easymultiple choiceObjective-mapped

Exhibit

Automation notes

VMs: vm-a1, vm-a2, vm-a3
Script requirement:
- Authenticate to Azure Resource Manager
- No password or certificate stored on disk
- Same identity must be used by all three VMs
- Identity must survive VM rebuilds and replacements

Based on the exhibit, three Azure virtual machines run the same automation script. The VMs are rebuilt often, and the team wants one identity that can be reused across all three VMs and retained even if a VM is replaced. Which identity type should the administrator use?

Question 1easymultiple choice
Full question →

Based on the exhibit, three Azure virtual machines run the same automation script. The VMs are rebuilt often, and the team wants one identity that can be reused across all three VMs and retained even if a VM is replaced. Which identity type should the administrator use?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

System-assigned managed identity on each VM, because each VM gets the same identity automatically.

System-assigned identities are unique to each resource and are deleted with that resource. They cannot be shared across multiple VMs and would not survive rebuilds or replacements in the way described.

B

Best answer

A user-assigned managed identity attached to all three VMs.

A user-assigned managed identity is independent of any single VM and can be attached to multiple resources. That makes it ideal when several VMs need the same identity and the identity must survive if a VM is deleted, rebuilt, or replaced during maintenance or scaling.

C

Distractor review

An Azure AD guest user account, because the same account can sign in from every VM.

A guest user account is a human identity and is not the proper pattern for noninteractive automation. It would also introduce password management and lifecycle concerns that the scenario explicitly wants to avoid.

D

Distractor review

A shared storage account key, because it can be used by multiple VMs without extra configuration.

A storage account key is unrelated to Azure Resource Manager authentication and does not meet the requirement for a reusable Azure identity. It would also weaken security because it is a long-lived secret that the team wants to avoid storing on disk.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: A user-assigned managed identity attached to all three VMs. — A user-assigned managed identity is the right answer because it can be created once and attached to multiple VMs. Since it is not tied to a single VM lifecycle, it remains available even if one VM is rebuilt or replaced. This gives the team a reusable, secretless identity for automation across all three machines. Why others are wrong: System-assigned identities are bound to each individual VM, so they cannot serve as one shared identity. A guest user account is a human identity and is inappropriate for automation. A storage key is not an Azure identity and does not address the requirement to authenticate to Azure Resource Manager without storing secrets.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.