New Microsoft 70-535 Exam Dumps Collection (Question 1 - Question 10)

Q1. You are developing a web application that connects to an existing virtual network. The web application needs to access a database that runs on a virtual machine.

In the Azure portal, you use the virtual network integration user interface to select from a list of virtual networks. The virtual network that the web application needs to connect to is not selectable.

You need to update the existing virtual network so you can connect to it. What should you do?

A. Enable ExpressRoute.

B. Enable site-to-site VPN.

C. Enable point-to-site VPN with a dynamic routing gateway.

D. Enable point-to-site VPN with a static routing gateway.

Answer: B

Q2. You administer an Azure Web Site named contosoweb that is used to sell various products. Contosoweb experiences heavy traffic during weekends.

You need to analyze the response time of the product catalog page during peak times, from different locations. What should you do?

A. Configure endpoint monitoring

B. Add the Requests metric

C. Turn on Failed Request Tracing

D. Turn on Detailed Error Messages

Answer: A


As we want to analyze response times from different locations, we should use endpoint monitoring.

References: https://docs.microsoft.com/en-us/azure/app-service-web/web-sites-monitor#webendpointstatus

Q3. You manage a virtual Windows Server 2012 web server that is hosted by an on-premises Windows Hyper-V server. You plan to use the virtual machine (VM) in Azure.

You need to migrate the VM to Azure Storage to add it to your repository. Which Azure Power Shell cmdlet should you use?

A. Import-AzureVM

B. New-AzureVM

C. Add-AzureDisk

D. Add-AzureWebRole

E. Add-AzureVhd

Answer: E


The Add-AzureVhd cmdlet uploads on premise Virtual hard disk (VHD) images to a blob storage account as fixed .vhd images.

References: https://docs.microsoft.com/en-us/powershell/module/Azure/Add-AzureVhd?view=azuresmps-4.0.0

Q4. Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are designing a storage solution to support on-premises resources and Azure-hosted resources.

You need to provide on-premises storage that has built-in replication to Azure. Solution: You include Azure File Storage in the design.

Does the solution meet the goal?

A. Yes

B. No

Answer: B

Q5. You manage a set of virtual machines (VMs) deployed to the cloud service named fabrikamVM. You configure auto scaling according to the following parameters:

* With an instance range of two to six instances

* To maintain CPU usage between 70 and 80 percent

* To scale up one instance at a time

* With a scale up wait time of 30 minutes

* To scale down one instance at a time

* With a scale down wait time of 30 minutes

You discover the following usage pattern of a specific application:

* The application peaks very quickly, and the peak lasts for several hours.

* CPU usage stays above 90 percent for the first 1 to 1.5 hours after usage increases. After

1.5 hours, the CPU usage falls to about 75 percent until application usage begins to decline.

You need to modify the auto scaling configuration to scale up faster when usage peaks. What are two possible ways to achieve this goal? Each correct answer presents a complete solution.

A. Decrease the scale down wait time.

B. Decrease the scale up wait time.

C. Increase the number of scale up instances.

D. Increase the scale up wait time.

E. Increase the maximum number of instances

Answer: B,C

Q6. You are designing a plan to deploy a new application to Azure. The solution must provide a single sign-on experience for users.

You need to recommend an authentication type. Which authentication type should you recommend?

A. SAML credential tokens

B. Azure managed access keys

C. Windows Authentication


Answer: A


A Microsoft cloud service administrator who wants to provide their Azure Active Directory (AD) users with sign-on validation can use a SAML 2.0 compliant SP-Lite profile based Identity Provider as their preferred Security Token Service (STS) / identity provider. This is useful where the solution implementer already has a user directory and password store on- premises that can be accessed using SAML 2.0. This existing user directory can be used for sign-on to Office 365 and other Azure AD-secured resources.

References: https://msdn.microsoft.com/en- us/library/azure/dn641269.aspx?f=255&MSPPError=-2147217396

Q7. Your company has a subscription to Azure. You configure your contoso.com domain to use a private Certificate Authority. You deploy a web site named MyApp by using the Shared (Preview) web hosting plan.

You need to ensure that clients are able to access the MyApp website by using https. What should you do?

A. Back up the Site and import into a new website.

B. Use the internal Certificate Authority and ensure that clients download the certificate chain.

C. Add custom domain SSL support to your current web hosting plan.

D. Change the web hosting plan to Standard

Answer: D


The Basic or the Standard plan is required for SSL support for custom domains. References: https://azure.microsoft.com/en-us/pricing/details/app-service/

Q8. An application sends Azure push notifications to a client application that runs on Windows Phone, iOS, and Android devices. Users cannot use the application on some devices. The authentication mechanisms that the application uses are the source of the problem.

You need to monitor the number of notifications that failed because of authentication errors. Which three metrics should you monitor? Each correct answer presents part of the solution

A. Microsoft Push Notification Service (MPNS) authentication errors

B. External notification system errors

C. Apple Push Notification Service (APNS) authentication errors

D. Channel errors

E. Windows Push Notification Services (WNS) authentication errors

F. Google Cloud Messaging (GCM) authentication errors

Answer: A,C,F


You must provision your app with one or more of the following services: Microsoft Push Notification Service (MPNS) for Windows Phone devices Apple Push Notification Service (APNS) for iPad and iPhone devices Google Cloud Messaging service (GCM) for Android devices

Windows Notification Service (WNS) for Windows devices

References: https://msdn.microsoft.com/en-us/magazine/dn879353.aspx

Q9. Your company has recently signed up for Azure. You plan to register a Data Protection Manager (DPM) server with the Azure Backup service. You need to recommend a method for registering the DPM server with the Azure Backup vault.

What are two possible ways to achieve this goal? Each correct answer presents a complete solution.

A. Import a self-signed certificate created using the makecert tool.

B. Import a self-signed certificate created using the createcert tool.

C. Import an X.509 v3 certificate with valid clientauthentication EKU.

D. Import an X.509 v3 certificate with valid serverauthentication EKU.

Answer: A,C


The certificate used for the backup vault in Azure must fulfill the following prerequisites: References: https://blogs.technet.microsoft.com/hybridcloud/2014/03/16/using-azure-backup-with-dpm/

Q10. Your company network has two physical locations configured in a geo-clustered environment.

You create a Blob storage account in Azure that contains all the data associated with your company.

You need to ensure that the data remains available in the event of a site outage. Which storage option should you enable?

A. Locally redundant storage

B. Geo-redundant storage

C. Zone-redundant storage

D. Read-only geo-redundant storage

Answer: D


Read-access geo-redundant storage (RA-GRS) maximizes availability for your storage account, by providing read-only access to the data in the secondary location, in addition to the replication across two regions provided by GRS.

When you enable read-only access to your data in the secondary region, your data is available on a secondary endpoint, in addition to the primary endpoint for your storage account.

References: https://docs.microsoft.com/en-us/azure/storage/storage-redundancy

