AZ-140 sample questions with answers

10 free practice questions for the Microsoft Certified: Azure Virtual Desktop Specialty exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Plan and implement an Azure Virtual Desktop infrastructure

Tailspin Toys is sizing a pooled host pool for 600 knowledge workers. The agreed density is 4 users per session host, and each host will be a StandardD8asv5 with 8 vCPUs. The target region currently has a quota of 1,000 vCPUs for the Dasv5 family in the subscription, and no other workloads use that family. What must you do before deployment?

  1. A.

    Deploy the session hosts across two availability zones so that each zone has its own quota

  2. B.

    Request a quota increase for the standard DASv5 family vCPUs in the target region

  3. C.

    Split the session hosts across two resource groups in the same subscription

  4. D.

    Change the load-balancing algorithm to depth-first so that fewer vCPUs are consumed

Show answer

Answer: B

600 users at 4 per host needs 150 hosts of 8 vCPUs, which is 1,200 vCPUs against a 1,000 vCPU family quota, so the quota must be raised first.

  • A. Availability zones share the regional family quota; zonal spread improves resilience but grants no extra vCPUs.
  • B. 150 hosts at 8 vCPUs equals 1,200 vCPUs, above the 1,000 vCPU family quota, and quota is enforced per subscription, region, and family.
  • C. Compute quota is not scoped to resource groups, so redistributing resources between them leaves the limit unchanged.
  • D. Load balancing only distributes sessions among existing hosts and does not reduce the number of virtual machines required.
Question 2Plan and implement an Azure Virtual Desktop infrastructure

A nightly Azure DevOps pipeline at Fabrikam deploys replacement session hosts with a Bicep file. The registration token must never appear in pipeline logs, in source control, or in the deployment history, and the pipeline must run unattended. How should you supply the token to the deployment?

  1. A.

    Write the token to a tag on the host pool resource and read the tag inside the Bicep file by using the reference function at deployment time

  2. B.

    Store the token in a pipeline variable marked as secret and pass it to the Bicep deployment as an ordinary string parameter without a decorator

  3. C.

    Declare the token parameter with the @secure() decorator and source its value from Azure Key Vault by using the getSecret function on a Key Vault reference in the parent Bicep file

  4. D.

    Store the token as a variable inside the Bicep file and restrict read access to the repository to the platform team only

Show answer

Answer: C

A secure parameter fed by a Key Vault getSecret reference keeps the token out of logs, source control, and the deployment history.

  • A. Tags are plaintext metadata visible to anyone with reader access on the resource, so they must never hold secrets.
  • B. A secret pipeline variable masks pipeline output, but a non-secure parameter value is still written to the deployment history in clear text.
  • C. @secure() removes the value from deployment history and getSecret keeps the plaintext inside Resource Manager rather than on the build agent.
  • D. Hard-coding a credential in a template puts it in source control permanently; repository permissions do not make that acceptable.
Question 3Plan and implement an Azure Virtual Desktop infrastructure

Alpine Ski House deploys host pools in North Europe, East US, and Southeast Asia from one golden image. Each regional deployment creates up to 120 session hosts at a time, and deployment time must stay short in every region. Where should you store the image?

  1. A.

    As a managed image in a North Europe resource group that the deployments in all three regions reference directly

  2. B.

    As a snapshot of the golden virtual machine's operating system disk, shared with each subscription

  3. C.

    In an Azure Compute Gallery, as an image version replicated to all three regions with several replicas per region

  4. D.

    As a VHD file in a geo-redundant storage account from which each regional deployment copies the disk before creating its hosts

Show answer

Answer: C

Azure Compute Gallery is the only option that replicates an image version into each target region and scales deployment throughput through replica count.

  • A. A managed image lives in one region with no replicas, so remote deployments are slow and large parallel batches hit throttling.
  • B. Snapshots are single-region point-in-time disk copies without versioning and are not intended as a mass deployment source.
  • C. Gallery image versions replicate per region and the replica count scales parallel deployments, which is what large multi-region batches need.
  • D. Copying VHDs adds manual staging per region and provides no versioning or parallel-read scaling; GRS improves durability, not deployment locality.
Question 4Plan and implement an Azure Virtual Desktop infrastructure

Garnet Hotels has enabled Microsoft Entra Kerberos on the storage account that hosts FSLogix profiles for hybrid users on Microsoft Entra joined session hosts. Users still get temporary profiles. A Conditional Access policy requires MFA for all cloud apps. Which three actions should you take to complete the configuration? (Choose THREE.)

Choose 3.

  1. A.

    Disable storage account key access so that only Kerberos can be used

  2. B.

    Enable cloud Kerberos ticket retrieval on the session hosts

  3. C.

    Exclude the storage account application from the Conditional Access MFA policy

  4. D.

    Join the storage account to AD DS by running Join-AzStorageAccount

  5. E.

    Grant admin consent to the application registration created for the storage account

Show answer

Answer: B, C, E

After enabling Microsoft Entra Kerberos you must grant admin consent to the storage account's app, exclude that app from MFA policies, and enable CloudKerberosTicketRetrievalEnabled on the session hosts.

  • A. Disabling key access isn't part of the Microsoft Entra Kerberos setup and doesn't fix ticket retrieval.
  • B. Session hosts need CloudKerberosTicketRetrievalEnabled (Intune, Group Policy or registry) to get the cloud Kerberos ticket.
  • C. Microsoft Entra Kerberos doesn't support MFA for the share, so the storage app must be excluded from MFA policies.
  • D. A storage account supports only one identity source, so it can't also be joined to AD DS.
  • E. Admin consent to the storage account's app registration is required so users can obtain tokens and Kerberos tickets.
Question 5Plan and implement an Azure Virtual Desktop infrastructure

Bluewater Ferries is creating the network security group for a new session host subnet. The security team wants to open only what Azure Virtual Desktop requires for users to connect through the standard reverse connect transport. Which inbound rule should the network security group contain for user connections?

  1. A.

    An inbound rule that allows TCP 443 from the WindowsVirtualDesktop service tag

  2. B.

    No inbound rule, because session hosts connect outbound to the service over TCP 443

  3. C.

    An inbound rule that allows TCP 3389 from the Internet service tag

  4. D.

    An inbound rule that allows UDP 3390 from any source address

Show answer

Answer: B

Reverse connect uses only outbound connectivity from the session host to the service over TCP 443, so no inbound port has to be opened for user connections.

  • A. The WindowsVirtualDesktop tag is used for outbound rules to the service; the service does not initiate inbound connections to hosts.
  • B. Reverse connect is outbound-only from the session host over TCP 443, so no inbound NSG rule is needed for user connections.
  • C. Azure Virtual Desktop never needs inbound RDP on 3389, and Microsoft recommends against opening it on session hosts.
  • D. UDP 3390 is only for the optional Shortpath listener on managed networks and should be limited to the private client network.
Question 6Plan and implement an Azure Virtual Desktop infrastructure

Glasswater Tours is provisioning a new premium file share for the profile containers of 500 medium-workload users of a pooled host pool. Using the minimum profile container storage in Microsoft's session host sizing guidelines, what is the smallest capacity you should provision before adding growth headroom?

  1. A.

    About 5 TB, which is 10 GB for each of the 500 users

  2. B.

    About 50 TB, which is 100 GB for each of the 500 users

  3. C.

    About 15 TB, which is 30 GB for each of the 500 users

  4. D.

    About 1.5 TB, which is 3 GB for each of the 500 users

Show answer

Answer: C

Microsoft's sizing tables list a minimum profile container storage of 30 GB per user for light, medium, heavy and power workloads, so 500 users need at least about 15 TB.

  • A. 10 GB per user is below the documented 30 GB minimum and would risk the share filling up.
  • B. 100 GB per user isn't the documented minimum and would over-provision capacity you pay for regardless of use.
  • C. The sizing guidelines list 30 GB minimum profile storage per user, so 500 users need about 15 TB before headroom.
  • D. 3 GB per user is a tenth of the documented minimum profile storage.
Question 7Plan and implement an Azure Virtual Desktop infrastructure

Newly deployed session hosts at Carrow Estates stay unavailable in their host pool, and the network team recently tightened egress filtering on the session host subnet. You need a list, from one of the affected session hosts, of the required Azure Virtual Desktop FQDNs and endpoints that it can't reach. What should you use?

  1. A.

    The Azure Virtual Desktop Agent URL Tool (WVDAgentUrlTool.exe) in the RDAgent installation folder

  2. B.

    avdnettest.exe on the session host to test the STUN and TURN servers

  3. C.

    The Connection Reliability tab of Azure Virtual Desktop Insights for the host pool

  4. D.

    IP flow verify in Azure Network Watcher for a single destination and port

Show answer

Answer: A

The Agent URL Tool ships with the RDAgent on each session host and lists which required FQDNs and endpoints the host can and can't access.

  • A. WVDAgentUrlTool.exe checks every required FQDN and endpoint from the session host and lists those it can't reach.
  • B. avdnettest.exe checks STUN/TURN and NAT for Shortpath, not the agent's required service endpoints.
  • C. Connection Reliability analyses disconnections of existing sessions; unavailable hosts produce no sessions to analyse.
  • D. IP flow verify tests one NSG flow at a time and has no knowledge of the required FQDN list or firewall filtering.
Question 8Plan and implement an Azure Virtual Desktop infrastructure

Kelso Studios has a personal host pool of 60 StandardD8sv5 session hosts for developers who leave IDEs and device emulators running overnight. Profiles stay on each VM's OS disk, and the pool uses neither FSLogix nor App Attach. Finance wants no compute charges while developers are away, and developers want their open applications exactly as they left them each morning. What should you plan?

  1. A.

    Enable hibernation on the VMs and assign a personal scaling plan that hibernates them after users disconnect

  2. B.

    Assign a personal scaling plan that deallocates the VMs when users disconnect, and enable Start VM on Connect for the morning

  3. C.

    Enable Start VM on Connect on the host pool and leave the VMs running when users disconnect

  4. D.

    Convert the developers to a pooled host pool that uses depth-first load balancing

Show answer

Answer: A

Hibernation saves memory to the OS disk and deallocates the VM, so there's no compute charge and applications resume where they were; autoscale for personal host pools can hibernate hosts, and Dsv5 sizes up to 64 GB support it.

  • A. Hibernation preserves memory on the OS disk with no compute charge, and a personal scaling plan can hibernate hosts on disconnect.
  • B. Deallocation stops compute charges but discards memory, so the developers' open applications would be lost.
  • C. Leaving VMs running keeps state but incurs compute charges all night, which Finance ruled out.
  • D. A pooled host pool removes dedicated, persistent desktops, and depth-first doesn't preserve open applications.
Question 9Plan and implement an Azure Virtual Desktop infrastructure

Penrose Mutual stores FSLogix profiles on an Azure Files share that is joined to its AD DS domain. The FSLogix documentation now carries a notice about a Windows Server update from April 2026 that changes the default Kerberos encryption type. What should the team do to avoid profile access failures?

  1. A.

    Switch the share to storage account key authorization for users until RC4 is available again

  2. B.

    Disable Kerberos in the SMB security settings and allow NTLMv2 for the share

  3. C.

    Re-enable RC4 as the only permitted encryption type on every session host

  4. D.

    Upgrade the storage account's Kerberos encryption to AES-SHA1 before the update is installed

Show answer

Answer: D

The April 2026 update changes the default Kerberos encryption type from RC4 to AES-SHA1, and Microsoft says shares hosting FSLogix containers must be upgraded to AES-SHA1 before the update is installed.

  • A. Storage account key access isn't identity-based and can't apply per-user permissions to profile containers.
  • B. Identity-based access to Azure Files requires Kerberos to be enabled in the SMB security settings.
  • C. Keeping RC4 works against the hardening change; Microsoft's guidance is to complete the AES upgrade.
  • D. Microsoft says shares hosting FSLogix containers must be upgraded to AES-SHA1 before installing the update that drops the RC4 default.
Question 10Plan and implement an Azure Virtual Desktop infrastructure

Aldermoor Housing runs Azure Virtual Desktop host pools in two Azure subscriptions and is about to create private endpoints for them for the first time. According to the setup guidance, what must be done in each subscription before Private Link with Azure Virtual Desktop can be used?

  1. A.

    Disable network policies for private endpoints on every session host subnet

  2. B.

    Create a private DNS zone named privatelink.wvd.microsoft.com in the subscription

  3. C.

    Re-register the Microsoft.DesktopVirtualization resource provider in the subscription

  4. D.

    Move the host pools, workspaces and application groups into one resource group

Show answer

Answer: C

Private Link with Azure Virtual Desktop requires you to re-register the Microsoft.DesktopVirtualization resource provider on each subscription you want to use it with.

  • A. Private endpoint network policies are optional settings, not a prerequisite for Azure Virtual Desktop Private Link.
  • B. The private DNS zone is chosen during endpoint creation and can be in any subscription; it isn't a per-subscription prerequisite.
  • C. Microsoft requires re-registering Microsoft.DesktopVirtualization on each subscription before Private Link with Azure Virtual Desktop works.
  • D. Private Link has no requirement for host pools, workspaces and application groups to share a resource group.

Keep going with 502 more AZ-140 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.