exam questions

Exam AZ-140 All Questions

View all questions & answers for the AZ-140 exam

Exam AZ-140 topic 3 question 11 discussion

Actual exam question from Microsoft's AZ-140
Question #: 11
Topic #: 3
[All AZ-140 Questions]

You have an Azure Active Directory Domain Services (Azure AD DS) managed domain named contoso.com.
You create an Azure Virtual Desktop host pool named Pool1. You assign the Virtual Machine Contributor role for the Azure subscription to a user named Admin1.
You need to ensure that Admin1 can add session hosts to Pool1. The solution must use the principle of least privilege.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Assign Admin1 the Desktop Virtualization Host Pool Contributor role for Pool1
  • B. Assign Admin1 the Desktop Virtualization Session Host Operator role for Pool1
  • C. Add Admin1 to the AAD DC Administrators group
  • D. Assign a Microsoft 365 Enterprise E3 license to Admin1
  • E. Generate a registration token
Show Suggested Answer Hide Answer
Suggested Answer: BE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Krazzy46
Highly Voted 2 years, 9 months ago
Selected Answer: BE
Answer is correct it's B and E if you read the microsoft document properly you will get to know. https://docs.microsoft.com/en-us/azure/virtual-desktop/rbac
upvoted 17 times
KaiUno
2 years, 9 months ago
"users assigned this role can add session hosts to the host pool outside of the Azure portal if they also have the Virtual Machine Contributor role" Nowhere does it say the user also has that role...
upvoted 5 times
afbnfz
2 years, 8 months ago
bro it literally says the user has that role in the 3rd sentence of the question: "You assign the Virtual Machine Contributor role for the Azure subscription to a user named Admin1."
upvoted 21 times
...
...
Jordan_exams
1 year, 6 months ago
If the registration token is valid (generated and not expired). A and E is correct.
upvoted 1 times
...
...
rfelipe
Highly Voted 2 years, 11 months ago
Selected Answer: AE
Correct A and E since - Desktop Virtualization Session Host Operator: This role lets you view and remove session hosts, and change drain mode. You CAN'T ADD session hosts using the Azure portal because you don't have write permission for host pool objects.
upvoted 16 times
OllyThompson
1 year, 6 months ago
You can if you have the Virtual Machine Contributor role, which this question states they do, so i'd go with B and E
upvoted 2 times
...
...
belyo
Most Recent 3 months, 4 weeks ago
Selected Answer: AE
must have the following RBAC: Desktop Virtualization Host Pool Contributor -> to generate reg key Virtual Machine Contributor -> to add session hosts [already had] definitely A & E https://learn.microsoft.com/en-us/azure/virtual-desktop/add-session-hosts-host-pool?tabs=portal%2Cgui&pivots=host-pool-standard#prerequisites:~:text=The%20Azure%20account,Expand%20table
upvoted 3 times
...
sbwdek88
6 months, 1 week ago
Selected Answer: AE
Answer is A & E.
upvoted 1 times
...
e0a5fc3
6 months, 1 week ago
Selected Answer: BE
The Desktop Virtualization Session Host Operator role allows viewing and removing session hosts, and changing drain mode. This role can't add session hosts using the Azure portal because it doesn't have write permission for host pool objects. For adding session hosts outside of the Azure portal, if the registration token is valid (generated and not expired), this role can add session hosts to the host pool "if the Virtual Machine Contributor role is also assigned." (which it states in the question)
upvoted 2 times
...
jeff1988
6 months, 2 weeks ago
Selected Answer: AE
Option B, Assign Admin1 the Desktop Virtualization Session Host Operator role for Pool1, is not necessary in this case because this role primarily allows a user to manage session hosts, including starting, stopping, and restarting them. However, it does not grant the permissions needed to add new session hosts to the pool. The Desktop Virtualization Host Pool Contributor role (Option A) specifically includes the ability to manage the host pool, which encompasses adding session hosts. Therefore, combining this role with the registration token (Option E) ensures Admin1 has the precise permissions required to add session hosts without granting additional, unnecessary privileges.
upvoted 1 times
...
jeff1988
6 months, 2 weeks ago
Option B, Assign Admin1 the Desktop Virtualization Session Host Operator role for Pool1, is not necessary in this case because this role primarily allows a user to manage session hosts, including starting, stopping, and restarting them. However, it does not grant the permissions needed to add new session hosts to the pool. The Desktop Virtualization Host Pool Contributor role (Option A) specifically includes the ability to manage the host pool, which encompasses adding session hosts. Therefore, combining this role with the registration token (Option E) ensures Admin1 has the precise permissions required to add session hosts without granting additional, unnecessary privileges.
upvoted 1 times
...
RabbitB
7 months, 2 weeks ago
Selected Answer: AE
Desktop Virtualization Session Host Operator role: This role can't add session hosts using the Azure portal because it doesn't have write permission for host pool objects. For adding session hosts outside of the Azure portal, if the registration token is valid (generated and not expired), this role can add session hosts to the host pool if the Virtual Machine Contributor role is also assigned. https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac#desktop-virtualization-session-host-operator The answer must be A & E
upvoted 1 times
...
pissbang
11 months, 1 week ago
A & E Not B because, The Desktop Virtualization User Session Operator role allows sending messages, disconnecting sessions, and using the logoff function to sign users out of a session host. However, this role doesn't allow host pool or session host management like removing a session host, changing drain mode, and so on.
upvoted 2 times
...
[Removed]
1 year ago
Selected Answer: AE
I'll go for A&E because the user has already the "Virtual Machine Contributor" role and as the MS doc clearly states that: "The Desktop Virtualization Session Host Operator role allows viewing and removing session hosts, and changing drain mode. This role can't add session hosts using the Azure portal because it doesn't have write permission for host pool objects. For adding session hosts outside of the Azure portal, if the registration token is valid (generated and not expired), this role can add session hosts to the host pool if the Virtual Machine Contributor role is also assigned" Also the question demands that the solution must use the principle of least privilege. https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac#desktop-virtualization-session-host-operator
upvoted 1 times
...
kapankaj
1 year, 1 month ago
Selected Answer: BE
Answer BE is correct. Microsoft article clearly states that: The Desktop Virtualization Session Host Operator role allows viewing and removing session hosts, and changing drain mode So it mandatory to have operator role assigned.
upvoted 1 times
...
ESAJRR
1 year, 4 months ago
Selected Answer: BE
B. Assign Admin1 the Desktop Virtualization Session Host Operator role for Pool1 E. Generate a registration token
upvoted 1 times
...
RDIO
1 year, 7 months ago
Selected Answer: BE
"You assign the Virtual Machine Contributor role for the Azure subscription to a user named Admin1. You need to ensure that Admin1 can add session hosts to Pool1. The solution must use the principle of least privilege." - To follow this principle B+E are the correct ones. Check the link I've put below and you will come to the same conclusion. https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac#desktop-virtualization-session-host-operator:~:text=If%20the%20registration%20token%20is%20valid%20(generated%20and%20not%20expired)%2C%20users%20assigned%20this%20role%20can%20add%20session%20hosts%20to%20the%20host%20pool%20outside%20of%20the%20Azure%20portal%20if%20they%20also%20have%20the%20Virtual%20Machine%20Contributor%20role.
upvoted 2 times
...
katayama
1 year, 8 months ago
Selected Answer: AE
E. Generate a registration token. is required. and to generate a registration token, A. Desktop Virtualization Session Host Operator is required role. (Microsoft.DesktopVirtualization/hostpools/retrieveRegistrationToken/action is the required action and B. Desktop Virtualization Session Host Operator dont have this action) https://learn.microsoft.com/azure/virtual-desktop/rbac#desktop-virtualization-host-pool-contributor https://learn.microsoft.com/azure/role-based-access-control/resource-provider-operations#microsoftdesktopvirtualization https://learn.microsoft.com/azure/virtual-desktop/rbac#desktop-virtualization-session-host-operator
upvoted 2 times
...
[Removed]
1 year, 9 months ago
Selected Answer: BE
Answer B and E meets the requirement of Least Privilege. Very tricky question! Question states that you have assigned the "Virtual Machine Contributor" role for the subscription to Admin1. So with a valid token and "Desktop Virtualization Session Host operator" role Admin1 can add session hosts outside of the Azure Portal. (PowerShell or CLI) https://docs.microsoft.com/en-us/azure/virtual-desktop/rbac Desktop Virtualization Session Host Operator The Desktop Virtualization Session Host Operator role allows users to view and remove session hosts, as well as change drain mode. Users can't add session hosts using the Azure portal because they don't have write permission for host pool objects. ****If the registration token is valid (generated and not expired), users assigned this role can add session hosts to the host pool outside of the Azure portal**** if they also have the ****Virtual Machine Contributor role****.
upvoted 6 times
...
Toschu
1 year, 10 months ago
Selected Answer: BE
A. Assign Admin1 the "Desktop Virtualization Host Pool Contributor" role for Pool1. This role provides permissions to create and manage host pools and session hosts in Azure Virtual Desktop. E. Generate a registration token. The registration token is required for adding session hosts to a host pool in Azure Virtual Desktop. The Admin1 can use this token to register new session hosts to Pool1. Option B would allow for management of individual session hosts, but not for adding new hosts to the pool. Option C is not required for managing Azure Virtual Desktop, as it pertains to Azure AD DS administration. Option D involves assigning a license which is not directly related to the task of adding session hosts to an Azure Virtual Desktop host pool.
upvoted 2 times
...
poullb
1 year, 11 months ago
Selected Answer: BE
BE - Resposta Correta. Desktop Virtualization Session Host Operator → "If the registration token is valid (generated and not expired), users assigned this role can add session hosts to the host pool outside of the Azure portal if they also have the Virtual Machine Contributor role" https://learn.microsoft.com/pt-br/azure/virtual-desktop/rbac
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago