Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

You have an Azure Virtual Desktop deployment that contains a host pool named Pool1

Pool1 contains two session hosts that are Microsoft Entra joined.

You need to configure single sign-on (SSO) to connect to the session hosts. The solution must enable Microsoft Entra authentication for Remote Desktop Protocol (RDP) in the Microsoft Entra tenant.

Which application requires that you modify the remoteDesktopSecurityConfiguration object?

A.

Windows 365

B.

Azure Virtual Desktop

C.

Windows Cloud Login

D.

Microsoft Azure Windows Virtual Machine Sign-in

You have an Azure Virtual Desktop deployment that contains a host pool named HostPool1.

You plan to deploy session hosts to HostPool1 as shown in the following table.

Each session host must support up to 15 concurrent users.

You need to recommend which operating system version to deploy from Azure Marketplace to the session hosts.

What should you recommend for each session host? To answer, select the appropriate options in the answer area.

You deploy multiple Windows Virtual Desktop session hosts that have only private IP addresses.

You need to ensure that administrators can initiate an RDP session to the session hosts by using the Azure portal.

What should you implement?

A.

Remote Desktop Connection Broker (RD Connection Broker)

B.

Azure Application Gateway

C.

Azure Bastion

D.

Remote Desktop Session Host (RD Session Host)

You have an Azure Virtual Desktop deployment.

You need to secure administrative access to session hosts. The solution must require that administrators use the Azure portal to access the session hosts.

What should you include in the solution?

A.

Azure Bastion

B.

Conditional Access policies

C.

Azure Firewall

D.

Microsoft Defender for Cloud

You have an Azure subscription that is linked to a hybrid Microsoft Entra tenant and contains a storage account named storage1.

You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains session hosts that are Microsoft Entra joined.

You plan to implement FSLogix profile containers for the session hosts of Pool1.

In storage1, you create a new Azure Files share named share1.

You need to ensure that share! can store the FSLogix profile containers.

What should you enable for share!?

A.

a security profile set to Maximum compatibility

B.

Microsoft Entra Domain Services

C.

Microsoft Entra Kerberos

D.

a security profile set to Maximum security

You have a Windows Virtual Desktop host pool named Pool1 and an Azure Storage account named Storage1.

Storage1 stores FSLogix profile containers in a share folder named share1.

You create a new group named Group1. You provide Group1 with permission to sign in to Pool1.

You need to ensure that the members of Group1 can store the FSLogix profile containers in share1. The solution must use the principle of least privilege.

Which two privileges should you assign to Group1? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

the Storage Blob Data Contributor role for storage1

B.

the List folder / read data NTFS permissions for share1

C.

the Modify NTFS permissions for share1

D.

the Storage File Data SMB Share Reader role for storage1

E.

the Storage File Data SMB Share Elevated Contributor role for storage1

F.

the Storage File Data SMB Share Contributor role for storage1

You need to create a Conditional Access policy to meet the security require-ments.

How should you configure the policy? To answer, select the appropriate options in the answer area.

What should you configure to meet the networking requirements?

A.

an on-premises data gateway

B.

the Networking settings for the host pool

C.

a Site-to-Site (S2S) VPN connection

D.

a Point-to-Site (P2S) VPN connection

Which type of host pool and load balancing algorithm should you configure to meet the performance requirements? To answer, select the appropriate options in The answer area.

NOTE: Each correct selection is worth one point.

Which two actions should you perform to meet the security requirements for Defender for Endpoint? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A.

Create an app attach image for the Azure Virtual Desktop deployment.

B.

Use a Group Policy Object (GPO) to run an onboarding script from a shared location.

C.

Add a Defender for Endpoint onboarding script to VM1 and run the script at first startup.

D.

Run a Defender for Endpoint onboarding script on VM1 before generalizing the VM1 source image.