SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
AZ-104 · Domain 3

Deploy and manage Azure compute resources practice questions

Deploy and manage Azure compute resources is worth 24% of the AZ-104 exam — the heaviest of the 5 domains. ARM template and Bicep deployments, virtual machines, containers, and Azure App Service. Official weighting 20–25%. 6 fully worked examples are further down this page, answers included.

Exam weight
24%
the heaviest of the 5 domains
Questions
80
across 4 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Deploy and manage Azure compute resources questions, fully explained

Questions from the AZ-104 bank mapped to domain 3, with the answer key and the reasoning behind every option. None of them repeat the examples on the main AZ-104 practice page.

Question 1Deploy and manage Azure compute resources

A resource group named RG-App contains a virtual network, a storage account, and a virtual machine. An administrator deploys an ARM template to RG-App that defines only the virtual network, using Complete mode. What happens to the storage account and the virtual machine?

Choose one.

  • a
    They are left unchanged, because deployments only affect resources defined in the template

    That describes Incremental mode, the default. Complete mode was chosen here specifically to make the group match the template, which means deleting the extras.

  • b
    The deployment fails with a conflict error because the template does not include them

    Complete mode does not fail on undeclared resources — it silently deletes them, which is exactly why it must be used with care.

  • c
    They are moved to a recovery resource group for 14 days before deletion

    There is no recovery holding area for Complete-mode deletions — removed resources are deleted immediately, with no built-in grace period.

  • d
    They are deleted, because Complete mode removes resources in the resource group that are not defined in the template Correct

    In Complete mode, Resource Manager makes the resource group match the template exactly — resources present in the group but absent from the template are deleted.

The concept

ARM deployments run in one of two modes. Incremental (default) adds or updates resources defined in the template and leaves everything else alone. Complete makes the resource group match the template exactly, deleting resources that exist in the group but are not in the template.

Why that’s the answer

Because the deployment used Complete mode and the template defines only the virtual network, the storage account and VM are not in the desired state and are deleted. 'Left unchanged' describes Incremental mode. The deployment does not error on extra resources — silent deletion is the documented (and dangerous) behavior. There is no recovery resource group or grace period for deleted resources.

How to reason it out
  1. Before any Complete-mode deployment, list what the template defines and compare it against the resource group's current contents.
  2. Run the what-if operation ('az deployment group what-if' or -WhatIf) to preview exactly which resources would be deleted.
  3. Only then deploy with '--mode Complete', or keep the default Incremental mode if extra resources must survive.

Exam tip: Complete mode deletes anything in the resource group that the template doesn't define — always preview with what-if first.

ARM Templates and Bicep: AZ-104 Deployment Guide — the lesson that teaches this.

Question 2Deploy and manage Azure compute resources

An administrator runs 'az deployment group create' against a resource group without specifying a deployment mode. The resource group already contains several resources that are not defined in the template. What is the result?

Choose one.

  • a
    The existing undeclared resources are deleted so the resource group matches the template

    That is Complete mode, which must be requested explicitly with --mode Complete — it is never the default.

  • b
    The template's resources are created or updated, and the existing undeclared resources are left unchanged Correct

    Incremental is the default deployment mode — it only acts on resources defined in the template and never touches resources that exist outside it.

  • c
    The deployment is blocked until the administrator chooses a mode interactively

    Deployments never prompt for a mode — Incremental applies automatically when no mode is specified.

  • d
    The deployment fails because the template does not describe the full resource group

    Incremental mode has no requirement that the template describe everything in the group — partial templates are the normal case.

The concept

Incremental mode is the default for every ARM and Bicep deployment. It treats the template as additive: resources in the template are created or updated to match, and anything else in the resource group is ignored.

Why that’s the answer

With no mode specified, Incremental applies, so the undeclared resources survive and only the template's resources are created or updated. Deleting undeclared resources is Complete-mode behavior and requires an explicit flag. There is no interactive mode prompt, and Incremental deployments have no requirement to describe the entire resource group.

How to reason it out
  1. Omit the mode parameter (or pass --mode Incremental) to get additive behavior — this is the safe default.
  2. Verify with the deployment history in the portal that only template-defined resources were touched.
  3. Reserve --mode Complete for cases where the template is intentionally the full source of truth for the group.

Exam tip: Incremental is the default deployment mode — it adds and updates but never deletes undeclared resources.

ARM Templates and Bicep: AZ-104 Deployment Guide — the lesson that teaches this.

Question 3Deploy and manage Azure compute resources

Before deploying an updated Bicep file to a production resource group, an administrator must see exactly which resources would be created, modified, or deleted — without changing anything. Which operation should the administrator use?

Choose one.

  • a
    Template validation ('az deployment group validate')

    Validation checks that the template is syntactically well-formed and would be accepted, but it does not report per-resource changes against current state.

  • b
    The what-if operation ('az deployment group what-if' or New-AzResourceGroupDeployment -WhatIf) Correct

    What-if compares the template against the current state of the resource group and reports every create, modify, and delete before any change is made.

  • c
    Exporting the resource group's template and comparing the files manually

    Exported templates are noisy, auto-generated representations of current state — manually diffing them is error-prone and misses how Resource Manager would actually apply the change.

  • d
    Deploying to production in Complete mode and reviewing the deployment history afterward

    Reviewing history happens after changes are applied — the requirement is a preview with zero changes, and Complete mode could delete production resources.

The concept

The what-if operation is ARM's change-preview feature. It evaluates the template against the target scope's live state and lists the effect on each resource — Create, Modify, Delete, NoChange, or Ignore — without applying anything.

Why that’s the answer

What-if is purpose-built for this requirement: a per-resource change preview with no side effects. Validation only confirms the template is deployable, not what it would change. Manual diffs of exported templates are unreliable and not how Resource Manager evaluates changes. Deploying first and reading history violates the 'without changing anything' constraint — and doing so in Complete mode could destroy resources.

How to reason it out
  1. Run 'az deployment group what-if --resource-group RG --template-file main.bicep' (or add -WhatIf to New-AzResourceGroupDeployment).
  2. Review the color-coded output: Create, Modify, and Delete entries show the exact properties that change.
  3. Once the preview matches expectations, run the same command without what-if to apply the deployment.

Exam tip: Use what-if to preview a deployment's per-resource changes before applying anything — especially before Complete-mode deployments.

ARM Templates and Bicep: AZ-104 Deployment Guide — the lesson that teaches this.

Question 4Deploy and manage Azure compute resources

A Bicep file must create three new resource groups and assign an Azure Policy definition across the subscription. At which scope must this Bicep file be deployed?

Choose one.

  • a
    Resource group scope, using 'az deployment group create' against any existing resource group

    A resource-group-scoped deployment creates resources inside one group — it cannot create new resource groups or assign policy across the subscription.

  • b
    Tenant scope, because policy assignments always require tenant-level rights

    Tenant scope is for cross-subscription concerns like management group creation — a policy assignment over one subscription only needs subscription scope.

  • c
    Subscription scope, using 'az deployment sub create' with targetScope set to 'subscription' Correct

    Resource groups and subscription-wide policy assignments are subscription-level resources — they can only be created by a deployment that targets the subscription scope.

  • d
    Any scope, because Bicep files automatically escalate to the scope each resource requires

    Deployments never escalate scope automatically — the targetScope declared in the file must match the deployment command, and out-of-scope resources cause errors.

The concept

ARM and Bicep deployments run at one of four scopes: resource group, subscription, management group, or tenant. The scope determines which resource types the deployment can create — resource groups themselves and subscription-wide policy assignments are subscription-scope resources.

Why that’s the answer

Creating resource groups and assigning policy across a subscription both require a subscription-scoped deployment, declared with targetScope = 'subscription' and run via 'az deployment sub create' or New-AzSubscriptionDeployment. A resource-group deployment can only place resources inside an existing group. Tenant scope is broader than needed for a single subscription's policy. And scope never escalates automatically — the declared targetScope governs.

How to reason it out
  1. Set 'targetScope = 'subscription'' at the top of the Bicep file.
  2. Define the resource groups (Microsoft.Resources/resourceGroups) and the policy assignment in the file; use modules to deploy resources into the new groups.
  3. Deploy with 'az deployment sub create --location <region> --template-file main.bicep' (location stores the deployment metadata).

Exam tip: Match the deployment scope to what the template creates — resource groups and subscription-wide policy require subscription-scope deployments.

ARM Templates and Bicep: AZ-104 Deployment Guide — the lesson that teaches this.

Question 5Deploy and manage Azure compute resources

In an ARM template, which section defines values that a user supplies at deployment time, such as an environment name or a VM administrator username?

Choose one.

  • a
    variables

    Variables are computed inside the template from expressions and parameters — they cannot be supplied by the person deploying.

  • b
    outputs

    Outputs return values after the deployment finishes, such as a generated hostname — they flow out of the template, not into it.

  • c
    resources

    The resources section declares the Azure resources to deploy — it consumes parameter values but is not where inputs are defined.

  • d
    parameters Correct

    Parameters are the template's external inputs — their values are provided at deployment time, on the command line or via a parameter file.

The concept

An ARM template separates concerns into sections: parameters (deployment-time inputs), variables (internal computed values), resources (what gets deployed), and outputs (values returned after deployment). Functions like concat and resourceId glue them together.

Why that’s the answer

Values supplied by the deployer — environment names, admin usernames, SKU choices — belong in parameters, the only section whose values come from outside the template at deployment time. Variables are derived internally and cannot be overridden at deploy time. Outputs are return values, the opposite direction. Resources declare infrastructure and merely reference the inputs.

How to reason it out
  1. Declare each input in the parameters section with a type, and add allowed values or defaults where sensible.
  2. Reference the input in resources with the parameters() function (or directly by name in Bicep).
  3. Supply values at deploy time via --parameters on the CLI or a parameter file per environment.

Exam tip: Parameters are deploy-time inputs, variables are internal calculations, outputs are return values.

ARM Templates and Bicep: AZ-104 Deployment Guide — the lesson that teaches this.

Question 6Deploy and manage Azure compute resources

A company deploys the same Bicep file to dev, test, and production environments. Each environment needs different VM sizes, instance counts, and name prefixes. Which approach requires the LEAST administrative effort while keeping one template?

Choose one.

  • a
    Maintain three copies of the Bicep file, one edited for each environment

    Copies inevitably drift apart — every template change must be applied three times, which multiplies effort and risk instead of reducing it.

  • b
    Create one parameter file per environment and pass the matching file at deployment time Correct

    Per-environment parameter files (dev.bicepparam, prod.bicepparam) keep a single template as the source of truth while cleanly capturing each environment's values.

  • c
    Edit the template's default parameter values before each deployment

    Hand-editing the template before every deployment is manual, error-prone, and destroys the audit trail of what each environment received.

  • d
    Hard-code the environment differences into the variables section using nested if() functions

    Burying environment values in conditional variables makes the template hard to read and still requires template edits whenever an environment's values change.

The concept

Parameter files separate a template's logic from its environment-specific values. One template plus one parameter file per environment is the standard multi-environment pattern for ARM and Bicep (.parameters.json or .bicepparam).

Why that’s the answer

Parameter files achieve the goal directly: a single, unchanging template and a small values file per environment, selected at deploy time. Duplicating the template three times creates drift and triple maintenance. Editing defaults before each deployment is manual toil with no repeatability. Hard-coding conditionals in variables couples environment data to template logic and still needs template edits for value changes.

How to reason it out
  1. Declare every environment-varying value (VM size, count, prefix) as a parameter in the single Bicep file.
  2. Create dev.bicepparam, test.bicepparam, and prod.bicepparam, each supplying that environment's values.
  3. Deploy with 'az deployment group create --template-file main.bicep --parameters prod.bicepparam' — the same command pattern for every environment.

Exam tip: One template, one parameter file per environment — never fork the template to vary its values.

ARM Templates and Bicep: AZ-104 Deployment Guide — the lesson that teaches this.

What AZ-104 domain 3 tests, topic by topic

The official exam guide breaks Deploy and manage Azure compute resources into 4 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published AZ-104 practice questions per topic in Deploy and manage Azure compute resources
TopicWhat it coversQuestions
Automate deployment of resources by using Azure Resource Manager (ARM) templates or Bicep filesSkills outline section (AZ-104, as of April 17, 2026). Interpreting an ARM template or a Bicep file; modifying an existing ARM template or Bicep file; deploying resources by using an ARM template or a Bicep file; exporting a deployment as an ARM template or converting an ARM template to a Bicep file.20
Create and configure virtual machinesSkills outline section (AZ-104, as of April 17, 2026). Creating a virtual machine; configuring encryption at host; moving a VM to another resource group, subscription, or region; managing VM sizes and disks; deploying VMs to availability zones and availability sets; deploying and configuring Azure Virtual Machine Scale Sets.20
Provision and manage containers in the Azure portalSkills outline section (AZ-104, as of April 17, 2026). Creating and managing an Azure Container Registry; provisioning containers by using Azure Container Instances and Azure Container Apps; managing sizing and scaling for containers, including Container Instances and Container Apps.20
Create and configure Azure App ServiceSkills outline section (AZ-104, as of April 17, 2026). Provisioning an App Service plan and configuring its scaling; creating an App Service; configuring certificates and Transport Layer Security (TLS); mapping an existing custom DNS name; configuring backup, networking settings, and deployment slots for an App Service.20
Total80

Revise Deploy and manage Azure compute resources before you drill it

Other AZ-104 domains

Deploy and manage Azure compute resources: your questions

Deploy and manage Azure compute resources is domain 3 of the AZ-104 exam guide and carries 24% of the scored content — the heaviest of the 5 domains. On a 50-question paper that works out to roughly 12 questions, though Microsoft Azure does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official AZ-104 exam guide.