Microsoft Configuring and Operating Microsoft Azure Virtual Desktop (AZ-140) Free Practice Test
Question 1
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1.
Pool1 contains two session hosts that are Microsoft Entra joined.
You need to configure single sign-on (SSO) to connect to the session hosts. The solution must enable Microsoft Entra authentication for Remote Desktop Protocol (RDP) in the Microsoft Entra tenant.
Which application requires that you modify the remoteDesktopSecurityConfiguration object?
Pool1 contains two session hosts that are Microsoft Entra joined.
You need to configure single sign-on (SSO) to connect to the session hosts. The solution must enable Microsoft Entra authentication for Remote Desktop Protocol (RDP) in the Microsoft Entra tenant.
Which application requires that you modify the remoteDesktopSecurityConfiguration object?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 2
You need to configure a host pool to automatically assign users to Virtual Machines. Complete the following PowerShell cmdlet to meet the goal.
_______________ -ResourceGroupName <resourcegroupname> -Name <hostpoolname> - PersonalDesktopAssignmentType Automatic
_______________ -ResourceGroupName <resourcegroupname> -Name <hostpoolname> - PersonalDesktopAssignmentType Automatic
Correct Answer: A
Question 3
Case Study 2 - Litware, Inc
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.

All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.

Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the

Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.

Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.

Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host

pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Azure Virtual Desktop connections from the Boston and

Chennai offices.
Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.

Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.

Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Azure Virtual Desktop apps.

Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.

Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.

Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual

Desktop infrastructure.
Use built-in groups for delegation.

Delegate the management of app groups to Admin2, including the ability to publish app groups

to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to

the app groups.
Minimize administrative effort to manage network security.

Use the principle of least privilege.

Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a

Azure Virtual Desktop host pool.
Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the

custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.

User Profile Requirements
Litware identifies the following user profile requirements:
* In storage1, store user profiles for the Boston office users.
* Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
* Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
Hotspot Question
You need to recommend a DNS infrastructure that meets the performance requirements.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.

All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.

Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the

Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.

Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.

Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host

pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Azure Virtual Desktop connections from the Boston and

Chennai offices.
Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.

Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.

Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Azure Virtual Desktop apps.

Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.

Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.

Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual

Desktop infrastructure.
Use built-in groups for delegation.

Delegate the management of app groups to Admin2, including the ability to publish app groups

to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to

the app groups.
Minimize administrative effort to manage network security.

Use the principle of least privilege.

Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a

Azure Virtual Desktop host pool.
Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the

custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.

User Profile Requirements
Litware identifies the following user profile requirements:
* In storage1, store user profiles for the Boston office users.
* Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
* Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
Hotspot Question
You need to recommend a DNS infrastructure that meets the performance requirements.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
https://azure.microsoft.com/en-us/services/virtual-desktop/assessment
Question 4
You have an Azure subscription that is linked to a Microsoft Entra hybrid tenant named contoso.com. The subscription contains the resources shown in the following table.

You create a new Azure Virtual Desktop host pool named HP01.
You plan to deploy new session hosts to HP01. The session hosts will be connected to VNet01.
You need to ensure that the new session hosts can join contoso.com. The solution must minimize administrative effort.
What should you configure first?

You create a new Azure Virtual Desktop host pool named HP01.
You plan to deploy new session hosts to HP01. The session hosts will be connected to VNet01.
You need to ensure that the new session hosts can join contoso.com. The solution must minimize administrative effort.
What should you configure first?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 5
Hotspot Question
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1.
You are adding Microsoft Entra joined session hosts to Pool1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

You have an Azure Virtual Desktop deployment that contains a host pool named Pool1.
You are adding Microsoft Entra joined session hosts to Pool1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Correct Answer:

Question 6
You have an Azure subscription that contains the storage accounts shown in the following table.

You deploy Azure Virtual Desktop. All the session hosts in the deployment are joined to Active Directory.
You need to implement FSLogix profile containers.
Which storage accounts can you use to store the profile containers?

You deploy Azure Virtual Desktop. All the session hosts in the deployment are joined to Active Directory.
You need to implement FSLogix profile containers.
Which storage accounts can you use to store the profile containers?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 7
Case Study 1 - Contoso, Ltd
Overview
Contoso, Ltd. is a law firm that has a main office in Montreal and branch offices in Paris and Seattle. The Seattle branch office opened recently.
Contoso has an Azure subscription and uses Microsoft 365.
Existing Infrastructure. Active Directory
The network contains an on-premises Active Directory domain named contoso.com and an Azure Active Directory (Azure AD) tenant. One of the domain controllers runs as an Azure virtual machine and connects to a virtual network named VNET1. All internal name resolution is provided by DNS server that run on the domain controllers.
The on-premises Active Directory domain contains the organizational units (OUs) shown in the following table.

The on-premises Active Directory domain contains the users shown in the following table.

The Azure AD tenant contains the cloud-only users shown in the following table.

Existing Infrastructure. Network Infrastructure
All the Azure virtual networks are peered. The on-premises network connects to the virtual networks.
All servers run Windows Server 2019. All laptops and desktop computers run Windows 10 Enterprise.
Since users often work on confidential documents, all the users use their computer as a client for connecting to Remote Desktop Services (RDS).
In the West US Azure region, you have the storage accounts shown in the following table.

Existing Infrastructure. Remote Desktop Infrastructure
Contoso has a Remote Desktop infrastructure shown in the following table.

Requirements. Planned Changes
Contoso plans to implement the following changes:
- Implement FSLogix profile containers for the Paris offices.
- Deploy a Azure Virtual Desktop host pool named Pool4.
- Migrate the RDS deployment in the Seattle office to Azure Virtual
Desktop in the West US Azure region.
Requirements. Pool4 Configuration
Pool4 will have the following settings:
- Host pool type: Pooled
- Max session limit: 7
- Load balancing algorithm: Depth-first
- Images: Windows 10 Enterprise multi-session
- Virtual machine size: Standard D2s v3
- Name prefix: Pool4
- Number of VMs: 5
- Virtual network: VNET4
Requirements. Technical Requirements
Contoso identifies the following technical requirements:
- Before migrating the RDS deployment in the Seattle office, obtain the recommended deployment configuration based on the current RDS utilization.
- For the Azure Virtual Desktop deployment in the Montreal office,
disable audio output in the device redirection settings.
- For the Azure Virtual Desktop deployment in the Seattle office, store the FSLogix profile containers in Azure Storage.
- Enable Operator2 to modify the RDP Properties of the Azure Virtual
Desktop deployment in the Montreal office.
- From a server named Server1, convert the user profile clicks to the
FSLogix profile containers.
- Ensure that the Pool1 virtual machines only run during business
hours.
- Use the principle of least privilege.
You need to configure the virtual machines that have the Pool1 prefix. The solution must meet the technical requirements.
What should you use?
Overview
Contoso, Ltd. is a law firm that has a main office in Montreal and branch offices in Paris and Seattle. The Seattle branch office opened recently.
Contoso has an Azure subscription and uses Microsoft 365.
Existing Infrastructure. Active Directory
The network contains an on-premises Active Directory domain named contoso.com and an Azure Active Directory (Azure AD) tenant. One of the domain controllers runs as an Azure virtual machine and connects to a virtual network named VNET1. All internal name resolution is provided by DNS server that run on the domain controllers.
The on-premises Active Directory domain contains the organizational units (OUs) shown in the following table.

The on-premises Active Directory domain contains the users shown in the following table.

The Azure AD tenant contains the cloud-only users shown in the following table.

Existing Infrastructure. Network Infrastructure
All the Azure virtual networks are peered. The on-premises network connects to the virtual networks.
All servers run Windows Server 2019. All laptops and desktop computers run Windows 10 Enterprise.
Since users often work on confidential documents, all the users use their computer as a client for connecting to Remote Desktop Services (RDS).
In the West US Azure region, you have the storage accounts shown in the following table.

Existing Infrastructure. Remote Desktop Infrastructure
Contoso has a Remote Desktop infrastructure shown in the following table.

Requirements. Planned Changes
Contoso plans to implement the following changes:
- Implement FSLogix profile containers for the Paris offices.
- Deploy a Azure Virtual Desktop host pool named Pool4.
- Migrate the RDS deployment in the Seattle office to Azure Virtual
Desktop in the West US Azure region.
Requirements. Pool4 Configuration
Pool4 will have the following settings:
- Host pool type: Pooled
- Max session limit: 7
- Load balancing algorithm: Depth-first
- Images: Windows 10 Enterprise multi-session
- Virtual machine size: Standard D2s v3
- Name prefix: Pool4
- Number of VMs: 5
- Virtual network: VNET4
Requirements. Technical Requirements
Contoso identifies the following technical requirements:
- Before migrating the RDS deployment in the Seattle office, obtain the recommended deployment configuration based on the current RDS utilization.
- For the Azure Virtual Desktop deployment in the Montreal office,
disable audio output in the device redirection settings.
- For the Azure Virtual Desktop deployment in the Seattle office, store the FSLogix profile containers in Azure Storage.
- Enable Operator2 to modify the RDP Properties of the Azure Virtual
Desktop deployment in the Montreal office.
- From a server named Server1, convert the user profile clicks to the
FSLogix profile containers.
- Ensure that the Pool1 virtual machines only run during business
hours.
- Use the principle of least privilege.
You need to configure the virtual machines that have the Pool1 prefix. The solution must meet the technical requirements.
What should you use?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 8
You are designing an Azure Virtual Desktop deployment.
You identify the network latency between the locations where users reside and the planned deployment.
What should you use to identify the best Azure region to deploy the host pool?
You identify the network latency between the locations where users reside and the planned deployment.
What should you use to identify the best Azure region to deploy the host pool?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 9
Hotspot Question
You have an Azure subscription that contains an Azure Virtual Desktop deployment. All the session hosts in the deployment are joined to Active Directory.
You plan to implement Quality of Service (QoS) for the deployment by using Group Policy You need to configure a QoS policy that will tag Remote Desktop Services (RDS) traffic for Expedited Forwarding (EF).
Which DSCP value should you specify, and which executable should you tag? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains an Azure Virtual Desktop deployment. All the session hosts in the deployment are joined to Active Directory.
You plan to implement Quality of Service (QoS) for the deployment by using Group Policy You need to configure a QoS policy that will tag Remote Desktop Services (RDS) traffic for Expedited Forwarding (EF).
Which DSCP value should you specify, and which executable should you tag? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: 46
Implement Quality of Service (QoS) for Azure Virtual Desktop
Insert DSCP markers
You could implement QoS using a Group Policy Object (GPO) to direct session hosts to insert a DSCP marker in IP packet headers identifying it as a particular type of traffic. Routers and other network devices can be configured to recognize these markings and put the traffic in a separate, higher-priority queue.
We recommend using DSCP value 46 that maps to Expedited Forwarding (EF) DSCP class.
Box 2: svchost.exe
[...] select Only applications with this executable name and enter the name svchost.exe, and then select Next. This setting instructs the policy to only prioritize matching traffic from the Remote Desktop Service.
Reference:
https://learn.microsoft.com/en-us/azure/virtual-desktop/rdp-quality-of-service-qos
Question 10
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have an Azure subscription that contains a virtual network named VNet1, a storage account named storage1, and five Azure Virtual Desktop session hosts. VNet1 and storage1 are in the East US Azure region. The session hosts are connected to VNet1.
In storage1, you create an Azure Files share named share1.
You need to ensure that the session hosts connect to share1 by using the Microsoft backbone network.
Solution: You add a service endpoint to VNet1.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have an Azure subscription that contains a virtual network named VNet1, a storage account named storage1, and five Azure Virtual Desktop session hosts. VNet1 and storage1 are in the East US Azure region. The session hosts are connected to VNet1.
In storage1, you create an Azure Files share named share1.
You need to ensure that the session hosts connect to share1 by using the Microsoft backbone network.
Solution: You add a service endpoint to VNet1.
Does this meet the goal?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 11
Hotspot Question
You have a Microsoft Entra hybrid tenant that contains the users shown in the following table.

You have an Azure Virtual Desktop deployment that contains the host pools shown in the following table.

Which users can sign in to the session hosts of each pool? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft Entra hybrid tenant that contains the users shown in the following table.

You have an Azure Virtual Desktop deployment that contains the host pools shown in the following table.

Which users can sign in to the session hosts of each pool? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:
