Free AZ-104 practice test: 20 questions

Updated September 28, 2026

Twenty questions across the five AZ-104 skill areas, weighted roughly as the real exam is: five on identity and governance, four on storage, five on compute, four on networking and two on monitoring and backup. These are original scenario questions. Find the constraint in each scenario before you look at the options.

Manage Azure identities and governance

Question 1. Users should be added to the Sales-Apps group automatically when their department attribute is set to Sales, and removed when it changes. What should you configure?

  • A. An assigned security group
  • B. A security group with a dynamic user membership rule on department
  • C. A Microsoft 365 group with assigned membership
  • D. A quarterly access review of the group
Show answer

Answer: B

A dynamic user group evaluates a membership rule on user attributes and updates membership automatically. Assigned groups need manual changes, a Microsoft 365 group with assigned membership has the same problem, and an access review checks membership periodically rather than following the attribute.

Want more questions like this? Full AZ-104 practice tests →

Question 2. You try to assign a Microsoft 365 licence to a new user in Microsoft Entra ID, but the assignment fails. The tenant has licences available. What is the most likely cause?

  • A. The user is not a member of any group
  • B. The user has not registered for SSPR
  • C. The user was created as a member rather than a guest
  • D. The user has no usage location set
Show answer

Answer: D

A licence cannot be assigned to a user without a usage location, because service availability varies by country. Group membership, SSPR registration and the user type do not block licence assignment in this way.

Want more questions like this? Full AZ-104 practice tests →

Question 3. A policy must add a missing environment tag to existing resources in a subscription. You assign a policy with the Modify effect, but existing resources remain untagged. What should you do?

  • A. Create a remediation task for the assignment
  • B. Change the effect to Audit
  • C. Apply a CanNotDelete lock to the subscription
  • D. Reassign the policy at the resource group scope
Show answer

Answer: A

Modify and DeployIfNotExists act on new and updated resources automatically, but existing resources are only changed by a remediation task, which runs under a managed identity. Changing to Audit only reports, a lock cannot add tags, and reassigning at another scope does not remediate anything.

Want more questions like this? Full AZ-104 practice tests →

Question 4. A single policy and RBAC assignment must apply to 12 subscriptions, including any subscriptions the company adds later. What should you use?

  • A. A tag applied to each subscription
  • B. Separate assignments on each subscription
  • C. A management group containing the subscriptions
  • D. A resource group per subscription with the assignments
Show answer

Answer: C

A management group that contains the subscriptions lets you assign policy and roles once, and new subscriptions moved into it inherit them. Tags do not carry permissions or policy. Assigning to each subscription does not cover future ones, and resource groups sit below subscriptions.

Want more questions like this? Full AZ-104 practice tests →

Question 5. The finance team wants an email when a subscription's forecast spend reaches 80% of 5,000 per month. Resources must not be stopped automatically. What should you configure?

  • A. Azure Advisor cost recommendations
  • B. A budget with an alert at 80% of forecast cost
  • C. An Azure Policy that denies expensive VM sizes
  • D. A ReadOnly lock on the subscription
Show answer

Answer: B

A budget with a threshold on forecast cost sends alerts without affecting resources. Azure Advisor recommends savings but does not alert on spend. A policy cannot track cost, and a ReadOnly lock would block changes rather than notify anyone.

Want more questions like this? Full AZ-104 practice tests →

Implement and manage storage

Question 6. An application must upload files to one blob container. Security requires that the token is not signed with the storage account key. Which type of SAS should you issue?

  • A. An account SAS
  • B. A service SAS
  • C. A user delegation SAS
  • D. The secondary access key
Show answer

Answer: C

A user delegation SAS is signed with Microsoft Entra credentials rather than the account key and works for Blob Storage. Account and service SAS tokens are both signed with an account key, and an access key is not a SAS at all.

Want more questions like this? Full AZ-104 practice tests →

Question 7. A storage account's firewall allows only one virtual network subnet. When you try to add the subnet, the portal warns that it is not configured correctly. What must you do on the subnet?

  • A. Enable a service endpoint for Microsoft.Storage
  • B. Link a private DNS zone to the virtual network
  • C. Add an NSG rule allowing outbound HTTPS
  • D. Associate a route table with the subnet
Show answer

Answer: A

The subnet needs a Microsoft.Storage service endpoint before it can be added as an allowed network in the storage firewall. A private DNS zone, an NSG rule or a route table does not satisfy that requirement.

Want more questions like this? Full AZ-104 practice tests →

Question 8. Users occasionally overwrite important blobs with incorrect content and need to get the previous content back. Which feature addresses this most directly?

  • A. Container soft delete
  • B. A lifecycle management rule
  • C. Object replication to another account
  • D. Blob versioning
Show answer

Answer: D

Blob versioning keeps a previous version automatically whenever a blob is overwritten, so the earlier content can be restored. Soft delete protects against deletion, not overwriting. Lifecycle management moves or deletes data, and object replication copies the overwritten content as well.

Want more questions like this? Full AZ-104 practice tests →

Question 9. You must copy 2 TB of files from an on-premises server to a blob container from a script, and resume if the transfer is interrupted. Which tool fits best?

  • A. Azure Storage Explorer
  • B. AzCopy
  • C. Upload through the Azure portal
  • D. Object replication
Show answer

Answer: B

AzCopy is the command-line tool for scripted bulk copies to Azure Storage and can resume interrupted jobs. Storage Explorer is a desktop tool for interactive use. The portal upload is manual and unsuited to 2 TB. Object replication copies between storage accounts, not from on-premises.

Want more questions like this? Full AZ-104 practice tests →

Deploy and manage Azure compute resources

Question 10. An ARM template deploys a storage account whose name comes from a parameter. The team wants the name built from a prefix plus a unique string, computed inside the template and reused in several resources. Which template section should hold it?

  • A. variables
  • B. parameters
  • C. outputs
  • D. resources
Show answer

Answer: A

Variables hold values computed inside the template, such as concatenating a prefix with uniqueString, and can be reused across resources. Parameters are supplied from outside at deployment time. Outputs return values after deployment, and resources define what is deployed rather than reusable values.

Want more questions like this? Full AZ-104 practice tests →

Question 11. You have an existing ARM template in JSON and want to maintain it in Bicep from now on. What should you do?

  • A. Export the resource group from the portal
  • B. Run a what-if deployment
  • C. Run az bicep decompile on the JSON file
  • D. Save it as a template spec
Show answer

Answer: C

The az bicep decompile command converts ARM JSON into a Bicep file that you then tidy up. Exporting from the portal produces ARM JSON, a what-if deployment previews changes, and a template spec stores a template without converting it.

Want more questions like this? Full AZ-104 practice tests →

Question 12. A VM must move from resource group RG1 to RG2 in the same subscription and region. What happens to the VM's region and what must move with it?

  • A. It moves to RG2’s region; only the VM resource moves
  • B. The region stays the same; dependent resources such as disks and NIC move with it
  • C. The VM must be recreated from a snapshot in RG2
  • D. The move requires Azure Site Recovery
Show answer

Answer: B

Moving between resource groups does not change the region. The VM’s dependent resources, such as its disks and network interface, must be moved along with it. Moving to another region needs Azure Resource Mover or Site Recovery, and the VM does not need to be recreated.

Want more questions like this? Full AZ-104 practice tests →

Question 13. A web app on an App Service plan in the Basic tier must scale out automatically on CPU load. The autoscale option is unavailable. What should you do?

  • A. Add a deployment slot
  • B. Set the manual instance count to three
  • C. Choose a larger Basic instance size
  • D. Scale the plan up to the Standard tier or higher
Show answer

Answer: D

Autoscale requires the Standard tier or higher, so the plan must be scaled up first. Adding a deployment slot also needs Standard, more manual instances do not scale automatically, and a larger Basic size scales up without adding autoscale.

Want more questions like this? Full AZ-104 practice tests →

Question 14. A containerised batch job runs once a night for 20 minutes. It needs no orchestration, scaling or ingress, and cost should be as low as possible. Which service fits best?

  • A. An App Service plan running a container
  • B. Azure Container Registry
  • C. Azure Container Instances
  • D. A Virtual Machine Scale Set
Show answer

Answer: C

Azure Container Instances starts a container quickly, bills per second while it runs, and suits a simple scheduled job with a restart policy of Never or OnFailure. App Service and a VM scale set run continuously. Container Registry stores images but does not run them.

Want more questions like this? Full AZ-104 practice tests →

Implement and manage virtual networking

Question 15. All traffic from a workload subnet to the internet must pass through a network virtual appliance at 10.0.0.4. What should you configure?

  • A. A route table with 0.0.0.0/0 to next hop virtual appliance 10.0.0.4, associated with the subnet
  • B. An NSG rule denying outbound internet traffic
  • C. Peering between the workload subnet and the NVA subnet
  • D. A service endpoint on the workload subnet
Show answer

Answer: A

A route table with a 0.0.0.0/0 route whose next hop type is virtual appliance at 10.0.0.4, associated with the workload subnet, sends internet-bound traffic through the NVA. An NSG filters but cannot redirect traffic. Peering and a service endpoint do not change the default route.

Want more questions like this? Full AZ-104 practice tests →

Question 16. Administrators need RDP access to VMs that have no public IP addresses, from a browser, without deploying a VPN. What should you deploy?

  • A. A public load balancer with an RDP rule
  • B. Azure Bastion in a subnet named AzureBastionSubnet
  • C. A private endpoint for each VM
  • D. A public IP address on each VM with an NSG rule
Show answer

Answer: B

Azure Bastion provides RDP and SSH through the portal to VMs with private IPs only. It needs a subnet named AzureBastionSubnet. A public load balancer or public IPs expose the VMs, and a private endpoint is for PaaS services, not VM administration.

Want more questions like this? Full AZ-104 practice tests →

Question 17. VMs in a virtual network must resolve each other by name, and records must be created automatically when a VM is added. What should you configure?

  • A. A public DNS zone with an A record per VM
  • B. A hosts file on every VM
  • C. A private DNS zone linked to the virtual network with auto-registration
  • D. A CNAME record in a public DNS zone
Show answer

Answer: C

A private DNS zone linked to the virtual network with auto-registration enabled creates and updates records for VMs automatically. A public zone is for internet-facing names, a hosts file per VM is manual, and a CNAME in a public zone does not resolve private addresses.

Want more questions like this? Full AZ-104 practice tests →

Question 18. An internal load balancer's backend VMs are healthy and the application listens on port 8080, but the health probe marks every backend as down. A custom NSG rule on the subnet denies all inbound traffic at priority 100. What is the fix?

  • A. Replace the internal load balancer with a public one
  • B. Add a DNS record for the load balancer frontend
  • C. Change the backend VMs to a larger size
  • D. Add an NSG rule allowing the AzureLoadBalancer service tag at a lower priority number than the deny rule
Show answer

Answer: D

Health probes originate from the AzureLoadBalancer service tag. The custom deny rule at priority 100 overrides the default allow rule, so the probe is blocked. An allow rule for AzureLoadBalancer with a lower number than the deny rule fixes it. A public load balancer, a different SKU or a DNS record does not unblock the probe.

Want more questions like this? Full AZ-104 practice tests →

Monitor and maintain Azure resources

Question 19. You want to analyse a storage account's read and write operations with KQL alongside logs from other resources. The data is not in Log Analytics today. What should you create?

  • A. A diagnostic setting sending resource logs to a Log Analytics workspace
  • B. A chart in Metrics explorer
  • C. An action group
  • D. An alert processing rule
Show answer

Answer: A

A diagnostic setting on the storage account sends its resource logs to a Log Analytics workspace, where they can be queried with KQL alongside other data. Metrics explorer shows numeric metrics, not operation logs. An action group sends notifications, and an alert processing rule changes alert handling.

Want more questions like this? Full AZ-104 practice tests →

Question 20. You need to back up Azure managed disks independently of their VMs, using the vault type Microsoft designed for disk backups. What should you create?

  • A. A Recovery Services vault
  • B. A Log Analytics workspace
  • C. A Backup vault
  • D. A Site Recovery replication policy
Show answer

Answer: C

Azure Disk Backup uses a Backup vault. The Recovery Services vault handles VM backups, Azure Files and workloads inside VMs, and hosts Site Recovery. A Log Analytics workspace and a snapshot of the OS disk alone are not vaults.

Want more questions like this? Full AZ-104 practice tests →

How did you do?

Sixteen or more correct suggests you are close. Below fourteen, the domain guides in this section are the fastest way to find the gaps. Questions 15–18 cover networking: if you missed more than one of them, spend your next study week on virtual networking, because that is where most AZ-104 candidates lose marks. Questions 1–5 are the largest domain; weak results there point to the identity and governance guide.

Repeat the free Microsoft practice assessment afterwards. If both results point at the same domain, you know where your remaining time should go.