Free AZ-104 sample questions with answers
Here are five free AZ-104 sample questions, one from each skill area, with the answer and the reasoning behind it. Try each one before opening the answer. These are original scenario questions written against the official skills outline, not questions from the real exam.
Question 1. A developer must be able to create and delete any resource in the resource group RG-Dev, but must not be able to grant access to anyone else or touch any other resource group in the subscription. Which assignment meets the requirement with the least privilege?
- A. Owner on RG-Dev
- B. Contributor on RG-Dev
- C. Contributor on the subscription
- D. User Access Administrator on RG-Dev
Show answer
Answer: B
Contributor allows full management of resources but not role assignments, and assigning it at the RG-Dev scope limits it to that resource group. Owner would let the developer grant access. Contributor at subscription scope reaches every resource group. User Access Administrator manages access but cannot create resources.
Want more questions like this? Full AZ-104 practice tests →
Question 2. You issued several service SAS tokens for a blob container to a partner. The partner's credentials have leaked and you must invalidate those tokens immediately without affecting other applications that use the storage account keys. The tokens were created from a stored access policy on the container. What should you do?
- A. Rotate both storage account access keys
- B. Enable soft delete on the container
- C. Delete or modify the stored access policy on the container
- D. Add a storage firewall rule that blocks the partner’s IP address
Show answer
Answer: C
A SAS linked to a stored access policy can be revoked by deleting the policy or changing its expiry, which affects only the tokens tied to it. Rotating both account keys would break every application using the keys. Enabling soft delete protects data, not access. A firewall rule on the partner’s IP does not invalidate the tokens and fails if they are used from elsewhere.
Want more questions like this? Full AZ-104 practice tests →
Question 3. Two VMs run a critical web application in one Azure region. The application must stay available if an entire datacenter in that region fails. What should you deploy?
- A. Place both VMs in one availability set
- B. Resize both VMs to a larger size
- C. Move both VMs to premium SSD disks
- D. Deploy the VMs across two availability zones
Show answer
Answer: D
Availability zones are physically separate datacenters within a region, so VMs spread across zones survive the loss of one datacenter. An availability set spreads VMs across fault and update domains inside a single datacenter. A larger VM size and premium disks improve performance, not resilience to a datacenter outage.
Want more questions like this? Full AZ-104 practice tests →
Question 4. VNet-A is peered with VNet-Hub, and VNet-Hub is peered with VNet-B. VMs in VNet-A cannot reach VMs in VNet-B. There is no network virtual appliance or gateway in the hub. What is the most direct fix?
- A. Create a peering between VNet-A and VNet-B
- B. Add an NSG rule allowing VirtualNetwork traffic in VNet-A
- C. Enable gateway transit on the existing peerings without deploying a gateway
- D. Create a private DNS zone linked to all three virtual networks
Show answer
Answer: A
Virtual network peering is not transitive: A to Hub and Hub to B does not create A to B. A direct peering between VNet-A and VNet-B solves it. Transit through the hub would require a gateway or network virtual appliance plus routes. NSG and DNS changes cannot create a route that does not exist.
Want more questions like this? Full AZ-104 practice tests →
Question 5. You need to back up Azure VMs daily and keep each backup for 30 days, and you want restores of individual VMs from the Azure portal. Which resource do you create first?
- A. A Log Analytics workspace
- B. A Recovery Services vault with a backup policy
- C. A storage account with a lifecycle management rule
- D. A Backup vault for the virtual machines
Show answer
Answer: B
Azure VM backups with Azure Backup are stored in a Recovery Services vault, where you define the backup policy with schedule and retention. A Backup vault serves other workloads such as Azure Disks and blobs. A Log Analytics workspace stores monitoring data, not backups. A storage account snapshot schedule is not how Azure Backup protects VMs.
Want more questions like this? Full AZ-104 practice tests →
How did you do?
Questions 2 and 4 catch the most people. Stored access policies are one of the least-used storage features in real work, and non-transitive peering looks obvious until it is hidden inside a longer scenario. If either slowed you down, read the storage guide or the networking guide.
Question 5 is worth a second look too. Microsoft now has two vault types, and the outline names both, so knowing which workload goes where is an easy mark to lose.
What these questions have in common
None of them asks for a definition. Each describes a requirement and several options that all sound reasonable, and the answer depends on one detail: least privilege, revoke only these tokens, survive a datacenter failure, no transit, individual VM restores. That is how most of AZ-104 reads. Train yourself to underline the constraint before looking at the options.
For a longer check, take the 20-question practice test.