - Create an MSIX image.
4 - Upload the MSIX image to Shsre1.
Reference:
https://docs.microsoft.com/en-us/windows/msix/packaging-tool/create-app-package
https://docs.microsoft.com/en-us/azure/virtual-desktop/app-attach-image-prep
質問 # 76
You have an Azure Virtual Desktop deployment.
You plan to use just-in-time (JIT) VM access to manage session host virtual machines.
You need to recommend license requirements for JIT VM access. Your solution must minimize costs.
Which license should you recommend?
- A. Microsoft 365 E5
- B. Microsoft Defender for Servers Plan 1
- C. Microsoft Defender for Servers Plan 2
- D. Enterprise Mobility + Security E5
正解:B
解説:
Topic 1, Litware, Inc
Overview
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.
All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.
Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Windows Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.
Optimize the custom virtual machine images for the Windows Virtual Desktop session hosts.
Use PowerShell to automate the addition of virtual machines to the Windows Virtual Desktop host pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Windows Virtual Desktop connections from the Boston and Chennai offices.
Minimize latency of the Windows Virtual Desktop host authentication in each Azure region.
Minimize how long it takes to sign in to the Windows Virtual Desktop session hosts.
Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Windows Virtual Desktop apps.
Force users to reauthenticate if their Windows Virtual Desktop session lasts more than eight hours.
Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Windows Virtual Desktop session hosts and Microsoft 365.
Explicitly allow traffic between the Windows Virtual Desktop session hosts and the Windows Virtual Desktop infrastructure.
Use built-in groups for delegation.
Delegate the management of app groups to CloudAdmin1, including the ability to publish app groups to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups.
Minimize administrative effort to manage network security.
Use the principle of least privilege.
Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a Windows Virtual Desktop host pool.
Minimize how long it takes to provision the Windows Virtual Desktop session hosts based on the custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.
質問 # 77
You have a Windows Virtual Desktop host pool named Pool1 and an Azure Storage account named Storage1.
Storage1 stores FSLogix profile containers in a share folder named share1.
You create a new group named Group1. You provide Group1 with permission to sign in to Pool1.
You need to ensure that the members of Group1 can store the FSLogix profile containers in share1. The solution must use the principle of least privilege.
Which two privileges should you assign to Group1? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. the Storage Blob Data Contributor role for storage1
- B. the Storage File Data SMB Share Reader role for storage1
- C. the Modify NTFS permissions for share1
- D. the List folder / read data NTFS permissions for share1
- E. the Storage File Data SMB Share Contributor role for storage1
- F. the Storage File Data SMB Share Elevated Contributor role for storage1
正解:C、E
解説:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/create-file-share
質問 # 78
You have an Azure Active Directory Domain Services (Azure AD D5) domain named contoso.com.
You have an Azure Storage account named storage1. Storage1 hosts a file share named share1 that has share and file system permissions configured. Share1 is configured to use contoso.com for authentication, You create an Azure Virtual Desktop host pool named Pool1. Pool1 contains two session hosts that use the Windows 10 multi-session + Microsoft 365 Apps image.
You need to configure an FSLogix profile container for Pool1.
What should you do next?
- A. From storage1, set Allow shared key access to Disabled.
- B. Configure the Profiles setting for the session hosts of Pool1.
- C. Install the FSLogix agent on the session hosts of Pool1.
- D. Generate a shared access signature (SAS) key for storage1.
正解:C
解説:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/create-host-pools-user-profile
質問 # 79
Your company has the offices shown in the following table.
The company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1.
Users connect to a Windows Virtual Desktop deployment named WVD1. WVD1 contains session hosts that have public IP addresses from the 52.166.253.0/24 subnet.
Contoso.com has a conditional access policy that has the following settings:
Name: Policy1
Assignments:
Users and groups: User1
Cloud apps or actions: Windows Virtual Desktop
Access controls:
Grant: Grant access, Require multi-factor authentication
Enable policy: On
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
正解:
解説:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa
質問 # 80
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains two session hosts. Pool1 is configured as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE- Each correct selection is worth one point.

正解:
解説:
質問 # 81
You have an Azure Virtual Desktop Deployment that contains a workspace named Workspace1 and a user named User1. Workspace1 contains a Desktop application group named Pool1Desktop.
At 09:00, you create a conditional access policy that has the following settings:
Assignments:
- Users and groups: User1
- Cloud apps or actions: Azure Virtual Desktop
- Conditions: 0 conditions selected
Access controls
- Grant: Grant access, Require multi-factor authentication
- Sessions: Sign-in frequency 1 hour
User1 performs the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
Text Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/set-up-mfa
質問 # 82
You have an on-premises network.
All users have computers that run Windows 10 Pro.
You plan to deploy Azure Virtual Desktop to meet the department requirements shown in the following table.
You need to recommend licenses for the departments. The solution must minimize costs.
Which license should you recommend for each department? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/windows-10-multisession-faq
https://azure.microsoft.com/en-us/pricing/details/virtual-desktop/#pricing
質問 # 83
You need to configure the user settings of Admin1 to meet the user profile requirements.
What should you do?
- A. Modify the HKLM\SOFTWARE\FSLogix\ODFC registry settings.
- B. Modify the membership of the FSLogix ODFC Exclude List group.
- C. Modify the membership of the FSLogix Profile Exclude List group.
- D. Modify the HKLM\SOFTWARE\FSLogix\Profiles registry settings.
正解:B
解説:
Reference:
https://docs.microsoft.com/en-us/fslogix/overview
https://docs.microsoft.com/en-us/fslogix/configure-profile-container-tutorial#set-up-include-and-exclude-usergro
質問 # 84
You have a Windows Virtual Desktop host pool named Pool1 and an Azure Storage account named Storage1.
Storage1 stores FSLogix profile containers in a share folder named share1.
You create a new group named Group1. You provide Group1 with permission to sign in to Pool1.
You need to ensure that the members of Group1 can store the FSLogix profile containers in share1. The solution must use the principle of least privilege.
Which two privileges should you assign to Group1? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. the Storage Blob Data Contributor role for storage1
- B. the Storage File Data SMB Share Reader role for storage1
- C. the Modify NTFS permissions for share1
- D. the List folder / read data NTFS permissions for share1
- E. the Storage File Data SMB Share Contributor role for storage1
- F. the Storage File Data SMB Share Elevated Contributor role for storage1
正解:C、E
質問 # 85
You have an Azure Virtual Desktop host pool named Pool1 in the East US region.
You have a storage account named storage1 that contains FSLogix profile containers. In the East US region, you have a shared image gallery named SIG1 that contains a virtual machine image named Image1. Image1 is used to create new session hosts in Pool1.
You plan to deploy a new Azure Virtual Desktop host pool named Pool2 to the South India region.
You need to implement a session host deployment solution for Pool2 that meets the following requirements:
Image1 must replicate in the South India region.
The session hosts in Pool2 must be based on Image1.
Changes to Image1 must be available in the South India and East US regions.
What should you include in the solution?
- A. From SIG1, update the replication for the latest image version of Image1.
- B. Configure geo-redundant storage (GRS) replication for storage1. Copy the VHD file of Image1 to the FSLogix profile container.
- C. Create a new Azure Storage account named storage2 in the South India region. Copy Image1 to a shared folder in storage2.
- D. Create a new shared image gallery named SIG2 in the South India region. Upload a copy of Image1 to SIG2.
正解:A
解説:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-machines/shared-image-galleries
質問 # 86
You have the Azure Virtual Desktop deployment shown in the following table.
You plan to deploy a new host pool as shown in the following table.
You need to ensure that you can deploy the host pool.
What should you do?
- A. Submit a support request for service and subscription limits.
- B. Stop and deallocate one of the currently deployed virtual machines.
- C. Change the proposed virtual machine size for the session hosts to D4s_v3.
- D. Add a lock to the existing host pool.
正解:A
質問 # 87
You have an Azure Virtual Desktop deployment that contains two users named User1 and User2 and the storage accounts shown in the following table.
The File share settings for storage1 are configured as shown in the following exhibit.
The File share settings for storage2 are configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
正解:
解説:
Explanation:
YES, Yes , Yes
https://docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-ad-ds-assign-permissions?tabs=azure-p
"Once you've enabled Active Directory Domain Services (AD DS) authentication on your storage account, you must configure share-level permissions in order to get access to your file shares. There are two ways you can assign share-level permissions. You can assign them to specific Azure AD users/user groups and you can assign them to all authenticated identities as a default share level permission."
質問 # 88
You create an Azure Virtual Desktop host pool as shown in the following exhibit.
Use the drop-down menus to select the answer choice that answers each question based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:
正解:
解説:
質問 # 89
You need to ensure that you can implement user profile shares for the Boston office users. The solution must meet the user profile requirements.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
正解:
解説:
Explanation
Reference:
https://www.christiaanbrinkhoff.com/2020/03/01/learn-here-how-to-configure-azure-files-with-active-directory-a
質問 # 90
You need to configure a conditional access policy to meet the authentication requirements.
What should you include in the policy configuration? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.
正解:
解説:
質問 # 91
You plan to deploy Windows Virtual Desktop session host virtual machines based on a preconfigured master image. The master image will be stored in a shared image.
You create a virtual machine named Image1 to use as the master image. You install applications and apply configuration changes to Image1.
You need to ensure that the new session host virtual machines created based on Image1 have unique names and security identifiers.
What should you do on Image1 before you add the image to the shared image gallery?
- A. At a command prompt, run the sysprep command.
- B. At a command prompt, run the set computername command.
- C. From the lock screen of the Windows device, perform a Windows Autopilot Reset.
- D. From PowerShell, run the rename-computer cmdlet.
正解:A
解説:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/prepare-for-upload-vhd-image#determinewhen-to-use-sysprep
質問 # 92
......
Microsoft AZ-140試験は、Microsoft Certified: Azure for Operators Associate認定トラックの一部です。この試験に合格することで、Microsoft Azure Virtual Desktopを使用してクラウド上で仮想デスクトップとアプリケーションを展開および管理する能力を示すことができます。また、ITニーズにクラウドベースのソリューションを採用する組織が増える中で、仮想デスクトップインフラストラクチャの専門家として認められます。
Microsoft AZ-140認定試験は、ITの専門家がAzure Virtual Desktopの構成と操作でスキルと知識を紹介する絶好の機会です。この認定は、今日のクラウドベースのITランドスケープの重要なスキルである仮想デスクトップ環境の展開と管理に関する候補者の専門知識も検証します。
AZ-140[2024年06月] 最新リリース] 試験問題あなたを必ず合格させます:https://www.jpntest.com/shiken/AZ-140-mondaishu
AZ-140解答AZ-140無料サンプルには全てリアル試験:https://drive.google.com/open?id=10AFffDWLCKFcnSZKbC2bCTJOHyCoTjyI