Azure Virtual Desktop Specialty Free Sample Questions

20 free sample questions263 in the full practice test

Try simulator

AZ-140 Sample Questions

  1. Question 1

    A financial services company is deploying a pooled Azure Virtual Desktop host pool for its traders. A key requirement is that all RDP traffic between the clients and session hosts must be encrypted and must not traverse the public internet at any stage, including the connection through the Azure Virtual Desktop service. The company has an ExpressRoute connection (private peering) between their on-premises network and the Azure virtual network where the session hosts reside. Which configuration should be implemented to meet these requirements?

    Answer and explanation

    Correct answer: D

    With Private Link, a private endpoint for the host pool's connection sub-resource lets both clients and session hosts reach the Azure Virtual Desktop service over private routes. Clients on the on-premises network reach that private endpoint over ExpressRoute or VPN, so remote session traffic stays on the Microsoft network instead of the public internet. RDP is always encrypted with TLS (TLS 1.2 minimum to the service). RDP Shortpath for managed networks alone isn't enough: every connection starts with a TCP reverse-connect transport through the Azure Virtual Desktop gateway's public endpoints and falls back to it if UDP fails. You can combine Shortpath with Private Link by using the host pool's UDP opt-in. Shortpath for public networks uses the internet, and forcing client traffic through a VPN gateway doesn't make the service endpoints private.

  2. Question 2

    A manufacturing company uses a legacy line-of-business (LOB) application that, when it starts, registers COM components and writes configuration values under the HKEY_LOCAL_MACHINE (HKLM) registry hive. The company packages the application as MSIX and delivers it to users in Azure Virtual Desktop with App Attach to simplify image management. During testing, the application fails at launch with access-denied errors. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: C

    An MSIX-packaged app gets a private, virtualized view of the registry. Any attempt by the app to create an HKLM key, or to open one for modification, fails with access denied, so an app that registers its COM components or writes settings under HKLM when it runs breaks. Registry content and COM servers declared inside the package (packaged COM) are supported, so the fix is to repackage the app with its COM registration in the package or to write per-user data to HKCU; otherwise install it in the image. An untrusted signing certificate or missing share permissions would stop the package from being staged or mounted, not cause access-denied errors from a running app.

  3. Question 3

    Multiple answers

    You are designing an FSLogix solution for a large enterprise with 10,000 users distributed between offices in the East US and West Europe Azure regions. You must provide a highly available and performant user profile solution that minimizes login times for users in both regions. Which storage and FSLogix configuration should you implement? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    For a multi-region deployment, you need local storage in each region to ensure low-latency access to profile data.

    FSLogix Cloud Cache is designed for this exact scenario. It uses a local cache on the session host and asynchronously replicates profile data to multiple remote locations (CCDLocations), providing both performance and high availability across regions.

  4. Question 4

    A university is deploying Azure Virtual Desktop for student labs. To manage costs, they have implemented an autoscaling plan. During peak hours (9 AM to 5 PM), the scaling plan increases the number of active session hosts. However, students are reporting that they are being forcibly logged off at 5 PM when the scaling plan begins to deallocate session hosts. You need to configure the scaling plan to allow students to finish their work before a session host is shut down. Which scaling plan setting should you modify?

    Answer and explanation

    Correct answer: C

    When "Force logoff users" is enabled for ramp-down, autoscale puts the session host in drain mode, sends the users a notification that they'll be signed out, and signs them out only after the configured wait time (the delay before logging out users and shutting down VMs; RampDownWaitTimeMinute in PowerShell). It then deallocates the VM. Increasing this delay gives students time to save their work. Alternatively, turning off forced sign-out makes autoscale stop only hosts without sessions. Drain mode isn't a separate scaling plan setting; autoscale applies it automatically. The ramp-up start time and the ramp-down load-balancing algorithm don't control when users are signed out.

  5. Question 5

    You are creating a new custom image for an Azure Virtual Desktop host pool using the Azure VM Image Builder. The image needs to be based on the latest 'Windows 10 Enterprise multi-session, version 22H2' image from the Azure Marketplace, have the FSLogix agent installed, and then be distributed to an Azure Compute Gallery. You need to define the source for the image builder template. Which type should you specify for the source?

    Answer and explanation

    Correct answer: C

    When the source of an Azure VM Image Builder template is an Azure Marketplace image, the source type is PlatformImage, and you specify the publisher, offer, SKU and version (version can be "latest"). ManagedImage and SharedImageVersion are for existing managed images and Azure Compute Gallery image versions; VHD isn't an Image Builder source type.

  6. Question 6

    True or False: When using FSLogix Profile Containers stored on Azure Files, the storage account must be joined to an Active Directory Domain Services (AD DS) or Microsoft Entra Domain Services domain to enforce user-level permissions.

    Answer and explanation

    Correct answer: B

    False. Azure Files supports three identity sources for identity-based SMB access: on-premises AD DS, Microsoft Entra Domain Services and Microsoft Entra Kerberos. With Microsoft Entra Kerberos, Microsoft Entra ID issues the Kerberos tickets, the storage account isn't joined to an AD DS or Microsoft Entra Domain Services domain, and Microsoft Entra joined or hybrid joined clients don't need line of sight to domain controllers; Microsoft lists it as a fit for FSLogix profiles. With any identity source you still assign share-level permissions and configure directory and file (NTFS) permissions so users can access only their own profile containers. Using the storage account key isn't recommended for production.

  7. Question 7

    Multiple answers

    An administrator is investigating long session connection times reported by users. In Azure Virtual Desktop Insights, the administrator opens the Connection Performance tab and observes that the 95th percentile of "Time to connect" is consistently over 45 seconds. The breakdown shows that the longest delay occurs during the "Logon" stage. Which two factors are most likely contributing to this long logon duration? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    In Azure Virtual Desktop Insights, time to connect is broken down into user route, stack connected, logon, and shell start to shell ready. The logon stage, from when the connection to the host is established to when the shell starts to load, includes loading the user profile, applying Group Policy objects, launching FSLogix (frxsvc) and starting the shell. Slow or under-scaled storage for FSLogix profile containers lengthens profile and FSLogix load time. Many or slow-to-apply GPOs lengthen Group Policy processing. Both directly extend the logon stage. Network latency between the client and the gateway affects the user route and stack connected stages instead.

  8. Question 8

    A retail company is migrating its on-premises VDI environment to Azure Virtual Desktop. They have a custom golden image that is currently a 200 GB VHD file stored in an on-premises file server. The goal is to use this image to deploy session hosts in a new host pool. The administrator has already uploaded the VHD to an Azure Storage account. What is the next step required to make this VHD usable for deploying new session hosts from the Azure portal?

    Answer and explanation

    Correct answer: D

    To deploy Azure VMs from a custom VHD, the VHD must first be used to create a managed image resource in Azure. This managed image acts as a template. Once the managed image is created, it can be selected during the virtual machine creation process in the Azure portal to deploy new session hosts based on that specific image.

  9. Question 9

    You are configuring a personal host pool for a group of developers. The organization has a policy that all Azure VMs must be powered off outside of business hours (9 AM to 6 PM, Monday-Friday) to reduce costs. However, developers occasionally need to work late or on weekends. You need to implement a solution that keeps the VMs deallocated by default but allows a developer to power on their assigned VM on-demand by simply attempting to connect to it. Which feature should you configure on the host pool?

    Answer and explanation

    Correct answer: C

    The 'Start VM on Connect' feature is designed specifically for this use case, primarily with personal host pools. It allows session host VMs to be deallocated to save costs. When a user assigned to a specific VM attempts to connect via their Remote Desktop client, the AVD service intercepts the request, sends a command to power on the VM, and then brokers the connection once the VM is ready. This provides on-demand access while maximizing cost savings.

  10. Question 10

    A government agency is deploying Azure Virtual Desktop. Its security policy requires that RDP port 3389 on the session hosts stays closed by default. Administrators must request access through the Azure portal, access must be opened only to the requesting administrator's IP address for a limited time, and all access requests must be audited. Which Azure service should be implemented to meet all these requirements?

    Answer and explanation

    Correct answer: C

    Just-in-time (JIT) VM access, part of Microsoft Defender for Servers Plan 2 in Microsoft Defender for Cloud, keeps deny rules on the selected management ports (such as RDP 3389) in the network security group and Azure Firewall. When a user with the right Azure RBAC permissions requests access from the Azure portal (or programmatically) and the request is approved, Defender for Cloud allows inbound traffic to the port only from the requester's IP address or range for the specified time, then restores the rules. JIT activity can be audited from the VM's Activity Log. Azure Bastion gives portal-based RDP over TLS 443 without opening 3389, but it doesn't provide request-based, time-limited access.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 263 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon