You have a hybrid Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table

HOTSPOT

You have a hybrid Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

You have an Azure Virtual Desktop host pool. All the session hosts have a folder named C:Folder1.

You create an FSLogix Application Masking rule as shown in the following exhibit.

You create assignments for the Application Masking rule as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Graphical user interface, text

Description automatically generated

References:

https://docs.microsoft.com/en-us/fslogix/application-masking-rules-ht

https://docs.microsoft.com/en-us/fslogix/application-masking-users-groups-ht

Which resources can you back up using Azure Backup to Vault1?

You have an Azure subscription that contains the resources shown in the following table.

You create a recovery services vault named Vault1.

Which resources can you back up using Azure Backup to Vault1?
A . AVDVM-0 only
B. AVDVM-0 and share1 only
C. AVDVM-0, Image1 and Image2 only
D. AVDVM-0. share1 and Image1 only
E. AVDVM-0. share1. Image1 and Image2

Answer: B

Explanation:

https://docs.microsoft.com/en-us/azure/backup/backup-overview#what-can-i-back-up Operational backup of blobs is a local backup solution. So the backup data isn’t transferred to the Backup vault

What should you do?

You have a Azure Virtual Desktop host pool named Pool1 that contains three session hosts. The session hosts are configured to use FSLogtx profile containers. You need to configure Cloud Cache on the session hosts.

What should you do?
A . Remove VHDlocations entries from the Windows registry.
B. Configure FSLogtx Office Container.
C. Add VHDlocations entries to the Windows registry.
D. Uninstall the FSLogix agent

Answer: A

Explanation:

Reference: https://docs.microsoft.com/en-us/fslogix/configure-cloud-cache-tutorial

What should you use?

Topic 1, Contoso. Ltd

Case study

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.

Overview

Contoso, Ltd. is a law firm that has a main office in Montreal and branch offices in Paris and Seattle. The Seattle branch office opened recently.

Contoso has an Azure subscription and uses Microsoft 365.

Existing Infrastructure. Active Directory

The network contains an on-premises Active Directory domain named contoso.com and an Azure Active Directory (Azure AD) tenant. One of the domain controllers runs as an Azure virtual machine and connects to a virtual network named VNET1. All internal name resolution is provided by DNS server that run on the domain controllers.

The on-premises Active Directory domain contains the organizational units (OUs) shown in the following table.

The on-premises Active Directory domain contains the users shown in the following table.

The Azure AD tenant contains the cloud-only users shown in the following table.

Existing Infrastructure. Network Infrastructure

All the Azure virtual networks are peered. The on-premises network connects to the virtual networks.

All servers run Windows Server 2019. All laptops and desktop computers run Windows 10 Enterprise.

Since users often work on confidential documents, all the users use their computer as a client for connecting to Remote Desktop Services (RDS).

In the West US Azure region, you have the storage accounts shown in the following table.

Existing Infrastructure. Remote Desktop Infrastructure

Contoso has a Remote Desktop infrastructure shown in the following table.

Requirements. Planned Changes

Contoso plans to implement the following changes:

– Implement FSLogix profile containers for the Paris offices.

– Deploy a Windows Virtual Desktop host pool named Pool4.

– Migrate the RDS deployment in the Seattle office to Windows Virtual Desktop in the West US Azure region.

Requirements. Pool4 Configuration

Pool4 will have the following settings:

– Host pool type: Pooled

– Max session limit: 7

– Load balancing algorithm: Depth-first

– mages: Windows 10 Enterprise multi-session

– Virtual machine size: Standard D2s v3

– Name prefix: Pool4

– Number of VMs: 5

– Virtual network: VNET4

Requirements. Technical Requirements

Contoso identifies the following technical requirements:

– Before migrating the RDS deployment in the Seattle office, obtain the recommended deployment configuration based on the current RDS utilization.

– For the Windows Virtual Desktop deployment in the Montreal office, disable audio output in the device redirection settings.

– For the Windows Virtual Desktop deployment in the Seattle office, store the FSLogix profile containers in Azure Storage.

– Enable Operator2 to modify the RDP Properties of the Windows Virtual Desktop deployment in the Montreal office.

– From a server named Server1, convert the user profile clicks to the FSLogix profile containers.

– Ensure that the Pool1 virtual machines only run during business hours.

– Use the principle of least privilege.

You need to configure the virtual machines that have the Pool1 prefix. The solution must meet the technical requirements.

What should you use?
A . a Windows Virtual Desktop automation task
B. Virtual machine auto-shutdown
C. Service Health in Azure Monitor
D. Azure Automation

Answer: A

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/logic-apps/create-automation-tasks-azure-resources

Which command should you run first?

HOTSPOT

You have an Azure virtual machine named VM1 that runs Windows 10 Enterprise multi-session.

You plan to add language packs to VM1 and create a custom image of VM1 for a Windows Virtual Desktop host pool.

You need to ensure that modern apps can use the additional language packs when you deploy session hosts by using the custom image.

Which command should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Answer:

What should you configure?

You have a Windows Virtual Desktop host pool named Pool1 and an Azure Automation account named account1. Pool1 is integrated with an Azure Active Directory Domain Services (Azure AD DS) managed domain named contoso.com.

You plan to configure scaling for Pool1 by using Azure Automation runbooks.

You need to authorize the runbooks to manage the scaling of Pool1. The solution must minimize administrative effort.

What should you configure?
A . a managed identity in Azure Active Directory (Azure AD)
B. a group Managed Service Account (gMSA) in Azure AD DS
C. a Connections shared resource in Azure Automation
D. a Run As account in Azure Automation

Answer: A

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/virtual-desktop/set-up-scaling-script

Which outbound URL and outbound port should you configure to ensure that the host machines maintain Windows activation?

HOTSPOT

You have an Azure Virtual Desktop deployment.

You are configuring the outbound firewall settings for the host pool.

Which outbound URL and outbound port should you configure to ensure that the host machines maintain Windows activation? To answer, select the appropriate options In the answer area. NOTE: Each correct selection is worth one point.

Answer:

Which two actions should you perform?

You need to implement network security to meet the security requirements and the performance requirements.

Which two actions should you perform? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
A . Deploy two Azure Firewall instances and Azure Firewall Manager.
B. Filter traffic by using outbound rules.
C. Filter traffic by using infrastructure rules.
D. Filter traffic by using inbound rules.
E. Deploy a network security group (NSG) and two application security groups.
F. Deploy an Azure Firewall instance and Azure Firewall Manager.

Answer: A,B

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/firewall/protect-windows-virtual-desktop

Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have the following:

✑ A Microsoft 365 E5 tenant

✑ An on-premises Active Directory domain

✑ A hybrid Azure Active Directory (Azure AD) tenant

✑ An Azure Active Directory Domain Services (Azure AD DS) managed domain

✑ An Azure Virtual Desktop deployment

The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune.

You need to configure the security settings for the Microsoft Edge browsers on the personal desktops.

Solution: You configure a configuration profile in Intune.

Does this meet the goal?
A . Yes
B. No

Answer: A

Explanation:

Reference: https://docs.microsoft.com/en-us/mem/intune/fundamentals/azure-virtual-desktop

Which three actions should you perform?

You have a Azure Virtual Desktop deployment that uses Microsoft 355 cloud services including Microsoft Teams.

Users use the Remote Desktop client to connect to the deployment from computers that run Windows 10

You need to support audio and video in Azure Virtual Desktop and provide the users with access to Microsoft Teams calling and meeting features.

Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A . Install the Microsoft Teams WebSocket Service on the Windows 10 computers
B. Configure the IsVWDEnvironment registry key on the Windows 10 computers
C. Configure the isWVDEnvironment registry key on the virtual machines
D. Install the Microsoft Teams desktop app on the Windows 10 computers
E. Install the Microsoft Teams WebSocket Service on the virtual machines
F. Install the Microsoft Teams desktop app on the virtual machines

Answer: B,D,E

Explanation:

Reference: https://docs.microsoft.com/en-us/azure/virtual-desktop/teams-on-avd