Deploy & manage compute
You are deploying two VMs that must remain available if a single Azure datacenter (physical location) fails, and you want the strongest infrastructure-level protection within one region. How should you deploy them?
- AOn a single VM with Premium SSD disks
- BIn the same proximity placement group
- CAcross multiple availability zonesCorrect
- DIn a single availability set
Why: Availability zones are physically separate datacenters within a region, so spreading VMs across zones protects against the failure of an entire datacenter. Availability sets only protect against rack-level (fault domain) and update failures within one datacenter. A proximity placement group reduces latency but does not add fault isolation, and a single VM has no redundancy.
Manage identities & governance
You need to grant a support engineer the ability to reset passwords and manage user accounts in Microsoft Entra ID, but not manage Azure resources like virtual machines. Which type of role assignment is appropriate?
- AAn Azure RBAC role such as Owner at the resource group scope
- BA custom Azure Policy definition assigned to the tenant
- CA Microsoft Entra role such as User AdministratorCorrect
- DAn Azure RBAC role such as Contributor at the subscription scope
Why: Microsoft Entra roles (like User Administrator) control access to Entra ID resources such as users, groups, and directory settings. Azure RBAC roles (Contributor, Owner) control access to Azure resources like VMs and storage, which is not what is needed here. The two role systems are separate, so managing directory objects requires an Entra role, not an RBAC assignment.