[Feb 03, 2024] Verified AZ-600 dumps and 179 unique questions
AZ-600 Dumps for Pass Guaranteed - Pass AZ-600 Exam 2024
One of the key benefits of the Microsoft AZ-600 exam is that it is designed to help you develop the skills you need to succeed in a hybrid cloud environment. AZ-600 exam covers a range of topics related to Azure Stack Hub, including how to deploy and configure the platform, how to manage and monitor the environment, and how to troubleshoot issues. By taking AZ-600 exam, you will gain the knowledge and skills you need to succeed in a hybrid cloud environment.
NEW QUESTION # 22
You have an Azure Stack Hub integrated system.
You unlock the privileged endpoint (PEP).
How long will the PEP session remain unlocked?
- A. eight hours
- B. one hour
- C. 30 minutes
- D. 24 hours
Answer: A
Explanation:
Explanation
Unlocking the privileged endpoint for support scenarios
During a support scenario, the Microsoft support engineer might need to elevate the privileged endpoint PowerShell session to access the internals of the Azure Stack Hub infrastructure. This process is sometimes informally referred to as "break the glass" or "unlock the PEP".
An elevated PEP session has a validity of 8 hours, after which, if not terminated, the elevated PEP session will automatically lock back to a regular PEP session.
Reference: https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-privileged-endpoint
NEW QUESTION # 23
You deploy an Azure Stack Hub integrated system that contains an Azure App Service deployment. The integrated system uses an Azure Active Directory (Azure AD) identity provider.
You need to provide users with the ability to deploy App Service web apps directly from their GitHub repositories.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-app-service-configure-deployment-sources?vi
NEW QUESTION # 24
You have an Azure Stack Hub integrated system that is enabled for multi-tenancy.
You deploy a new computer named Computer1 that runs Windows 11.
You need to connect to the Azure Stack Hub Resource Manager (user) endpoint from Computer1 by using PowerShell.
Which command should you run?
- A. Add-AzureEnvironment -Name "AzureStackUser" -ArmEndpoint
"https://adminmanagement.region1.fabrikam.com"Connect-AzureRmAccount -EnvironmentName "AzureStackUser" - B. Add-AzEnvironment -Name "AzureStackUser" -ArmEndpoint
"https://adminmanagement.region1.fabrikam.com"
Connect-AzAccount -EnvironmentName "AzureStackUser" - C. Add-AzEnvironment -Name "AzureStackUser" -ArmEndpoint
"https://management.region1.fabrikam.com"
Connect-AzureRmAccount -EnvironmentName "AzureStackUser" - D. Add-AzEnvironment -Name "AzureStackUser" -ArmEndpoint "https://portal.region1.fabrikam.com" Connect-AzAccount -EnvironmentName "AzureStackUser"
Answer: C
Explanation:
Explanation
A DNS entry is created for each endpoint in the external DNS zone that's specified at deployment time. For example, the user portal is assigned the DNS host entry of portal.<region>.<fqdn>.
* Azure Resource Manager (user)
Management.<region>.<fqdn>
Incorrect:
Not C: Portal (user)
Portal.<region>.<fqdn>
Not A, Not D: Azure Resource Manager (administrator)
Adminmanagement.<region>.<fqdn>
Note: Portal (administrator)
Adminportal.<region>.<fqdn>
Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-integrate-endpoints
NEW QUESTION # 25
You have an Azure Stack Hub integrated system that is enabled for multitenancy and uses an Azure Active Directory (Azure AD) tenant named fabrikam.com as an identity provider.
The integrated system has the following guest directory tenants onboarded and enabled for multitenancy:
com
onmicrosoft.com
onmicrosoft.com
You need to verify whether all the guest directory tenants are registered properly.
How should you complete the PowerShell script? To answer, drag the appropriate cmdlet to the correct targets.
Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-enable-multitenancy?view=azs-2008
NEW QUESTION # 26
You need to create User2. The solution must support the planned changes.
What should you use?
- A. HLH
- B. ASZ-ERCS01
- C. the tenant portal
- D. Azure Stack Hub Administrator Resource Management Endpoint
Answer: C
Explanation:
Explanation
Create a new cloudadmin user named User2.
Add a new Azure Stack Hub user account in Azure Active Directory (Azure AD) Before you can test offers and plans and create resources, you'll need a user account for the Azure Stack Hub user portal. You create a user account in your Azure AD tenant, by using the Azure portal or PowerShell.
Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-add-new-user-aad
NEW QUESTION # 27
You have an Azure Stack Hub integrated system. The current VIP pool uses a subnet of 192.168.203.0/24 and has routing configured to use BGP.
In the administrator portal, you receive an alert that the public IP addresses are at 95 percent utilization.
You need to add 192.168.204.0/24 to the public IP address pool.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Connect to the administrator portal.
2 - From the Resource providers blade, select Network, and then view the Public IP pools usage tile.
3 - Select Add IP pool and enter 192.168.204.0/24 as the new IP pool.
Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-add-ips
NEW QUESTION # 28
You have an Azure Stack Hub integrated system.
The retention period for storage accounts is set to 7 days.
A user reports that a storage account named hr12943 was deleted accidentally two days ago.
You need to restore hr12943.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Step 1: Connect to the administrator portal
Find a storage account
The list of storage accounts in the region can be viewed in Azure Stack Hub by following these steps:
1. Sign in to the administrator portal https://adminportal.local.azurestack.external.
2. Select All services > Storage > Storage accounts.
By default, the first 10 accounts are displayed. You can choose to fetch more by clicking the Load more link at the bottom of the list.
Step 2: Open the Storage accounts blade.
Step 3: Select hr12943.
Once you've located the accounts you're interested in viewing, you can select the particular account to view certain details. A new pane opens with the account details. These details include the kind of account, creation time, location, and so on.
Step 4: Select Recover.
Recover a deleted account
You may be in a situation where you need to recover a deleted account.
In Azure Stack Hub, there's a simple way to do that:
* Browse to the storage accounts list. For more information, see Find a storage account at the top of this article.
* Locate that particular account in the list. You may need to filter.
* Check the state of the account. It should say Deleted.
* Select the account, which opens the account details pane. (Step 3 above)
* On top of this pane, locate the Recover button and select it. (Step 4)
* Select Yes to confirm.
Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-manage-storage-accounts
NEW QUESTION # 29
You plan to deploy an Azure Stack Hub integrated system to a datacenter.
You need to connect the top-of-rack (ToR) switches to the existing border devices. The solution must ensure that routes propagate dynamically between the ToR switches and the border devices.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Box 1: BGP
BGP routing
Using a dynamic routing protocol like BGP guarantees that your system is always aware of network changes and facilitates administration. For enhanced security, a password may be set on the BGP peering between the TOR and the Border.
Box 2: Layer 3 uplinks with point-to-point connectivity
To integrate Azure Stack Hub to the network it requires uplinks from the Top-of-Rack switches (ToR) to the nearest switch or router, which on this documentation is referred as Border. The ToRs can be uplinked to a single or a pair of Borders.
The top of rack (TOR) switches require Layer 3 uplinks with Point-to-Point IPs (/30 networks) configured on the physical interfaces. Layer 2 uplinks with TOR switches supporting Azure Stack Hub operations isn't supported Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-border-connectivity
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-network
NEW QUESTION # 30
You plan to deploy an Azure Stack Hub integrated system that will be disconnected from the internet. The integrated system region name is region1, and the external domain is name is contoso.local.
You need to ensure that the generated certificate signing request (CSR) has the correct subjects and subject alternative names (SAN).
Which name must you include in the CSR?
- A. *.hosting.region1.azurestack.local
- B. *.adminhosting.region 1.azurestack.local
- C. graph.local.azurestack.external
- D. graph.region1.contoso.local
Answer: B
Explanation:
Explanation
You can deploy and use Azure Stack Hub without a connection to the internet. However, with a disconnected deployment, you're limited to an Active Directory Federation Services (AD FS) identity store and the capacity-based billing model. Because multitenancy requires the use of Azure Active Directory (Azure AD), multitenancy isn't supported for disconnected deployments.
The implementation of Extension Host requires two wild card SSL certificates, one for the Admin portal and one for the Tenant portal.
Note: Certificate requirements
The extension host implements two new domain namespaces to guarantee unique host entries for each portal extension. The new domain namespaces require two additional wildcard certificates to ensure secure communication.
The table shows the new namespaces and the associated certificates:
Table Description automatically generated
Example:
$regionName = 'east' # The region name for your Azure Stack Hub deployment
$externalFQDN = 'azurestack.contoso.com' # The external FQDN for your Azure Stack Hub deployment Starting Certificate Request Process for Deployment CSR generating for following SAN(s):
*.adminhosting.east.azurestack.contoso.com,*.adminvault.east.azurestack.contoso.com,*.blob.east.azurestack.co Present this CSR to your Certificate Authority for Certificate Generation:
C:\Users\username\Documents\AzureStackCSR\Deployment_east_azurestack_contoso_com_SingleCSR_CertRe Certreq.exe output: CertReq: Request Created Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-disconnected-deployment
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-extension-host-prepare
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-get-pki-certs
NEW QUESTION # 31
You have a Windows Server-based certification authority (CA) and a disconnected Azure Stack Hub integrated system.
You need to issue a certificate that will be used to authenticate a service principal when the service principal accesses Azure Stack Hub resources.
How should you configure the certificate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 32
You have an Azure Stack Hub integrated system that contains a user named User1.
User1 creates a new virtual machine named VM01.
You need to grant User1 console access to VM01.
Which five actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Graphical user interface, application Description automatically generated
NEW QUESTION # 33
You have an Azure Stack Hub integrated system that contains a user named User1.
User1 creates a new virtual machine named VM01.
You need to grant User1 console access to VM01.
Which five actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Graphical user interface, application Description automatically generated
NEW QUESTION # 34
You have an Azure Stack Hub integrated system that has syslog forwarding configured.
You need to remove syslog forwarding and the associated certificate.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-integrate-security?view=azs-2008
NEW QUESTION # 35
You have an Azure Stack Hub integrated system that is enabled for multitenancy.
The Directories list for the integrated system is shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Box 1: 3
3 registered, and one in need of an update.
Note: Update the Azure Stack Hub directories
When an Azure Stack Hub directory update is required, a status of Update Required is shown. For example:
Graphical user interface, application Description automatically generated
To update the directory, select the Directory name checkbox, and then select Update.
Box 2: global administrator of ITHCSubAS2021.onmicrosoft.com
The guest directory ITHCSubAS2021.onmicrosoft.com needs an update.
Update the guest directory
An Azure Stack Hub operator should also inform the guest directory owner that they need to update their directory by using the URL shared for registration.
Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/enable-multitenancy
NEW QUESTION # 36
You plan to deploy an Azure Stack Hub integrated system that will connect to the internet.
You are planning the network design. You plan the address space for the public VIP network and the private network.
Which three additional networks are required for the Azure Stack Hub deployment? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. a storage network
- B. a switch infrastructure network
- C. a BMC network
- D. a DNS network
- E. a hypervisor network
- F. an infrastructure network
Answer: B,C,F
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-network?view=azs-2008
NEW QUESTION # 37
You plan to deploy two Azure Stack Hub integrated systems named AZStack1 and AZStack2.
AZStack1 must meet the following requirements:
* Connect to the Internet.
* Have minimal capital expenditures.
* Use the minimum number of on-premises servers for identity.
* Have no existing licenses for Windows virtual machines deployed.
AZStack2 must meet the following requirements:
* Be disconnected from the Internet.
* Use the minimum number of on-premises servers for identity.
* Support the syndication of Azure Stack Hub Marketplace items.
Which identity provider and licensing model should you use for each integrated system? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-connected-deployment?view=azs-2008
NEW QUESTION # 38
You have an Azure Stack Hub integrated system.
You need to update the integrated system to use a non-Windows NTP service that has a host name of ntp1.contoso.com.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-configure-time?view=azs-2008
NEW QUESTION # 39
You start the update of an Azure Stack Hub integrated system. The Update run details are shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-apply-updates?view=azs-2008
NEW QUESTION # 40
You have an Azure Stack Hub integrated system that is disconnected from the Internet. The integrated system is registered to an Azure Active Directory (Azure AD) tenant named contoso.com.
You need to download the latest Ubuntu image for Azure Stack Hub Marketplace.
How should you complete the PowerShell script? To answer, drag the appropriate cmdlets to the correct targets. Each cmdlet may be used once, more than once, or not at all. You may need to drag and split the bar between panes to scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-download-azure-marketplace-item?view=azs-
Topic 2, Litware Office
Case study
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the button to return to the question.
Overview
Existing Environment
Network Environment
The Litware offices and the Fabrikam office connect by using a private circuit. Each office connects directly to the Internet.
Identity Environment
The Litware network contains an Active Directory forest named litwareinc.com. The forest and an Azure Active Directory (Azure AD) tenant named litwareinc.com are integrated by using Active Directory Federation Services (AD FS). Litware has an enterprise certification authority (CA).
The Azure subscriptions of Litware are associated to the litwareic.com Azure AD tenant.
Fabrikam also has an Azure AD tenant.
Azure Stack Hub Environment
Litware has the following two Azure Stack Hub integrated systems:
* A fully operational integrated system in Boston that connects to the Internet and has the following configurations:
- Is managed by using an administrator management endpoint of:
https://adminportal.eastus.litwareinc.com
- Has an Azure App Service deployment that has two dedicated, large web workers
- Currently uses version 2005 of Azure Stack Hub
* A newly delivered integrated system in Chicago that is disconnected from the Internet and will be managed by using an administrator management endpoint of:
https://adminportal.northcentralus.litwareinc.com
Datacenter Environment
The Chicago datacenter of Litware contains the infrastructure shown in the following table.
Current Problems
During heavy usage, requests to App Service in Boston fail despite low utilization of the web workers.
Requirements
Planned Changes
Litware plans to implement the following changes:
* Deploy an Event Hubs resource provider to the integrated system in Boston.
* Make Azure Functions available to Azure Stack Hub users in Boston.
* Prepare the integrated system in Chicago to be production-ready.
Technical Requirements
Litware identifies the following technical requirements:
* Implement an infrastructure to support Azure Functions on the integrated system in Boston.
* Provision the certificates required to deploy the Event Hubs resource provider to the integrated system in Boston.
* Configure an identity provider for the integrated system in Chicago.
* Locate the IP address of the privileged endpoint (PEP) of the integrated system in Chicago.
* Ensure that only operators have control over the creation of subscriptions on the integrated system in Chicago.
* Provision a certificate to provide access to the Azure Resource Manager endpoint of the integrated system in Chicago.
* Identify which PowerShell setting on CLIENT1 and CLIENT2 must be modified to register the integrated system in Chicago.
* Implement a management app that will use Azure Resource Manager to inventory the resources of the integrated system in Chicago.
Security and Compliance Requirements
Litware has the following security and compliance requirements:
* All infrastructure software must run the latest version, including hotfixes.
* Litware must have control over certificate revocations.
Business Requirements
Litware wants to ensure that the users at Fabrikam have secure access to the workloads on the integrated system in Boston.
Updates and Hotfixes
The current hotfixes and updates available for Azure Stack Hub are:
* 2005
* 2005 hotfix 1
* 2005 hotfix 2
* 2005 hotfix 3
* 2008
* 2008 hotfix 1
* 2008 hotfix 2
* 2011 (latest version)
NEW QUESTION # 41
You plan to deploy two Azure Stack Hub integrated systems named AZStack1 and AZStack2.
AZStack1 must meet the following requirements:
* Connect to the Internet.
* Have minimal capital expenditures.
* Use the minimum number of on-premises servers for identity.
* Have no existing licenses for Windows virtual machines deployed.
AZStack2 must meet the following requirements:
* Be disconnected from the Internet.
* Use the minimum number of on-premises servers for identity.
* Support the syndication of Azure Stack Hub Marketplace items.
Which identity provider and licensing model should you use for each integrated system? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-connected-deployment?view=azs-2008
NEW QUESTION # 42
You have an Azure Stack Hub integrated system that is enabled for multi-tenancy.
You receive an alert that one or more guest Azure Active Directory (Azure AD) tenants requires updates to support new features.
You need to identify which Azure AD tenants you must update.
Which two options can you use? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
- A. the App registrations blade of the public Azure portal
- B. the Gec-AzsDireccoryTenancidentif ier cmdlet
- C. the Gec-AzsAlercs cmdlet
- D. the Get-AzureADTenancDecail cmdlet
- E. the Directories blade of the administrator portal in Azure Stack Hub
- F. the Gec-AzsHealchReporc cmdlet
- G. the User subscriptions blade of the administrator portal in Azure Stack Hub
Answer: E,F
Explanation:
Explanation
E: You can determine whether an update is required for home or guest directories by viewing the directories pane in the admin portal. Each directory listing shows the type of directory. The type can be a home or guest directory, and its status is shown.
F: .Synopsis
Gets the health report of identity application in the Azure Stack home and guest directories DESCRIPTION Gets the health report for Azure Stack identity applications in the home directory as well as guest directories of Azure Stack. Any directories with an unhealthy status need to have their permissions updated.
EXAMPLE
$adminResourceManagerEndpoint = "https://adminmanagement.local.azurestack.external"
$homeDirectoryTenantName = "<homeDirectoryTenant>.onmicrosoft.com"
Get-AzsHealthReport -AdminResourceManagerEndpoint $adminResourceManagerEndpoint `
-DirectoryTenantName $homeDirectoryTenantName -Verbose
Examples.
Example 1: Get details for a tenant
PS C:\>Get-AzureADTenantDetail
ObjectId DisplayName VerifiedDomains
-------- ----------- ---------------
85b5ff1e-0402-400c-9e3c-0f9e965325d1 Coho Vineyard & Winery {class VerifiedDomain {..
Reference: https://learn.microsoft.com/en-us/azure-stack/operator/enable-multitenancy
https://github.com/Azure/AzureStack-Tools/blob/master/Identity/AzureStack.Identity.psm1
NEW QUESTION # 43
You need to configure the Azure Stack Hub infrastructure backups. The solution must meet the Azure Stack Hub requirements.
What should you do in the Azure Stack Hub administrator portal? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Box 1: 4
The infrastructure of the integrated system must be backed up as frequently as possible.
Enable backup for Azure Stack Hub from the administrator portal
The frequency in hours determines how often backups are created. The default value is 12. Scheduler supports a maximum of 12 and a minimum of 4.
Box 2: Azure key vault
The integrated system backups must be retained for 28 days.
Online retention policy. This specifies the time period during which daily, weekly, monthly, and yearly backups are retained in the Azure Site Recovery vault that's associated with the local MABS instance.
Reference:
https://learn.microsoft.com/en-us/azure-stack/operator/azure-stack-backup-enable-backup-console
https://learn.microsoft.com/en-us/azure/architecture/hybrid/azure-stack-backup
NEW QUESTION # 44
......
Microsoft AZ-600 certification exam is designed to test the skills and knowledge of IT professionals who are responsible for configuring and operating hybrid cloud environments using Microsoft Azure Stack Hub. AZ-600 exam covers a range of topics, including deploying and configuring infrastructure, managing and monitoring resources, configuring identity and security, and implementing Azure Stack Hub solutions.
To prepare for the AZ-600 exam, candidates should have experience with Azure Stack Hub infrastructure, including deploying and managing virtual machines, storage solutions, and networking. They should also have experience with Azure Stack Hub administration, including backup and disaster recovery, patching and updating, and access control. Candidates may also benefit from taking training courses or studying relevant documentation, such as the Azure Stack Hub documentation and Microsoft's Azure Stack Hub Operator Associate certification guide.
Latest 100% Passing Guarantee - Brilliant AZ-600 Exam Questions PDF: https://www.test4sure.com/AZ-600-pass4sure-vce.html
AZ-600 Exam Dumps - Try Best AZ-600 Exam Questions: https://drive.google.com/open?id=16lN3gXEOSPevSYQnnqISZQ9rD8AvU2kF