AZ-200: Microsoft Azure Developer Core Solutions — Questions and Answers
Question 1: Which Azure AD token type should be validated by a resource API to authorize incoming requests?
- SAML assertion
- Refresh token
- Access token (Correct answer)
- ID token
Correct answer: Access token
An API should validate the access token, which is issued by Azure AD and contains the caller's identity, roles, and scopes for authorization decisions.
Question 2: What is the purpose of RBAC role assignments in Azure?
- Define network security rules
- Set up multi-factor authentication
- Configure Azure Policy compliance rules
- Grant a security principal (user/group/identity) specific permissions to an Azure resource (Correct answer)
Correct answer: Grant a security principal (user/group/identity) specific permissions to an Azure resource
RBAC role assignments attach a role definition to a security principal at a specific scope, granting the permissions defined in that role to the principal.
Question 3: What is Azure Event Hubs Capture used for?
- Automatically saving event data to Azure Blob Storage or Data Lake Storage (Correct answer)
- Recording Event Grid events to SQL Database
- Capturing dead-lettered events from Service Bus
- Capturing Azure AD sign-in events
Correct answer: Automatically saving event data to Azure Blob Storage or Data Lake Storage
Event Hubs Capture automatically archives streaming data to Azure Blob Storage or Azure Data Lake Storage in Avro format for batch processing or archiving.
Question 4: Which conflict resolution policy in Cosmos DB multi-master automatically picks the winning write based on the highest timestamp?
- Manual merge
- Custom (stored procedure)
- First-Write-Wins
- Last-Write-Wins (LWW) using _ts (Correct answer)
Correct answer: Last-Write-Wins (LWW) using _ts
Last-Write-Wins uses the _ts (timestamp) property by default to automatically resolve write conflicts by selecting the item with the highest timestamp.
Question 5: What is the Application Insights connection string used for?
- Setting the sampling rate
- Authenticating users through Application Insights
- Connecting to the Azure SQL backend of Application Insights
- Configuring the SDK to send telemetry to the correct Application Insights resource (Correct answer)
Correct answer: Configuring the SDK to send telemetry to the correct Application Insights resource
The Application Insights connection string (or instrumentation key) tells the SDK which Application Insights resource to send telemetry data to.
Question 6: Which Azure AD grant type is used when a user signs in interactively via a browser and the app receives an authorization code?
- Device authorization flow
- Client credentials flow
- Resource owner password flow
- Authorization code flow (Correct answer)
Correct answer: Authorization code flow
The authorization code flow is the standard interactive sign-in flow where Azure AD redirects the user's browser back to the app with an authorization code that is exchanged for tokens.
Question 7: Which runtime identifier is used when deploying a .NET 8 isolated Azure Function in App Service?
- dotnet-isolated (Correct answer)
- net8
- dotnet
- functions-dotnet8
Correct answer: dotnet-isolated
The dotnet-isolated worker model runs .NET Functions in a separate process and requires specifying the dotnet-isolated runtime.
Question 8: Which Azure service is optimized for high-throughput event streaming, such as telemetry and log ingestion at millions of events per second?
- Azure Service Bus
- Azure Event Grid
- Azure Notification Hubs
- Azure Event Hubs (Correct answer)
Correct answer: Azure Event Hubs
Azure Event Hubs is a big-data streaming platform and event ingestion service capable of receiving millions of events per second with low latency.
Question 9: In Azure Functions, which interface should an orchestrator function use when awaiting an activity in C#?
- IDurableActivityContext
- IDurableOrchestrationContext (Correct answer)
- IDurableEntityClient
- IDurableOrchestrationClient
Correct answer: IDurableOrchestrationContext
IDurableOrchestrationContext provides the orchestrator with methods like CallActivityAsync to invoke activity functions and manage workflow state.
Question 10: Which consistency level in Azure Cosmos DB guarantees that reads always return the most recently written value?
- Consistent Prefix
- Session
- Strong (Correct answer)
- Bounded Staleness
Correct answer: Strong
Strong consistency guarantees that reads always reflect the latest committed write, providing linearizability at the cost of higher latency.
Question 11: What is the primary use case for Azure Event Grid?
- Large message batch processing
- Message ordering for financial transactions
- High-throughput event streaming for analytics
- Reactive, event-driven routing of discrete events to multiple subscribers (Correct answer)
Correct answer: Reactive, event-driven routing of discrete events to multiple subscribers
Event Grid excels at routing discrete events from Azure services or custom sources to event handlers, enabling reactive, serverless, event-driven architectures.
Question 12: What is the difference between LRS and ZRS redundancy options in Azure Storage?
- LRS is geo-redundant; ZRS is locally redundant
- LRS costs more; ZRS is free
- LRS replicates across zones; ZRS replicates within one datacenter
- LRS replicates within one datacenter; ZRS replicates across availability zones in a region (Correct answer)
Correct answer: LRS replicates within one datacenter; ZRS replicates across availability zones in a region
LRS keeps three copies within a single datacenter, while ZRS synchronously replicates data across three availability zones in the same region.
Question 13: What is the Azure Relay service used for?
- Routing Event Hub events to on-premises systems
- Relaying API calls through API Management
- Providing a proxy for Azure CDN
- Enabling secure hybrid connections between on-premises services and cloud applications without opening inbound firewall ports (Correct answer)
Correct answer: Enabling secure hybrid connections between on-premises services and cloud applications without opening inbound firewall ports
Azure Relay enables hybrid connectivity by letting on-premises services expose endpoints to the cloud without firewall changes, using outbound connections only.
Question 14: How do you configure an Azure Web App to use a custom domain over HTTPS?
- Set HTTPS in web.config only
- Enable CDN and configure HTTPS there
- Add a CNAME only
- Upload a TLS certificate and bind it to the custom domain in App Service (Correct answer)
Correct answer: Upload a TLS certificate and bind it to the custom domain in App Service
You must upload or import a TLS/SSL certificate and then create an SSL binding for the custom domain in App Service settings.
Question 15: Which KQL operator is used to filter rows in a Log Analytics query?
- restrict
- filter
- select
- where (Correct answer)
Correct answer: where
The `where` operator in KQL filters rows in a table based on a boolean condition, equivalent to SQL's WHERE clause.
Question 16: What is the purpose of specifying API permissions (scopes) in an Azure AD app registration?
- To assign users to the application
- To configure the app's pricing tier
- To set the app's redirect URIs
- To declare what downstream APIs or Microsoft Graph resources the app is allowed to call (Correct answer)
Correct answer: To declare what downstream APIs or Microsoft Graph resources the app is allowed to call
API permissions declare the OAuth2 scopes or roles the application needs to call downstream APIs, which must be consented to by users or admins.
Question 17: Which Azure Storage redundancy option provides read access to a secondary region in the event of primary region unavailability?
- RA-GRS (Correct answer)
- GRS
- GZRS
- ZRS
Correct answer: RA-GRS
Read-access geo-redundant storage (RA-GRS) replicates data to a secondary region and provides a secondary read endpoint that is always accessible.
Question 18: How do Azure Functions integrate natively with Azure Service Bus?
- Via the Service Bus trigger binding, which fires the function when new messages arrive (Correct answer)
- Via Logic Apps as a middleware layer
- Via a timer trigger that calls the Service Bus SDK
- Via polling using an HTTP trigger
Correct answer: Via the Service Bus trigger binding, which fires the function when new messages arrive
The Azure Functions Service Bus trigger binding listens for new messages on a queue or subscription and automatically invokes the function when messages arrive.
Question 19: What is the correct way to copy a large number of blobs between storage accounts efficiently using command-line tools?
- Download all blobs locally then upload
- Use Azure Data Factory for all blob copies
- Use AzCopy with the copy command and service-to-service transfer (Correct answer)
- Use Azure PowerShell Copy-AzBlob cmdlet for each blob
Correct answer: Use AzCopy with the copy command and service-to-service transfer
AzCopy supports server-side service-to-service transfers for blobs, copying data between storage accounts without passing through the client machine.
Question 20: Which class in the Azure Storage SDK for .NET is used to interact with a specific blob container?
- BlockBlobClient
- StorageClient
- BlobServiceClient
- BlobContainerClient (Correct answer)
Correct answer: BlobContainerClient
BlobContainerClient represents a specific container and provides methods for listing blobs, creating blobs, and managing container properties.
Question 21: Which Azure Functions trigger automatically scales based on the number of messages in a queue?
- Timer trigger
- Blob trigger
- HTTP trigger
- Queue Storage trigger (Correct answer)
Correct answer: Queue Storage trigger
The Azure Queue Storage trigger monitors queue depth and scales out function instances automatically when messages accumulate.
Question 22: Which Azure Functions Premium Plan feature ensures at least one function instance is always warm to eliminate cold starts?
- Elastic scale
- VNet integration
- Pre-warmed instances (Correct answer)
- Scale controller
Correct answer: Pre-warmed instances
Pre-warmed instances on the Premium Plan keep at least one instance initialized so the first request does not incur a cold-start delay.
Question 23: Which Azure Key Vault object type should be used to store a database connection string?
- Key
- Certificate
- Secret (Correct answer)
- Policy
Correct answer: Secret
Key Vault Secrets are designed to store sensitive string values like passwords, connection strings, and API keys securely.
Question 24: What does the Application Insights dependency tracking feature monitor?
- Outgoing calls from the app to external services like SQL, HTTP APIs, and storage (Correct answer)
- NuGet restore failures at build time
- NuGet package versions used by the application
- Infrastructure dependencies between Azure subscriptions
Correct answer: Outgoing calls from the app to external services like SQL, HTTP APIs, and storage
Dependency tracking captures outgoing calls from an application to external services like databases, HTTP APIs, and Azure Storage, including duration and success status.
Question 25: Which protocol does Azure Service Bus support for messaging in addition to AMQP?
- WebSocket only
- HTTP/REST (Correct answer)
- STOMP
- MQTT
Correct answer: HTTP/REST
Azure Service Bus supports both AMQP 1.0 and HTTP/REST protocols, allowing web clients and firewalled environments to send and receive messages via HTTPS.
Question 26: What happens to a Service Bus message that fails processing repeatedly and exceeds the max delivery count?
- Processing retries indefinitely
- The message is moved to the dead-letter queue (DLQ) (Correct answer)
- The message is returned to the beginning of the queue
- The message is permanently deleted
Correct answer: The message is moved to the dead-letter queue (DLQ)
When a message exceeds its maximum delivery count, Service Bus automatically moves it to the dead-letter queue (DLQ) for inspection and manual handling.
Question 27: Which App Service diagnostic feature captures slow requests and request traces to help identify performance bottlenecks?
- Failed Request Tracing (FREB) and Slow Request logs (Correct answer)
- Activity Log streaming
- Azure Monitor Metrics only
- Azure Advisor recommendations
Correct answer: Failed Request Tracing (FREB) and Slow Request logs
Failed Request Tracing (FREB) and slow request logs capture detailed traces of requests that exceed a defined duration threshold.
Question 28: Note: This is the first in a series of questions on the same situation. Each of the questions in the series has its own solution. Check to see if the solution achieves the given objectives. The following resource groups are available to you: <br> <br> Developers must use DevWorkstation to connect to DevServer. DevServer must not accept connections from the internet in order to ensure security. <br> Between the DevWorkstation and the DevServer, you must establish a secure connection. <br> Solution: DevServer WestCentral should have a public IP address configured. Allow all inbound ports by configuring the Network Security Group. <br> Is the solution effective in achieving the goal?
- Yes
- No (Correct answer)
Correct answer: No
Explanation: <br> Internet connections must not be accepted by DevServer. <br> Use Global Virtual Network peering instead. <br> Peering virtual networks in various Azure regions to create a global private network in Azure is possible using Azure Global Virtual Network Peering.
Question 29: In Azure Durable Functions, which function type orchestrates the execution of other functions?
- Client function
- Orchestrator function (Correct answer)
- Entity function
- Activity function
Correct answer: Orchestrator function
The Orchestrator function defines the workflow logic, calling Activity functions and managing their sequencing and state.
Question 30: What is the purpose of the Time to Live (TTL) feature in Azure Cosmos DB?
- Controls session token expiry
- Automatically deletes items after a specified number of seconds (Correct answer)
- Sets the maximum RU burst duration
- Limits query execution time
Correct answer: Automatically deletes items after a specified number of seconds
TTL automatically deletes documents after a configured number of seconds, enabling automatic data expiration without consuming RUs for manual deletes.
Question 31: To enable meaningful analysis of user interactions with a mobile app, you must utilize the Azure Mobile Apps SDK to implement Application Insights instrumentation features. To use Application Insights' Usage Analytics feature, you must first collect the necessary data. <br> What information should you collect? Each accurate response reveals a piece of the solution.
- Session Id
- Trace
- Exception
- Events (Correct answer)
Correct answer: Events
Explanation: <br> After your app has been onboarded to App Center, it must be changed to transmit custom event telemetry using the App Center SDK. <br>Custom events are the only sort of telemetry that can be sent using the App Center SDK. <br> Telemetry from the App Center that is sent to Application Insights.
Question 32: What Azure feature allows developers to verify that a request comes from a specific Azure service without checking credentials?
- Managed Identity with Azure AD token validation (Correct answer)
- Service Tags in network security groups
- API key rotation
- IP allowlisting only
Correct answer: Managed Identity with Azure AD token validation
Using managed identity, a service obtains an Azure AD access token that the receiving service can validate cryptographically to confirm the caller's identity.
Question 33: Which Azure Monitor component stores log data and supports KQL (Kusto Query Language) for querying?
- Log Analytics Workspace (Correct answer)
- Azure Metrics Explorer
- Application Insights Live Metrics
- Azure Data Explorer only
Correct answer: Log Analytics Workspace
Log Analytics Workspaces store structured log data from Azure resources and Application Insights, queried using Kusto Query Language (KQL).
Question 34: What is the purpose of using a synthetic partition key in Azure Cosmos DB?
- To replicate data to secondary regions
- To reduce RU consumption on reads
- To encrypt items at rest
- To combine multiple properties into a single high-cardinality partition key (Correct answer)
Correct answer: To combine multiple properties into a single high-cardinality partition key
A synthetic partition key concatenates or hashes multiple fields to create a high-cardinality key, ensuring even data distribution across partitions.
Question 35: What is an Azure AD application registration used for in development?
- Configuring network security groups
- Registering virtual machines in Azure AD
- Representing an application in Azure AD to enable authentication and authorization via OAuth2/OIDC (Correct answer)
- Creating user accounts for the app
Correct answer: Representing an application in Azure AD to enable authentication and authorization via OAuth2/OIDC
An app registration creates an identity for an application in Azure AD, enabling it to authenticate users or other services using OAuth2 and OpenID Connect protocols.
Question 36: Which Durable Functions pattern is best suited for running multiple independent tasks in parallel and aggregating their results?
- Fan-out/fan-in (Correct answer)
- Monitor
- Async HTTP APIs
- Function chaining
Correct answer: Fan-out/fan-in
The fan-out/fan-in pattern starts multiple activity functions simultaneously and waits for all of them to complete before aggregating results.
Question 37: What is the purpose of Azure AD Conditional Access policies for application developers?
- Enforce additional security requirements (MFA, compliant device) when accessing applications (Correct answer)
- Generate API keys for applications
- Configure user roles in the application
- Automatically scale apps based on user load
Correct answer: Enforce additional security requirements (MFA, compliant device) when accessing applications
Conditional Access policies enforce security requirements like MFA or compliant device when users sign into applications, protecting against compromised credentials.
Question 38: What is the purpose of adaptive sampling in Application Insights?
- Reduces telemetry volume by sending a statistical sample of requests while preserving data accuracy (Correct answer)
- Increases telemetry data volume for high-traffic apps
- Samples only error telemetry
- Enables real-time streaming of all telemetry
Correct answer: Reduces telemetry volume by sending a statistical sample of requests while preserving data accuracy
Adaptive sampling dynamically adjusts the fraction of telemetry sent to Application Insights to stay within data volume limits while preserving statistical accuracy.
Question 39: Which Azure Key Vault soft-delete feature prevents accidental permanent deletion of secrets?
- Key rotation policy
- Purge protection (Correct answer)
- Access policy deny assignment
- Versioning
Correct answer: Purge protection
Purge protection prevents a soft-deleted Key Vault or its objects from being permanently purged during the retention period, even by administrators.
Question 40: Which HTTP authorization level requires callers to include a function-specific API key in the request?
- Admin
- Function (Correct answer)
- User
- Anonymous
Correct answer: Function
The Function authorization level requires a function key (or higher) to be passed with each request, limiting access to authorized callers.
Question 41: What is the role of the Event Hubs partition in enabling parallel processing?
- Partitions encrypt data for different consumers
- Partitions limit the number of producers
- Each partition holds an independent ordered stream of events, allowing multiple consumers to read in parallel (Correct answer)
- Partitions store dead-lettered events
Correct answer: Each partition holds an independent ordered stream of events, allowing multiple consumers to read in parallel
Each Event Hubs partition maintains its own ordered sequence of events, allowing one consumer per partition, enabling fully parallel processing across partitions.
Question 42: What is the key difference between Azure Service Bus queues and Azure Storage queues?
- Storage queues support larger messages
- Service Bus supports advanced features like sessions, dead-lettering, and duplicate detection; Storage queues are simpler and cheaper (Correct answer)
- Storage queues support ordering guarantees; Service Bus does not
- Service Bus is free; Storage queues have per-message costs
Correct answer: Service Bus supports advanced features like sessions, dead-lettering, and duplicate detection; Storage queues are simpler and cheaper
Azure Service Bus provides enterprise messaging features like message sessions, dead-letter queues, duplicate detection, and transactions, while Storage queues are simpler and cost-effective.
Question 43: You're responsible for an Azure Web App that runs within a container. The container uses a Dockerfile that is copied all over the place and takes up a lot of space. The Dockerfile must be optimized. <br> What are your options?
- Concatenate all RUN instructions on one line to reduce layers
- For a cached operation, use multiple RUN commands
- Reduce the number of levels by condensing actions into as few RUN commands as possible (Correct answer)
- Use a.dockerignore file to configure the CLI
Correct answer: Reduce the number of levels by condensing actions into as few RUN commands as possible
Explanation: <br> Reduce the amount of layers as much as possible. <br> Prior to Docker 17.05, and even before Docker 1.10, it was necessary to keep the number of layers in your image to a minimum. <br> Only the RUN, COPY, and ADD instructions build layers with Docker 1.10 and higher.
Question 44: How do you correlate logs from multiple Azure services in a single Log Analytics workspace query?
- Use Azure Data Factory to merge logs first
- Export all logs to CSV and join in Excel
- Use KQL join or union operators across multiple tables in the same workspace (Correct answer)
- Each service requires a separate workspace
Correct answer: Use KQL join or union operators across multiple tables in the same workspace
KQL's join and union operators allow queries across multiple log tables in the same Log Analytics workspace, enabling cross-service correlation.
Question 45: What does the lock duration property control for Azure Service Bus messages?
- How long duplicate detection is active
- The delay before a scheduled message is delivered
- How long the message is stored before expiring
- How long a receiver holds exclusive access to a message before it becomes visible again (Correct answer)
Correct answer: How long a receiver holds exclusive access to a message before it becomes visible again
Lock duration defines how long a consumer has exclusive access to a message after receiving it; if not settled within that time, the lock expires and the message becomes available again.
Question 46: Which Azure Event Grid schema format should be used for maximum interoperability with open-source event frameworks?
- Event Grid schema
- CloudEvents schema (Correct answer)
- Custom schema
- JSON-API schema
Correct answer: CloudEvents schema
The CloudEvents schema is an open standard (CNCF) for describing event data, providing maximum interoperability with open-source tools and frameworks.
Question 47: How do you enable health check monitoring so App Service removes unhealthy instances from the load balancer?
- Use Traffic Manager health probes
- Enable Azure Monitor alerts on HTTP 5xx
- Set a Health Check path in App Service configuration (Correct answer)
- Configure Application Insights availability tests
Correct answer: Set a Health Check path in App Service configuration
The Health Check feature in App Service pings a specified path and removes instances that return non-2xx responses from the load balancer rotation.
Question 48: How long does Azure Event Hubs retain events by default?
- 24 hours
- 7 days
- 1 hour
- 1 day (24 hours), configurable up to 90 days (Correct answer)
Correct answer: 1 day (24 hours), configurable up to 90 days
Event Hubs retains events for 1 day by default, but retention can be configured up to 90 days depending on the tier.
Question 49: Which Azure Monitor alert type evaluates a KQL query against Log Analytics data and fires when results meet a threshold?
- Activity log alert
- Log search alert (Correct answer)
- Smart detection alert
- Metric alert
Correct answer: Log search alert
Log search alerts run a KQL query on a schedule against Log Analytics data and trigger when the number of results or a metric computed from results exceeds a threshold.
Question 50: Note: This is the first in a series of questions on the same situation. Each of the questions in the series has its own solution. Check to see if the solution achieves the given objectives. The following resource groups are available to you: <br> <br> Developers must use DevWorkstation to connect to DevServer. DevServer must not accept connections from the internet in order to ensure security.<br> Between the DevWorkstation and the DevServer, you must establish a secure connection.<br> Solution: Configure Global Virtual Network peering and network security groups to allow connectivity between the DevServer and the DevWorkstation using their private IP addresses.<br> Is the solution effective in achieving the goal?
- Yes (Correct answer)
- No
Correct answer: Yes
Explanation: <br> Peering virtual networks in various Azure regions to create a global private network in Azure is possible using Azure Global Virtual Network Peering.
Question 51: Which Azure Storage feature allows immutable, time-limited locks on blobs to prevent modification or deletion?
- Azure Backup integration
- Blob snapshots
- Immutability policies (WORM) (Correct answer)
- Soft delete
Correct answer: Immutability policies (WORM)
Immutability policies (Write Once, Read Many) on Azure Blob Storage lock blobs so they cannot be modified or deleted for a specified retention period.
Question 52: Which setting in local.settings.json is required to run Azure Functions locally?
- FUNCTIONS_EXTENSION_VERSION
- FUNCTIONS_WORKER_RUNTIME (Correct answer)
- AzureWebJobsDashboard
- WEBSITE_RUN_FROM_PACKAGE
Correct answer: FUNCTIONS_WORKER_RUNTIME
FUNCTIONS_WORKER_RUNTIME specifies the language worker (e.g., dotnet, node, python) and is required for the local runtime to load the correct worker process.
Question 53: What is the function of VNet Integration in Azure App Service?
- Allows the web app to make outbound calls into a VNet (Correct answer)
- Allows the web app to receive traffic from a VNet
- Replaces the need for a VPN gateway
- Enables private DNS resolution globally
Correct answer: Allows the web app to make outbound calls into a VNet
VNet Integration enables outbound traffic from the App Service to reach resources inside an Azure Virtual Network, such as private databases.
Question 54: What is the difference between a system-assigned and user-assigned managed identity?
- There is no functional difference
- System-assigned has a longer lifetime; user-assigned is deleted with the resource
- System-assigned supports multiple resources; user-assigned is single-use
- System-assigned is tied to a single resource and deleted with it; user-assigned is standalone and reusable (Correct answer)
Correct answer: System-assigned is tied to a single resource and deleted with it; user-assigned is standalone and reusable
System-assigned identities are created and deleted with the resource, while user-assigned identities exist independently and can be assigned to multiple resources.
Question 55: Which Cosmos DB feature streams all insert, update, and delete operations to downstream consumers in real time?
- Change Feed (Correct answer)
- Cosmos DB Triggers via Logic Apps
- Azure Data Factory pipeline
- Event Grid integration
Correct answer: Change Feed
Change Feed provides a sorted, persistent log of all changes (inserts and updates) in a Cosmos DB container, enabling real-time event-driven processing.
AZ-200: Microsoft Azure Developer Core Solutions
The AZ-200 exam validates skills in developing cloud solutions on Microsoft Azure, covering compute, storage, security, monitoring, and integration services. It was a predecessor to the AZ-204 Azure Developer Associate certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds