AZ-140 Exam Dumps Pass with Updated 2025 Certified Exam Questions
AZ-140 Exam Questions - Real & Updated Questions PDF
NEW QUESTION # 150
You have an Azure subscription that contains a hybrid Azure Active Directory (Azure AD) tenant and two domain-joined Azure virtual machines. The virtual machines run Windows Server 2019 and contain managed disks.
You plan to deploy an Azure Virtual Desktop host pool that will use a Storage Spaces Direct Scale-Out File Server to host user profiles.
You need to ensure that the virtual machines can host the Storage Spaces Direct deployment. The solution must meet the following requirements:
* Ensure that the user profiles are available if a single server falls.
* Minimize administrative effort.
What should you do? To answer, select the appropriate options In the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Graphical user interface, text, application Description automatically generated
References:
https://docs.microsoft.com/en-us/windows-server/storage/storage-spaces/deploy-storage-spaces-direct
NEW QUESTION # 151
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have the following:
- A Microsoft 365 E5 tenant
- An on-premises Active Directory domain
- A hybrid Azure Active Directory (Azure AD) tenant
- An Azure Active Directory Domain Services (Azure AD DS) managed
domain
- An Azure Virtual Desktop deployment
The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune.
You need to configure the security settings for the Microsoft Edge browsers on the personal desktops.
Solution: You create and configure a Group Policy Object (GPO) in the on-premises domain.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
In a hybrid environment, group policies configured in an on-premises AD DS environment aren't synchronized to Azure AD DS. To define configuration settings for users or computers in Azure AD DS, edit one of the default GPOs or create a custom GPO.
https://learn.microsoft.com/en-us/azure/active-directory-domain-services/manage-group-policy/
NEW QUESTION # 152
Question: 182
You have an Azure Virtual Desktop deployment that contains two host pools named Pool! and Pool2.
Pool1 contains 10 session hosts and supports 100 concurrent users. Pool2 contains two session hosts and supports 20 concurrent users.
You need to recommend an Azure Virtual Desktop update solution that meets the following requirements:
* All service updates must be tested before reaching general availability.
* Testing must have a minimal impact on the organization.
* No new host pools can be created.
What should you include in the recommendation?
- A. From the properties of Pool2, enable the validation environment.
- B. From the properties of Pool2, assign a scaling plan.
- C. From the properties of Pool1, enable the validation environment.
- D. From the properties of Pool1, assign a scaling plan.
Answer: A
NEW QUESTION # 153
You have an Azure subscription that contains the resources shown in the following table.
You create a recovery services vault named Vault1.
Which resources can you back up using Azure Backup to Vault1?
- A. AVDVM-0. share1 and Image1 only
- B. AVDVM-0 and share1 only
- C. AVDVM-0 only
- D. AVDVM-0, Image1 and Image2 only
- E. AVDVM-0. share1. Image1 and Image2
Answer: B
Explanation:
Explanation
https://docs.microsoft.com/en-us/azure/backup/backup-overview#what-can-i-back-up Operational backup of blobs is a local backup solution. So the backup data isn't transferred to the Backup vault
NEW QUESTION # 154
You have an Azure Virtual Desktop deployment that contains a host pool. The pool has the following settings:
* Resource group: RG1
* Host pool name: Pool1
* Location: East US
* Host pool type: Pooled
The deployment contains the workspaces shown in the following table.
For Pool1, you plan to create a RemoteApp application group named AppGroup1.
In which workspaces can you register AppGroup1?
- A. Workspace1 and Workspace2 only
- B. Workspace1, Workspace2, Workspace3, and Workspace4
- C. Workspace1 only
- D. Workspace1 and Workspace3 only
Answer: D
NEW QUESTION # 155
You have the devices shown in the following table.
You plan to deploy Azure Virtual Desktop for client access to remote virtualized apps.
Which devices support the Remote Desktop client?
- A. Device1 and Device3 only
- B. Device1 only
- C. Device1 and Device2 only
- D. Device1, Device2, and Device3
Answer: A
Explanation:
https://learn.microsoft.com/en-us/azure/virtual-desktop/users/connect-windows?tabs=subscribe
NEW QUESTION # 156
You have an Azure Virtual Desktop Deployment that contains a workspace named Workspace1 and a user named User1. Workspace1 contains a Desktop application group named Pool1Desktop.
At 09:00, you create a conditional access policy that has the following settings:
* Assignments:
- Users and groups: User1
- Cloud apps or actions: Azure Virtual Desktop
- Conditions: 0 conditions selected
* Access controls
- Grant: Grant access, Require multi-factor authentication
- Sessions: Sign-in frequency 1 hour
User1 performs the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Text Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/set-up-mfa
NEW QUESTION # 157
You have a Windows Virtual Desktop deployment.
You need to provide external users with access to the deployment. The external users have computers that run Windows 10 Pro and Windows 10 Enterprise. The users do not have the ability to install applications.
What should you recommend that the users use to connect to the deployment?
- A. RemoteApp and Desktop Connection
- B. Remote Desktop Connection
- C. Remote Desktop Manager
- D. Microsoft Edge
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-external-users
https://docs.microsoft.com/en-us/azure/virtual-desktop/connect-web
Topic 1, Litware, Inc
Overview
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.
All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.
Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Windows Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.
Optimize the custom virtual machine images for the Windows Virtual Desktop session hosts.
Use PowerShell to automate the addition of virtual machines to the Windows Virtual Desktop host pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Windows Virtual Desktop connections from the Boston and Chennai offices.
Minimize latency of the Windows Virtual Desktop host authentication in each Azure region.
Minimize how long it takes to sign in to the Windows Virtual Desktop session hosts.
Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Windows Virtual Desktop apps.
Force users to reauthenticate if their Windows Virtual Desktop session lasts more than eight hours.
Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Windows Virtual Desktop session hosts and Microsoft 365.
Explicitly allow traffic between the Windows Virtual Desktop session hosts and the Windows Virtual Desktop infrastructure.
Use built-in groups for delegation.
Delegate the management of app groups to CloudAdmin1, including the ability to publish app groups to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups.
Minimize administrative effort to manage network security.
Use the principle of least privilege.
Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a Windows Virtual Desktop host pool.
Minimize how long it takes to provision the Windows Virtual Desktop session hosts based on the custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.
NEW QUESTION # 158
You have an Azure subscription that contains an Azure Virtual Desktop deployment, a standard Azure Firewall instance named FW1, and the virtual networks shown in the following table.
You need to configure VNet2 to route all outbound traffic via FW1. The solution must minimize the impact on the Azure Virtual Desktop deployment.
What should you do first?
- A. Deploy Azure Route Server to VNet2.
- B. Deploy Azure NAT Gateway to VNet1.
- C. Upgrade FW1 to the Premium SKU
- D. For FW1, enable DNS Proxy.
Answer: A
NEW QUESTION # 159
You have an Azure Virtual Desktop deployment that contains a session host named Host1.
You need to configure Windows Defender Firewall to allow inbound network traffic for RDP Shortpath on Host1.
Which program in the C:\Windows\System32 folder should you specify in the inbound firewall rule?
- A. Mstsc.exe
- B. Raserver.exe
- C. Rdpshell.exe
- D. Svchost.exe
Answer: D
Explanation:
New-NetFirewallRule -DisplayName 'Remote Desktop - RDP Shortpath (UDP-In)' -Action Allow -Description 'Inbound rule for the Remote Desktop service to allow RDP Shortpath traffic. [UDP 3390]' -Group '@FirewallAPI.dll,-28752' -Name 'RemoteDesktop-UserMode-In-RDPShortpath-UDP' -PolicyStore PersistentStore -Profile Domain, Private -Service TermService -Protocol UDP -LocalPort 3390 -Program '%SystemRoot%\system32\svchost.exe' -Enabled:True https://learn.microsoft.com/en-us/azure/virtual-desktop/configure-rdp-shortpath?tabs=managed-networks
NEW QUESTION # 160
You have an Azure Virtual Desktop deployment that contains a host pool.
The host pool contains 100 session hosts that run Windows 10 on general-purpose virtual machines.
You plan to implement Quality of Service (QoS) for the deployment.
What should you do first?
- A. Switch to a high-performance computing (HPC) virtual machine.
- B. Configure a scaling plan.
- C. Implement RDP Shortpath.
- D. Upgrade all the session hosts to Windows 11.
Answer: C
NEW QUESTION # 161
-
You have an Azure Virtual Desktop personal host pool. Each session host in the pool that has an operating system disk and a data disk.
You need to back up the session host data disks.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Text, letter Description automatically generated
NEW QUESTION # 162
You have an Azure Virtual Desktop deployment that contains a host pool named Pool 1. Pool 1 contains 10 session hosts that were deployed by using an Azure Resource Manager (ARM) template.
You discover that Windows licenses were NOT applied to the session hosts. You need to use a PowerShell script to update the licenses. Which cmdlet should you include in the solution?
- A. Update-ArVm
- B. Update-AzWvdWorkspace
- C. Update-AzWvdHostPoo1
- D. update-AzWvdDesktop
- E. Update-AzWvdsessionHost
Answer: A
NEW QUESTION # 163
You have an Azure subscription that contains the virtual machines shown in the following table.
You create an Azure Compute Gallery as shown in the Azure compute gallery exhibit. (Click the Azure compute gallery tab.)
You create a virtual machine image definition as shown in the VM image definition exhibit. (Click the VM image definition tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
Text Description automatically generated with medium confidence
NEW QUESTION # 164
You need to configure the virtual machines that have the Pool1 prefix. The solution must meet the technical requirements.
What should you use?
- A. a Windows Virtual Desktop automation task
- B. Service Health in Azure Monitor
- C. Virtual machine auto-shutdown
- D. Azure Automation
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/logic-apps/create-automation-tasks-azure-resources
NEW QUESTION # 165
-
You have an Azure Virtual Desktop deployment that contains the session hosts shown in the following table.
You have the users shows in the following table.
Users connect to Azure from the locations shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 166
You have a Azure Virtual Desktop deployment that contains multiple host pools.
You need to create a PowerShell script to sign users out of a specific session host before you perform a maintenance task.
Which PowerShell module should you load in the script?
- A. Az.Automation
- B. Az.COMputC
- C. Az.DektopVirtualization
- D. Az.Maintenance
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/powershell/module/az.desktopvirtualization/?view=azps-6.6.0#desktopvirtualization
https://techgenix.com/logging-off-and-removing-wvd-user-sessions/
NEW QUESTION # 167
You have an Azure subscription that contains the virtual machines shown in the following table.
You create an Azure Compute Gallery as shown in the Azure compute gallery exhibit. (Click the Azure compute gallery tab.)
You create a virtual machine image definition as shown in the VM image definition exhibit. (Click the VM image definition tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
NEW QUESTION # 168
You need to ensure that you can implement user profile shares for the Boston office users. The solution must meet the user profile requirements.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Sign in to VM1 asCloudAdmin1.
2 - Create a file share and configure share permissions.
3 - Install the AzFilesHybrid PowerShell module.
4 - Run the Join-AzureAccountForAuth cmdlet.
Reference:
https://www.christiaanbrinkhoff.com/2020/03/01/learn-here-how-to-configure-azure-files-with-active-directory-ad-authentication-for-fslogix-profile-container-and-msix-app-attach/
NEW QUESTION # 169
......
Pass Guaranteed Quiz 2025 Realistic Verified Free Microsoft: https://www.testsimulate.com/AZ-140-study-materials.html