Skip to content

AZ-140 Practice Questions

Prepare for AZ-140 with more than an answer.

263 questions in the full set20 sample questionsUpdated Jan 24, 2026
Exam fee
$165 USD
Level
Specialty
Valid for
1 year
Domains covered on the exam 4
  1. Plan and implement an Azure Virtual Desktop infrastructure42%
  2. Plan and implement identity and security17%
  3. Plan and implement user environments and apps22%
  4. Monitor and maintain an Azure Virtual Desktop infrastructure12%
  1. 1

    You are designing a disaster recovery strategy for an Azure Virtual Desktop deployment. The primary deployment is in the East US region. The DR site will be in the West US region. The design must ensure that user profiles are available in the DR site with minimal data loss. Which Azure Files replication option should be used for the file share hosting the FSLogix profiles to support this strategy?

    Show answer details

    Correct answer: D

    Geo-Redundant Storage (GRS) is the appropriate choice for this disaster recovery scenario. GRS asynchronously replicates data to a secondary Azure region (a paired region, in this case West US for East US). In the event of a primary region failure, you can fail over to the secondary region, making the user profile data available to the DR session hosts. LRS and ZRS only provide redundancy within the primary region and would not protect against a full regional outage.

  2. 2

    An administrator is setting up Universal Print to allow users in Azure Virtual Desktop to print to on-premises printers. The on-premises network does not have a direct connection like ExpressRoute or a Site-to-Site VPN to Azure. What component must be installed on an on-premises Windows computer to discover and register local printers with the Universal Print service?

    Show answer details

    Correct answer: B

    The Universal Print connector is a bridge that lets printers without native Universal Print support work with Universal Print. You install the connector app on a Windows machine (client or server) where the printers are installed; it lets the administrator register those printers with Universal Print, reports job and printer status, and fetches print jobs from the cloud service and delivers them to the printers. It communicates with the cloud service, so no VPN or ExpressRoute is needed.

  3. 3

    A company is using Azure Virtual Desktop with Windows 10 multi-session hosts. They want to use Microsoft Defender for Endpoint to protect the session hosts. What is the recommended onboarding method for this scenario to ensure that each session host is correctly registered as a unique device in Defender for Endpoint?

    Show answer details

    Correct answer: D

    For non-persistent VDI scenarios like pooled AVD host pools, Microsoft provides a specific onboarding script and process. This involves including the onboarding script in the golden image. A startup script is then configured to run the onboarding script every time a VM starts. This ensures that each session host, even if recreated from the same image, registers as a distinct object in the Defender for Endpoint portal, preventing duplicate or stale entries.

  4. 4

    True or False: The 'Start VM on Connect' feature is supported for both personal and pooled host pools.

    Show answer details

    Correct answer: A

    True. You can enable Start VM on Connect for session hosts on Azure and Azure Local in personal or pooled host pools. In personal host pools it powers on the session host already assigned (or assignable) to the user. In pooled host pools it powers on a session host only when none are running, and turns on more only when the first reaches its session limit. The Desktop Virtualization Power On Contributor role must be assigned to the host pool's managed identity or the Azure Virtual Desktop service principal.

  5. 5

    An architect is designing the network security for an Azure Virtual Desktop deployment. A key requirement is that all outbound internet traffic from the session hosts must be inspected by a central Azure Firewall instance. The session hosts and the Azure Firewall are in separate subnets within the same virtual network. How should the architect enforce this traffic flow?

    graph TD subgraph VNet subgraph AVD Subnet SH[Session Hosts] end subgraph Firewall Subnet FW[Azure Firewall] end end Internet((Internet)) SH -->|Outbound Traffic| FW FW --> Internet

    Show answer details

    Correct answer: D

    The standard Azure mechanism for forcing traffic from one subnet to a network virtual appliance (like Azure Firewall) is to use a User-Defined Route (UDR). By creating a route table, adding a route for 0.0.0.0/0 (representing all internet-bound traffic), setting the next hop to 'Virtual appliance', and providing the firewall's IP, you override the default system route and ensure all outbound traffic from the AVD subnet is directed to the firewall for inspection.

  6. 6

    A financial services company is deploying a pooled Azure Virtual Desktop host pool for its traders. A key requirement is that all RDP traffic between the clients and session hosts must be encrypted and must not traverse the public internet at any stage, including the connection through the Azure Virtual Desktop service. The company has an ExpressRoute connection (private peering) between their on-premises network and the Azure virtual network where the session hosts reside. Which configuration should be implemented to meet these requirements?

    Show answer details

    Correct answer: A

    With Private Link, a private endpoint for the host pool's connection sub-resource lets both clients and session hosts reach the Azure Virtual Desktop service over private routes. Clients on the on-premises network reach that private endpoint over ExpressRoute or VPN, so remote session traffic stays on the Microsoft network instead of the public internet. RDP is always encrypted with TLS (TLS 1.2 minimum to the service). RDP Shortpath for managed networks alone isn't enough: every connection starts with a TCP reverse-connect transport through the Azure Virtual Desktop gateway's public endpoints and falls back to it if UDP fails. You can combine Shortpath with Private Link by using the host pool's UDP opt-in. Shortpath for public networks uses the internet, and forcing client traffic through a VPN gateway doesn't make the service endpoints private.

  7. 7

    A manufacturing company uses a legacy line-of-business (LOB) application that, when it starts, registers COM components and writes configuration values under the HKEY_LOCAL_MACHINE (HKLM) registry hive. The company packages the application as MSIX and delivers it to users in Azure Virtual Desktop with App Attach to simplify image management. During testing, the application fails at launch with access-denied errors. What is the most likely cause of this issue?

    Show answer details

    Correct answer: C

    An MSIX-packaged app gets a private, virtualized view of the registry. Any attempt by the app to create an HKLM key, or to open one for modification, fails with access denied, so an app that registers its COM components or writes settings under HKLM when it runs breaks. Registry content and COM servers declared inside the package (packaged COM) are supported, so the fix is to repackage the app with its COM registration in the package or to write per-user data to HKCU; otherwise install it in the image. An untrusted signing certificate or missing share permissions would stop the package from being staged or mounted, not cause access-denied errors from a running app.

  8. 8

    You are designing an FSLogix solution for a large enterprise with 10,000 users distributed between offices in the East US and West Europe Azure regions. You must provide a highly available and performant user profile solution that minimizes login times for users in both regions. Which storage and FSLogix configuration should you implement? (Select TWO)

    Show answer details

    Correct answer: A, C

    FSLogix Cloud Cache is designed for this exact scenario. It uses a local cache on the session host and asynchronously replicates profile data to multiple remote locations (CCDLocations), providing both performance and high availability across regions.

    For a multi-region deployment, you need local storage in each region to ensure low-latency access to profile data.

  9. 9

    A university is deploying Azure Virtual Desktop for student labs. To manage costs, they have implemented an autoscaling plan. During peak hours (9 AM to 5 PM), the scaling plan increases the number of active session hosts. However, students are reporting that they are being forcibly logged off at 5 PM when the scaling plan begins to deallocate session hosts. You need to configure the scaling plan to allow students to finish their work before a session host is shut down. Which scaling plan setting should you modify?

    Show answer details

    Correct answer: A

    When "Force logoff users" is enabled for ramp-down, autoscale puts the session host in drain mode, sends the users a notification that they'll be signed out, and signs them out only after the configured wait time (the delay before logging out users and shutting down VMs; RampDownWaitTimeMinute in PowerShell). It then deallocates the VM. Increasing this delay gives students time to save their work. Alternatively, turning off forced sign-out makes autoscale stop only hosts without sessions. Drain mode isn't a separate scaling plan setting; autoscale applies it automatically. The ramp-up start time and the ramp-down load-balancing algorithm don't control when users are signed out.

  10. 10

    You are creating a new custom image for an Azure Virtual Desktop host pool using the Azure VM Image Builder. The image needs to be based on the latest 'Windows 10 Enterprise multi-session, version 22H2' image from the Azure Marketplace, have the FSLogix agent installed, and then be distributed to an Azure Compute Gallery. You need to define the source for the image builder template. Which type should you specify for the source?

    Show answer details

    Correct answer: A

    When the source of an Azure VM Image Builder template is an Azure Marketplace image, the source type is PlatformImage, and you specify the publisher, offer, SKU and version (version can be "latest"). ManagedImage and SharedImageVersion are for existing managed images and Azure Compute Gallery image versions; VHD isn't an Image Builder source type.

Create an account to continue.