Microsoft AZ-140 Practice Test Questions and Exam Dumps Part 10 Q181-200

View Full Microsoft AZ-140 Exam Dumps and Practice Test Dumps

 

Q181. What is a primary benefit of using RDP Shortpath with Azure Virtual Desktop?

1) It automatically creates new session hosts
2) It replaces the need for a host pool
3) It stores user profiles in Azure Files
4) It can provide a more direct network path for RDP traffic

Correct Answer: 4)

Explanation:

RDP Shortpath can improve Azure Virtual Desktop connection performance by establishing a more direct transport path between the client and session host when the required networking conditions are available. This can reduce latency and improve the consistency of the user experience compared with relying entirely on reverse-connect transport through the service. RDP Shortpath is particularly useful when network connectivity between the client and session host can support an appropriate UDP-based path. It does not replace host pools, profile storage, or session hosts. Administrators should evaluate network configuration, firewall rules, and connectivity requirements before enabling and using RDP Shortpath in an Azure Virtual Desktop environment.

Q182. Which network protocol is associated with RDP Shortpath for Azure Virtual Desktop?

1) UDP
2) FTP
3) SMTP
4) SNMP

Correct Answer: 1)

Explanation:

RDP Shortpath uses UDP-based transport to provide a more direct connection path for Azure Virtual Desktop RDP traffic when the environment supports it. UDP can provide efficient delivery for interactive remote desktop workloads because it can reduce the impact of certain network conditions and avoid unnecessary routing through intermediate service paths. Administrators must still configure networking and firewall access correctly for the chosen Shortpath scenario. FTP, SMTP, and SNMP are unrelated to the transport mechanism used for Azure Virtual Desktop interactive sessions. Understanding the transport protocol is important when troubleshooting connectivity, latency, firewall rules, and performance problems involving RDP Shortpath.

Q183. An administrator is planning an Azure Virtual Desktop deployment. Which Azure resource should be used to provide network connectivity for session host virtual machines?

1) Azure Storage account
2) Azure Virtual Network
3) Azure Key Vault
4) Azure Monitor workspace

Correct Answer: 2)

Explanation:

Azure Virtual Network provides the network environment in which Azure Virtual Desktop session host virtual machines can communicate with required services and resources. A properly designed virtual network and subnet are important for domain connectivity, profile storage, application access, DNS resolution, and other dependencies. Network security groups and routing can also be incorporated into the design to control traffic. An Azure Storage account is primarily used for storage workloads, while Azure Key Vault manages secrets and certificates. Azure Monitor is used for monitoring and diagnostics. Therefore, an Azure Virtual Network is the fundamental networking resource for session hosts.

Q184. What should an administrator verify if Azure Virtual Desktop session hosts cannot resolve domain names correctly?

1) Printer redirection settings
2) Clipboard settings
3) DNS configuration
4) Desktop application group type

Correct Answer: 3)

Explanation:

DNS configuration is critical for Azure Virtual Desktop session hosts because the machines must resolve domain controllers, Azure services, profile storage endpoints, and other required resources. If DNS settings are incorrect, session hosts may fail to join or communicate with a domain, authenticate users, or access required network resources. Administrators should verify that the virtual network uses appropriate DNS servers and that those servers can resolve the required internal and external names. Printer redirection, clipboard settings, and application group types do not control basic name resolution. Correct DNS configuration should therefore be one of the first areas investigated when session hosts experience name-resolution problems.

Q185. Which service can provide managed domain services for Azure Virtual Desktop session hosts without deploying traditional domain controllers?

1) Microsoft Entra Domain Services
2) Azure Monitor
3) Azure Application Insights
4) Azure Bastion

Correct Answer: 1)

Explanation:

Microsoft Entra Domain Services provides managed domain services such as domain join, Group Policy support, LDAP, and Kerberos/NTLM authentication without requiring administrators to deploy and maintain traditional domain controllers themselves. It can be useful when Azure Virtual Desktop session hosts require domain-based functionality but an organization does not want to operate domain controller virtual machines in Azure. Azure Monitor and Application Insights are monitoring services, while Azure Bastion provides secure administrative access to virtual machines. Microsoft Entra Domain Services therefore addresses the domain-services requirement rather than monitoring or remote administration.

Q186. Which configuration is important when Azure Virtual Desktop session hosts must join a traditional Active Directory domain?

1) Enable printer redirection
2) Configure appropriate DNS and network connectivity to domain controllers
3) Enable RemoteApp publishing
4) Configure clipboard redirection

Correct Answer: 2)

Explanation:

For session hosts to join a traditional Active Directory domain successfully, they need reliable network connectivity to the domain controllers and correct DNS configuration. DNS is especially important because domain-joined Windows computers use DNS to locate domain controllers and other Active Directory services. The session hosts must also be able to communicate with the necessary domain services through the configured network and security controls. Printer and clipboard redirection are RDP user-experience settings and do not establish domain connectivity. RemoteApp publishing controls application delivery after the environment is configured. Therefore, DNS and network connectivity should be verified before troubleshooting the domain-join process.

Q187. An organization wants to reduce latency for users connecting to Azure Virtual Desktop session hosts. Which factor should be evaluated first?

1) Number of published application groups
2) User profile file names
3) Network path and geographic proximity between users and session hosts
4) Desktop application group icon

Correct Answer: 3)

Explanation:

Network latency is strongly influenced by the network path and physical or logical distance between users and the Azure Virtual Desktop session hosts. Administrators should evaluate where users are located, where session hosts are deployed, and how traffic travels between those locations. A session host deployed in an appropriate Azure region can often provide a better experience for users than one located much farther away. Network congestion, routing, bandwidth, and transport configuration can also affect performance. Application group count, profile file names, and application group icons do not directly determine network latency. Network architecture should therefore be considered when optimizing the user experience.

Q188. What is the main purpose of a Network Security Group (NSG) in an Azure Virtual Desktop environment?

1) Store FSLogix profiles
2) Publish RemoteApp applications
3) Create user accounts
4) Control inbound and outbound network traffic

Correct Answer: 4)

Explanation:

A Network Security Group controls network traffic to and from Azure resources by using security rules that allow or deny specific traffic based on factors such as source, destination, protocol, and port. In an Azure Virtual Desktop deployment, NSGs can help restrict unnecessary network access while permitting required communication between session hosts, domain services, storage, management services, and other resources. NSGs do not store FSLogix profiles or publish applications. They also do not create user accounts. Administrators should design NSG rules carefully so that security controls do not unintentionally block required Azure Virtual Desktop, authentication, domain, or profile-management traffic.

Q189. Which Azure service is particularly suitable for high-performance file workloads that may be used for demanding FSLogix profile storage?

1) Azure NetApp Files
2) Azure DNS
3) Azure Monitor
4) Azure Policy

Correct Answer: 1)

Explanation:

Azure NetApp Files provides high-performance file storage designed for demanding workloads that require strong performance and predictable file-access characteristics. In Azure Virtual Desktop environments, it can be considered for workloads where FSLogix profile containers or related user data require higher performance than a basic file-storage design can provide. Administrators should still evaluate capacity, throughput, latency, permissions, networking, and cost before selecting a storage platform. Azure DNS is used for name resolution, Azure Monitor provides monitoring capabilities, and Azure Policy helps enforce governance rules. Azure NetApp Files is therefore the option most directly associated with high-performance file storage.

Q190. What should an administrator consider when selecting storage for FSLogix profile containers?

1) Only the desktop wallpaper
2) Storage latency, performance, permissions, and network connectivity
3) The number of application group icons
4) The RDP client display theme

Correct Answer: 2)

Explanation:

FSLogix profile containers depend heavily on reliable and responsive storage because user profile data is accessed during sign-in and throughout the user’s session. Administrators should evaluate storage latency, throughput, availability, permissions, and network connectivity. Poor storage performance can result in slow sign-ins, delayed application loading, or an inconsistent user experience. The storage location must also be accessible from the session hosts and configured with appropriate permissions. Desktop wallpaper, application group icons, and RDP display themes do not determine profile-storage performance. Properly planning FSLogix storage is therefore an important part of building a reliable Azure Virtual Desktop environment.

Q191. Which Azure Monitor capability can be used to notify administrators when a monitored Azure Virtual Desktop resource exceeds a defined threshold?

1) Application group publishing
2) Azure Monitor alerts
3) FSLogix profile containers
4) RDP Shortpath

Correct Answer: 2)

Explanation:

Azure Monitor alerts allow administrators to define conditions that trigger notifications or automated actions when monitored metrics or other supported signals meet specified criteria. For Azure Virtual Desktop, alerts can help administrators identify conditions such as unusually high resource utilization or other operational issues that require attention. This enables proactive monitoring rather than waiting for users to report problems. Application groups are responsible for resource publishing, FSLogix manages user profiles, and RDP Shortpath concerns network transport. Azure Monitor alerts therefore provide an appropriate mechanism for notifying administrators when monitored conditions exceed configured thresholds.

Q192. Which Azure Monitor feature is used to collect diagnostic data from Azure resources for centralized analysis?

1) Diagnostic settings
2) Personal host pools
3) Desktop application groups
4) RDP Shortpath

Correct Answer: 1)

Explanation:

Diagnostic settings allow supported Azure resources to send resource logs and metrics to destinations such as Log Analytics workspaces, storage accounts, or other supported monitoring destinations. In an Azure Virtual Desktop environment, diagnostic settings can be part of a centralized monitoring strategy that helps administrators analyze operational and troubleshooting information. This can make it easier to correlate events and investigate issues across multiple resources. Personal host pools and desktop application groups are AVD resource components, while RDP Shortpath is a networking feature. Diagnostic settings are therefore the appropriate choice for configuring the collection and routing of supported diagnostic information.

Q193. What is the main security reason to protect an Azure Virtual Desktop host pool registration token?

1) It controls printer preferences
2) It stores user passwords
3) It can be used to register session hosts with the host pool
4) It publishes applications to users

Correct Answer: 3)

Explanation:

A host pool registration token is used during the process of registering session hosts with an Azure Virtual Desktop host pool. Because possession of a valid token can enable a system to participate in the registration process, administrators should treat the token as sensitive information. Tokens should be generated when needed, protected from unauthorized access, and configured with an appropriate expiration period. The token does not function as a user password, printer configuration, or application-publishing mechanism. Proper token management reduces the risk of unauthorized session hosts being registered and helps maintain control over the Azure Virtual Desktop environment.

Q194. What should an administrator do before permanently removing a session host from an Azure Virtual Desktop host pool?

1) Immediately delete the VM without checking sessions
2) Disable all application groups
3) Change the workspace name
4) Check for active user sessions and move or sign them out appropriately

Correct Answer: 4)

Explanation:

Before permanently removing a session host, administrators should check whether users are currently connected and determine whether those sessions need to be moved, logged off, or otherwise handled. Removing a host without considering active sessions can unexpectedly interrupt users and potentially cause loss of unsaved work. Administrators can place the host into drain mode to prevent new sessions while existing sessions are addressed. After users have been handled appropriately, the host can be removed according to the organization’s operational procedure. Application groups and workspace names are unrelated to safely managing active sessions before host removal.

Q195. What is the purpose of placing an Azure Virtual Desktop session host into drain mode?

1) Prevent new user sessions from connecting to that host
2) Delete the session host automatically
3) Convert the host pool from pooled to personal
4) Move all user profiles to Azure NetApp Files

Correct Answer: 1)

Explanation:

Drain mode is used when an administrator needs to perform maintenance or prepare a session host for removal without allowing additional users to start new sessions on that host. Existing users can generally continue their sessions while administrators address maintenance requirements, depending on the operational procedure. Once users have disconnected or been handled appropriately, the administrator can perform maintenance, restart the machine, or remove it from service. Drain mode does not delete the VM, change the host pool type, or migrate profiles between storage platforms. It is therefore an important operational feature for safely maintaining Azure Virtual Desktop session hosts.

Q196. Which RDP property can administrators configure to control whether users can redirect local drives into an Azure Virtual Desktop session?

1) Drive redirection
2) Host pool scaling
3) Application group assignment
4) Image versioning

Correct Answer: 1)

Explanation:

Drive redirection is an RDP configuration that determines whether local client drives can be made available inside an Azure Virtual Desktop session. Administrators may restrict or disable drive redirection when organizational security requirements prohibit users from transferring files between local devices and remote session hosts. RDP properties can be applied at the appropriate Azure Virtual Desktop configuration level according to the deployment design. Host pool scaling manages session host capacity, application group assignment controls resource access, and image versioning manages VM images. Therefore, drive redirection is the specific setting used to control local-drive access within an RDP session.

Q197. Which feature can be used to restrict clipboard transfer between a user’s local device and an Azure Virtual Desktop session?

1) Azure Compute Gallery
2) Clipboard redirection settings
3) Host pool registration token
4) Azure Virtual Network peering

Correct Answer: 2)

Explanation:

Clipboard redirection settings control whether users can copy and paste content between their local client device and an Azure Virtual Desktop session. Organizations may restrict this capability to reduce the risk of sensitive information being transferred between managed and unmanaged environments. Administrators can configure the appropriate RDP properties based on organizational security requirements and the desired user experience. Azure Compute Gallery is used for image management, registration tokens are used for session host registration, and virtual network peering provides network connectivity between virtual networks. Therefore, clipboard redirection settings are the appropriate control for managing copy-and-paste behavior.

Q198. An administrator wants to apply different application sets to different departments while keeping the same base session host image. Which technology can help accomplish this?

1) RDP Shortpath
2) Azure DNS
3) MSIX app attach
4) Network Security Group

Correct Answer: 3)

Explanation:

MSIX app attach can help administrators deliver applications separately from the base operating system image used by Azure Virtual Desktop session hosts. This approach can reduce the need to maintain multiple images when different departments require different application sets. Administrators can maintain a standardized base image while making selected applications available to appropriate users or groups. RDP Shortpath addresses network transport, Azure DNS handles name resolution, and Network Security Groups control network traffic. MSIX app attach therefore supports a flexible application-delivery strategy that can help reduce image complexity and configuration differences between session hosts.

Q199. What is a key benefit of using Azure Compute Gallery for Azure Virtual Desktop images?

1) It replaces all user authentication
2) It provides RDP network transport
3) It disables session host scaling
4) It supports management and distribution of reusable image versions

Correct Answer: 4)

Explanation:

Azure Compute Gallery helps organizations manage reusable virtual machine images and their versions. For Azure Virtual Desktop, this can support a standardized image strategy in which administrators maintain tested operating system configurations and deploy consistent session hosts from approved image versions. Versioning also makes it easier to identify and manage different iterations of an image as updates are introduced. Azure Compute Gallery does not replace authentication, provide RDP transport, or disable scaling. Using controlled image versions can reduce configuration drift and make session host deployment and lifecycle management more predictable.

Q200. An organization has predictable high demand for Azure Virtual Desktop every weekday morning. Which feature can prepare session hosts ahead of that demand?

1) Scaling plan
2) Clipboard redirection
3) Drain mode
4) Application group assignment

Correct Answer: 1)

Explanation:

A scaling plan can be configured to help align Azure Virtual Desktop session host capacity with predictable usage patterns. For organizations with recurring demand, such as a large number of users signing in at the beginning of each business day, scheduled scaling behavior can prepare session hosts before users arrive. This can improve availability and reduce the delay associated with starting additional virtual machines at the moment demand increases. Clipboard redirection controls data transfer, drain mode manages new sessions on individual hosts, and application group assignment controls access to published resources. A scaling plan is therefore the most appropriate feature for predictable scheduled demand.