Microsoft Azure Architect Design (AZ-301) — Questions and Answers
Question 1: An architect needs to migrate a SQL Server database to Azure with minimal code changes, while needing features like SQL Agent, cross-database queries, and linked servers not supported in Azure SQL Database. Which service should be recommended?
- Azure SQL Database
- Azure Synapse Analytics
- Azure SQL Managed Instance (Correct answer)
- SQL Server on Azure VMs
Correct answer: Azure SQL Managed Instance
Azure SQL Managed Instance provides near 100% SQL Server compatibility including SQL Agent, cross-database queries, and linked servers in a fully managed PaaS service.
Question 2: During a proof-of-concept for Azure SQL Database, you need to compare query performance under different service tiers with reproducible workloads. Which feature best supports this evidence gathering?
- Azure Migrate assessment reports
- Azure SQL Database Hyperscale auto-scaling
- Azure SQL Database Query Performance Insight (Correct answer)
- Azure Advisor cost recommendations
Correct answer: Azure SQL Database Query Performance Insight
Query Performance Insight surfaces top resource-consuming queries with execution metrics, enabling reproducible, evidence-based tier comparisons.
Question 3: You have 100 Microsoft SQL Server Integration Services (SSIS) packages with 10 on-premises SQL Server databases defined as destinations. The ten on-premises databases will be moved to Azure SQL Database. You must propose a method for hosting SSIS packages in Azure. The solution must ensure that the packages can be used to target SQL Database instances. <br> <br> What should your advice include?
- Azure Data Catalog
- SQL Server Migration Assistant (SSMA)
- Azure Data Factory
- Data Migration Assistant (Correct answer)
Correct answer: Data Migration Assistant
Explanation: <br> Data Migration Assistant (DMA) assists you in migrating to a modern data platform by discovering compatibility issues that may affect database functioning in your new SQL Server version. It suggests enhancements to your target environment's performance and reliability.
Question 4: An architect needs to document trade-offs between an active-active and active-passive Azure disaster recovery design for multiple stakeholders. Which artifact best serves this purpose?
- An Architecture Decision Record (ADR) outlining options, trade-offs, and the rationale for the chosen approach (Correct answer)
- A PM2 process list showing running services
- A raw Azure Cost Management export spreadsheet
- A detailed Terraform script with comments
Correct answer: An Architecture Decision Record (ADR) outlining options, trade-offs, and the rationale for the chosen approach
Architecture Decision Records (ADRs) formally capture options considered, trade-offs, and the rationale, making them accessible to both technical and non-technical stakeholders.
Question 5: What is a compliance management system in AZ-301 - Microsoft Azure Solutions Architect Expert practice?
- A government reporting requirement
- A software application only
- An optional business tool
- A structured framework of policies, procedures, and controls that ensure regulatory adherence (Correct answer)
Correct answer: A structured framework of policies, procedures, and controls that ensure regulatory adherence
This is fundamental to AZ-301 - Microsoft Azure Solutions Architect Expert practice. A structured framework of policies, procedures, and controls that ensure regulatory adherence represents the professional standard for regulatory in the AZ-301 certification framework.
Question 6: An enterprise must guarantee that new Azure subscriptions always include a Log Analytics workspace and required RBAC roles. Which service automates this governance at scale?
- Azure Management Groups
- Azure Policy
- Azure Blueprints (Correct answer)
- ARM Template Specs
Correct answer: Azure Blueprints
Azure Blueprints bundles policies, RBAC roles, ARM templates, and resource groups into a single deployable artifact that can be assigned to subscriptions.
Question 7: A project team is debating whether to use IaaS or PaaS for a new web application. Which professional consideration should drive the recommendation toward PaaS?
- PaaS always costs less than IaaS
- PaaS reduces operational overhead by abstracting OS and middleware management (Correct answer)
- PaaS is required for all Azure compliance certifications
- PaaS provides more control over the underlying infrastructure
Correct answer: PaaS reduces operational overhead by abstracting OS and middleware management
PaaS abstracts OS patching, middleware updates, and infrastructure management, reducing operational burden and allowing teams to focus on application code.
Question 8: How should an AZ-301 professional respond to a compliance violation?
- Report it promptly, investigate the root cause, and implement corrective actions (Correct answer)
- Conceal it if minor
- Wait for an external audit to find it
- Blame the regulatory framework
Correct answer: Report it promptly, investigate the root cause, and implement corrective actions
This is fundamental to AZ-301 - Microsoft Azure Solutions Architect Expert practice. Report it promptly, investigate the root cause, and implement corrective actions represents the professional standard for regulatory in the AZ-301 certification framework.
Question 9: A company wants to implement geo-redundant storage for their Azure SQL Database to ensure data is replicated to a paired region for disaster recovery with an RPO of less than 5 seconds. Which feature should be configured?
- Azure SQL Database geo-replication
- Azure SQL Database active geo-replication (Correct answer)
- Azure SQL Database auto-failover groups
- Azure SQL Database long-term retention
Correct answer: Azure SQL Database active geo-replication
Azure SQL Database active geo-replication creates up to 4 readable secondary replicas in paired or other regions with asynchronous replication achieving RPO typically under 5 seconds.
Question 10: An architect must justify adopting Azure Kubernetes Service over Azure App Service for a microservices workload. Which Azure-native tool produces comparative benchmark evidence through load testing?
- Azure Application Gateway WAF logs
- Azure Traffic Manager performance routing
- Azure Load Testing (based on Apache JMeter) (Correct answer)
- Azure Front Door health probes
Correct answer: Azure Load Testing (based on Apache JMeter)
Azure Load Testing lets architects run high-scale JMeter-based tests against both deployment options and compare latency and throughput metrics as evidence.
Question 11: An enterprise application uses Azure Active Directory for authentication. Developers need to implement OAuth 2.0 authorization code flow. Which endpoint version should be used for the broadest compatibility with both personal and work accounts?
- v2.0 endpoint (Correct answer)
- ADFS endpoint
- v1.0 endpoint
- B2C endpoint
Correct answer: v2.0 endpoint
The Microsoft identity platform v2.0 endpoint supports both personal Microsoft accounts and Azure AD work/school accounts using a unified authentication flow.
Question 12: When architecting a solution using Azure Service Fabric, which programming model allows you to build stateful microservices that persist state within the service itself without an external database?
- Containers
- Reliable Actors
- Guest Executables
- Reliable Services (Correct answer)
Correct answer: Reliable Services
Reliable Services in Azure Service Fabric allows developers to build stateful services using Reliable Collections that persist state within the service.
Question 13: When designing a multi-model database solution that needs to store and query data as documents, graphs, key-value pairs, and wide-column tables in a single globally distributed service, which Azure service should be used?
- Azure Cosmos DB (Correct answer)
- Azure SQL Database
- Azure Table Storage
- Azure Cache for Redis
Correct answer: Azure Cosmos DB
Azure Cosmos DB is a globally distributed multi-model database supporting document, graph, key-value, table, and column-family APIs in a single service.
Question 14: You must suggest a solution that satisfies the database retention requirement. What would you suggest?
- Configure geo replication of the database (Correct answer)
- Use automatic Azure SQL Database backups
- Configure Azure Site Recovery
- Configure the database's long-term retention policy.
Correct answer: Configure geo replication of the database
The Correct Answers: <br> Configure geo replication of the database
Question 15: A data architect needs to design a solution for ingesting, storing, and analyzing large volumes of data from multiple sources with both batch and real-time processing capabilities. Which Azure service provides this unified analytics platform?
- Azure HDInsight
- Azure Databricks
- Azure Synapse Analytics (Correct answer)
- Azure Data Factory
Correct answer: Azure Synapse Analytics
Azure Synapse Analytics is a unified analytics platform that integrates big data and data warehousing with both batch processing and real-time analytics in a single service.
Question 16: How do AZ-301 professionals contribute to advancing their field?
- By competing with colleagues
- By maintaining current practices
- By conducting research, sharing outcomes, mentoring others, and participating in professional forums (Correct answer)
- Individual contribution is not possible
Correct answer: By conducting research, sharing outcomes, mentoring others, and participating in professional forums
This is fundamental to AZ-301 - Microsoft Azure Solutions Architect Expert practice. By conducting research, sharing outcomes, mentoring others, and participating in professional forums represents the professional standard for research in the AZ-301 certification framework.
Question 17: How should AZ-301 professionals stay current with regulatory changes?
- Rely on colleagues for updates
- Monitor regulatory updates, participate in professional associations, and attend continuing education (Correct answer)
- Regulations rarely change
- Wait until audited
Correct answer: Monitor regulatory updates, participate in professional associations, and attend continuing education
This is fundamental to AZ-301 - Microsoft Azure Solutions Architect Expert practice. Monitor regulatory updates, participate in professional associations, and attend continuing education represents the professional standard for regulatory in the AZ-301 certification framework.
Question 18: An architect recommends using managed identities instead of service principals with secrets for Azure resource authentication. What is the primary professional rationale?
- Managed identities work across all cloud providers
- Managed identities are free while service principals cost money
- Managed identities eliminate the need to store and rotate credentials, reducing secret sprawl risk (Correct answer)
- Managed identities provide higher RBAC permissions than service principals
Correct answer: Managed identities eliminate the need to store and rotate credentials, reducing secret sprawl risk
Managed identities are automatically managed by Azure AD and require no credential storage or rotation, eliminating a major class of credential-leakage vulnerabilities.
Question 19: Your quality process requires ensuring that secrets are never committed to Azure Repos. Which control prevents this proactively in CI/CD?
- Azure Policy on pipeline variables
- Microsoft Defender for DevOps secret scanning and branch policies blocking commits with secrets (Correct answer)
- Azure Key Vault reference scanning post-commit
- Azure Monitor log alert on repository events
Correct answer: Microsoft Defender for DevOps secret scanning and branch policies blocking commits with secrets
Microsoft Defender for DevOps includes secret scanning that detects credentials in code and, combined with branch policies, can block pull requests that contain secrets.
Question 20: Which Azure Storage redundancy option replicates data synchronously across three availability zones within the same region?
- Zone Redundant Storage (ZRS) (Correct answer)
- Locally Redundant Storage (LRS)
- Geo-Zone Redundant Storage (GZRS)
- Geo-Redundant Storage (GRS)
Correct answer: Zone Redundant Storage (ZRS)
Zone Redundant Storage (ZRS) replicates data synchronously across three Azure availability zones in the same region, protecting against datacenter-level failures within that region.
Question 21: A team is researching whether Azure Front Door or Azure Traffic Manager better reduces global user latency. Which method provides the most rigorous comparative evidence?
- Reviewing Azure Service Health SLA history for both services
- Deploying both in parallel with identical backends and measuring real user latency via Azure Application Insights (Correct answer)
- Checking Azure Advisor performance recommendations
- Reading the product documentation comparison page
Correct answer: Deploying both in parallel with identical backends and measuring real user latency via Azure Application Insights
Running a live A/B test with Application Insights telemetry capturing actual user-perceived latency for both services yields the most rigorous empirical evidence.
Question 22: When designing an Azure architecture, an architect needs to ensure that all outbound internet traffic from a VNet passes through a centralized security appliance for inspection. Which approach achieves this?
- Azure DDoS Protection
- Network Security Groups
- Azure Firewall with forced tunneling (Correct answer)
- Application Security Groups
Correct answer: Azure Firewall with forced tunneling
Azure Firewall with forced tunneling uses User Defined Routes to redirect all outbound traffic through the firewall for centralized inspection and filtering.
Question 23: A company's architecture requires connecting multiple Azure virtual networks across different regions with a hub-and-spoke topology. Which service simplifies this at scale with built-in routing?
- VNet Peering
- Azure VPN Gateway
- Azure Virtual WAN (Correct answer)
- Azure ExpressRoute
Correct answer: Azure Virtual WAN
Azure Virtual WAN provides a unified networking-as-a-service hub for connecting VNets, branches, and remote users with built-in routing at scale.
Question 24: Researchers need immutable audit evidence that Azure Blob Storage objects were not altered after upload for a regulatory investigation. Which feature provides cryptographically verifiable immutability?
- Azure Blob Storage immutability policies (WORM) with time-based retention locks (Correct answer)
- Azure Backup soft delete
- Azure Key Vault secret rotation
- Azure Storage versioning
Correct answer: Azure Blob Storage immutability policies (WORM) with time-based retention locks
Blob immutability policies with locked time-based retention enforce WORM compliance, and the locked state itself serves as cryptographically verifiable evidence of non-tampering.
Question 25: An architect must design a solution where Azure Cosmos DB consistency needs to balance between strong consistency for reads and high write throughput globally. Which consistency level provides linearizability with lowest write latency tradeoff?
- Session
- Strong
- Eventual
- Bounded Staleness (Correct answer)
Correct answer: Bounded Staleness
Bounded Staleness guarantees reads lag writes by at most K versions or T time interval, providing strong ordering guarantees with better write throughput than Strong consistency.
Question 26: In a Vmware environment, your organization has 300 virtual computers. The virtual machines are different sizes and have different levels of use. All of your virtual machines will be moved to Azure. To migrate present workloads to Azure, you must determine how many and what size Azure virtual machines would be required. The solution must require the least amount of administrative effort. <br> <br> What method should you utilize to make the suggestion?
- Azure Advisor
- Azure Pricing calculator
- Azure Migrate (Correct answer)
- Azure Cost Management
Correct answer: Azure Migrate
Explanation: <br> Azure Migrate assists with cloud migration planning, but it does not migrate on-premises virtual machines (VMs) to Azure.
Question 27: An architect must validate that an Azure Virtual Network peering configuration meets latency SLOs with empirical data. Which Network Watcher tool measures point-to-point latency across the peered VNets?
- VNet flow logs
- Network Performance Monitor (Connection Monitor v2) (Correct answer)
- Azure Traffic Analytics
- Azure DNS metrics
Correct answer: Network Performance Monitor (Connection Monitor v2)
Connection Monitor v2 in Network Watcher continuously measures end-to-end latency and packet loss between sources and destinations across VNet peers.
Question 28: An architect needs to design a BCDR solution where the secondary site actively serves read traffic during normal operations. Which pattern best describes this?
- Active-Passive (warm standby)
- Pilot light
- Active-Active (multi-region) (Correct answer)
- Active-Passive (cold standby)
Correct answer: Active-Active (multi-region)
An Active-Active multi-region pattern means both regions simultaneously handle traffic, including reads, ensuring zero failover time and enabling true load distribution.
Question 29: A SaaS company serves multiple enterprise customers and must ensure each customer's data is completely isolated at the database level while minimizing management overhead. Which Azure SQL approach is best?
- Single Azure SQL Database per tenant with separate server per customer
- Azure SQL Elastic Pool with one database per tenant and row-level security (Correct answer)
- A single Azure SQL Database with tenant_id column and application-level isolation
- Azure SQL Managed Instance per tenant
Correct answer: Azure SQL Elastic Pool with one database per tenant and row-level security
Elastic Pools share compute resources cost-effectively while providing database-level isolation per tenant, reducing management overhead versus per-tenant servers.
Question 30: Your team uses Azure Monitor to track application quality metrics. Which metric type allows you to define custom business KPIs and emit them from application code?
- Activity log metrics
- Custom metrics (Correct answer)
- Log-based metrics
- Platform metrics
Correct answer: Custom metrics
Custom metrics allow application code to emit domain-specific measurements to Azure Monitor using the Application Insights SDK or REST API.
Question 31: During a design review, two business units present conflicting requirements for an Azure shared services architecture. How should the architect facilitate resolution?
- Design separate independent architectures for each unit to avoid conflict
- Choose the requirement from the higher-revenue business unit automatically
- Facilitate a joint workshop with both units to identify shared goals and document agreed-upon requirements with sign-off from both parties (Correct answer)
- Defer the conflict to the next project phase
Correct answer: Facilitate a joint workshop with both units to identify shared goals and document agreed-upon requirements with sign-off from both parties
A joint workshop surfaces shared goals and produces mutually signed-off requirements, preventing future rework from unresolved conflicts.
Question 32: During an architecture review, a security stakeholder raises concerns about data residency for a proposed Azure solution. What is the architect's best initial response?
- Proceed with the design and add encryption as a workaround
- Acknowledge the concern and schedule a dedicated compliance review session (Correct answer)
- Redirect the stakeholder to read Azure compliance documentation independently
- Dismiss the concern as a deployment detail to resolve later
Correct answer: Acknowledge the concern and schedule a dedicated compliance review session
Acknowledging concerns and scheduling a focused session ensures compliance requirements are addressed without derailing the broader review.
Question 33: What distinguishes a peer-reviewed study in AZ-301 - Microsoft Azure Solutions Architect Expert literature?
- Independent experts in the field evaluated the methodology and conclusions before publication (Correct answer)
- It was published quickly
- It was published in any format
- It was written by multiple authors
Correct answer: Independent experts in the field evaluated the methodology and conclusions before publication
This is fundamental to AZ-301 - Microsoft Azure Solutions Architect Expert practice. Independent experts in the field evaluated the methodology and conclusions before publication represents the professional standard for research in the AZ-301 certification framework.
Question 34: A company needs to implement a hot path and cold path architecture (lambda architecture) for IoT data on Azure. Which combination of services best represents this pattern?
- Service Bus + Functions (hot) and SQL Database (cold)
- IoT Hub + Functions (hot) and Cosmos DB (cold)
- Event Hubs + Stream Analytics (hot) and Data Factory + Synapse (cold) (Correct answer)
- Event Grid + Logic Apps (hot) and Blob Storage (cold)
Correct answer: Event Hubs + Stream Analytics (hot) and Data Factory + Synapse (cold)
Event Hubs with Stream Analytics handles the real-time hot path while Data Factory with Synapse Analytics processes historical batch data in the cold path of a lambda architecture.
Question 35: A pipeline must run integration tests against a staging slot before swapping to production in Azure App Service. Which deployment strategy supports this quality gate natively?
- Canary deployment via Azure Front Door
- Blue-green deployment using Traffic Manager
- Deployment slot swap with slot-specific app settings (Correct answer)
- Rolling update via Azure Kubernetes Service
Correct answer: Deployment slot swap with slot-specific app settings
Azure App Service deployment slots allow warming up and testing the staging slot before a zero-downtime swap to production.
Question 36: A company needs to deploy a containerized application that automatically scales and does not require managing underlying infrastructure. Which Azure service should the architect recommend?
- Azure Kubernetes Service
- Azure Container Apps (Correct answer)
- Azure Virtual Machine Scale Sets
- Azure App Service
Correct answer: Azure Container Apps
Azure Container Apps is a fully managed serverless container service that scales automatically without requiring infrastructure management.
Question 37: A company requires that Azure Storage accounts enforce HTTPS-only access and have public blob access disabled by default as an organization-wide policy. Which approach ensures this compliance at scale?
- Azure RBAC with storage contributor role
- Azure Policy with Deny effect for non-HTTPS and public access (Correct answer)
- Azure Security Center recommendations
- Azure Blueprints with ARM templates
Correct answer: Azure Policy with Deny effect for non-HTTPS and public access
Azure Policy with Deny effect prevents creation of storage accounts that allow HTTP access or public blob access, enforcing compliance at the organization level.
Question 38: Which Azure service enables you to define, test, and execute automated recovery plans that sequence the failover of multiple VMs and applications?
- Azure Functions with Event Grid triggers
- Azure Automation runbooks integrated with Azure Site Recovery (Correct answer)
- Azure Logic Apps triggered by Azure Monitor alerts
- Azure DevOps release pipelines
Correct answer: Azure Automation runbooks integrated with Azure Site Recovery
Azure Site Recovery recovery plans support Azure Automation runbooks as pre/post-failover actions, enabling orchestrated, automated failover sequences across multiple VMs and tiers.
Question 39: An Azure architect is onboarding a new technical stakeholder who missed the initial design sessions. Which artifact is most efficient for bringing them up to speed on key decisions?
- A collection of raw Azure Monitor logs from the past month
- A curated set of Architecture Decision Records (ADRs) and the current architecture diagram with annotations (Correct answer)
- A link to general Azure documentation
- A list of all Azure resource names in the subscription
Correct answer: A curated set of Architecture Decision Records (ADRs) and the current architecture diagram with annotations
ADRs paired with annotated architecture diagrams efficiently convey both what was built and why, enabling rapid onboarding of new technical stakeholders.
Question 40: An architect must recommend how to handle schema changes in a microservices environment without breaking existing consumers. What pattern should be applied?
- Block all API changes until a quarterly release window
- Deploy a new service and deprecate the old one immediately
- Use backward-compatible schema evolution with versioned APIs (Correct answer)
- Require all consumers to update simultaneously
Correct answer: Use backward-compatible schema evolution with versioned APIs
Backward-compatible schema evolution with versioned APIs allows existing consumers to continue working while new consumers use updated contracts.
Question 41: A security architect must implement a solution where Azure AD users can only access Azure portal resources from compliant, hybrid Azure AD-joined devices on the corporate network. Which feature enforces this?
- Azure AD Conditional Access (Correct answer)
- Azure AD PIM
- Azure AD Identity Protection
- Azure AD Multi-Factor Authentication
Correct answer: Azure AD Conditional Access
Azure AD Conditional Access policies can enforce device compliance, hybrid join status, and network location as conditions before granting access.
Question 42: An architect discovers that a stakeholder's requirement would create a vendor lock-in risk with Azure Cognitive Services. What is the best way to surface this concern?
- Implement the requirement silently and document the risk in internal notes only
- Raise the risk in the next stakeholder meeting with a documented risk register entry including likelihood, impact, and mitigation options (Correct answer)
- Replace the requirement with a different feature without informing the stakeholder
- Refuse to implement the feature
Correct answer: Raise the risk in the next stakeholder meeting with a documented risk register entry including likelihood, impact, and mitigation options
Formally documenting risks in a risk register and presenting them to stakeholders ensures informed consent and traceable decision-making.
Question 43: A multi-tenant SaaS company on Azure needs to assess the risk of one tenant accessing another tenant's data. Which Azure architecture pattern BEST mitigates this data isolation risk?
- Use Azure AD B2C for all tenants
- Implement shared App Service Plans
- Separate Azure subscriptions per tenant with dedicated databases (Correct answer)
- Shared database with row-level security only
Correct answer: Separate Azure subscriptions per tenant with dedicated databases
Separate subscriptions and dedicated databases per tenant provide strong isolation boundaries, reducing cross-tenant data access risk to near-zero.
Question 44: When designing a BCDR strategy for Azure App Service, which combination provides geo-redundancy with automatic failover and lowest RTO?
- App Service with Azure Backup and point-in-time restore
- Two App Service instances in different regions behind Azure Traffic Manager with health probes (Correct answer)
- App Service Environment with zone redundancy in a single region
- App Service with deployment slots and manual swap
Correct answer: Two App Service instances in different regions behind Azure Traffic Manager with health probes
Deploying App Service instances in multiple regions with Azure Traffic Manager health probes enables automatic DNS-based failover, providing geo-redundancy with the lowest achievable RTO.
Question 45: A compliance officer requests evidence that all Azure administrative actions on production resources were performed by authorized identities only. Which log source is the authoritative record?
- Azure Resource Health event history
- Azure SQL Database audit logs
- Azure Monitor VM guest OS logs
- Azure Activity Log (Control Plane) scoped to production subscriptions (Correct answer)
Correct answer: Azure Activity Log (Control Plane) scoped to production subscriptions
The Azure Activity Log records all control-plane operations with caller identity, timestamp, and result, making it the authoritative evidence source for administrative action audits.
Question 46: A company needs to implement object-level immutability for compliance, ensuring that Azure Blob Storage objects cannot be deleted or modified for a defined retention period. Which feature should be configured?
- Blob soft delete
- Legal hold policies in Azure Policy
- Azure Backup for Blob Storage
- Azure Blob Storage immutability policies (WORM) (Correct answer)
Correct answer: Azure Blob Storage immutability policies (WORM)
Azure Blob Storage immutability policies implement WORM (Write Once Read Many) storage ensuring blobs cannot be deleted or modified for the policy retention period.
Question 47: A company needs to implement change data capture (CDC) for their Azure SQL Database to stream real-time changes to downstream analytics systems. Which Azure service provides this capability natively?
- Azure Data Factory with polling
- Azure Stream Analytics with SQL input
- Azure SQL Database with CDC enabled feeding Azure Event Hubs (Correct answer)
- Azure Synapse Analytics
Correct answer: Azure SQL Database with CDC enabled feeding Azure Event Hubs
Azure SQL Database supports CDC that captures row-level changes which can be fed to Azure Event Hubs for real-time streaming to downstream consumers.
Question 48: An architect needs to communicate an Azure architecture's recovery time objective (RTO) of 4 hours to operations and business stakeholders. Which scenario best validates that RTO has been understood by both audiences?
- Conduct a tabletop disaster recovery exercise where both operations and business stakeholders walk through the failure scenario and confirm acceptable downtime (Correct answer)
- Include RTO in the architecture diagram footnotes
- Have stakeholders sign the SLA document without a walkthrough
- Email the RTO value to all stakeholders and assume receipt equals understanding
Correct answer: Conduct a tabletop disaster recovery exercise where both operations and business stakeholders walk through the failure scenario and confirm acceptable downtime
Tabletop exercises validate that all stakeholders understand the practical meaning of RTO and confirm business acceptance of the recovery window.
Question 49: When designing a multi-region active-active architecture on Azure, which configuration ensures that read and write operations are distributed across all regions with lowest latency?
- Azure Front Door with origin groups
- Azure Traffic Manager with priority routing
- Azure SQL with active geo-replication
- Azure Cosmos DB with multi-region writes (Correct answer)
Correct answer: Azure Cosmos DB with multi-region writes
Azure Cosmos DB with multi-region writes (multi-master) allows read and write operations from any region simultaneously with guaranteed low latency.
Question 50: During a stakeholder review, a business owner asks why the architect recommends Azure Front Door instead of a simple load balancer for a global web app. What is the most accurate justification?
- Front Door provides global HTTP load balancing, WAF, SSL offload, and intelligent routing across regions (Correct answer)
- Front Door is cheaper than Azure Load Balancer for all scenarios
- Front Door supports more protocols than Load Balancer
- Front Door replaces the need for CDN in all cases
Correct answer: Front Door provides global HTTP load balancing, WAF, SSL offload, and intelligent routing across regions
Azure Front Door combines global HTTP(S) load balancing, WAF, SSL termination, and latency-based routing in a single service optimized for web applications.
Question 51: A research team evaluating Azure Cognitive Services must provide evidence that PII data never leaves a specific Azure region. Which compliance artifact provides authoritative residency evidence?
- Azure Security Center data classification report
- Azure Purview data map scan results
- Azure Monitor activity logs showing API call destinations
- Azure data residency documentation and the Cognitive Services regional endpoint configuration confirmed via ARM template (Correct answer)
Correct answer: Azure data residency documentation and the Cognitive Services regional endpoint configuration confirmed via ARM template
Using a region-specific Cognitive Services endpoint (documented in Azure data residency guidance) combined with ARM template deployment records provides authoritative evidence that data processing stays in-region.
Question 52: Under GDPR, a user requests deletion of all their personal data stored in your Azure SQL Database. Which approach best supports the 'right to be forgotten' requirement?
- Implement row-level security to hide the data
- Enable Transparent Data Encryption and rotate keys
- Archive the data to Azure Cold storage
- Delete the specific records and purge from backups within the required timeframe (Correct answer)
Correct answer: Delete the specific records and purge from backups within the required timeframe
GDPR's right to erasure requires actual deletion of personal data records, including purging from backups within a compliant timeframe.
Question 53: What is a corrective action in AZ-301 - Microsoft Azure Solutions Architect Expert quality systems?
- Ignoring minor issues
- Blaming individuals for errors
- Temporary workarounds only
- A systematic response to eliminate the cause of a detected nonconformity and prevent recurrence (Correct answer)
Correct answer: A systematic response to eliminate the cause of a detected nonconformity and prevent recurrence
This is fundamental to AZ-301 - Microsoft Azure Solutions Architect Expert practice. A systematic response to eliminate the cause of a detected nonconformity and prevent recurrence represents the professional standard for quality in the AZ-301 certification framework.
Question 54: A QA team needs to run exploratory tests and track manual test results in Azure. Which Azure DevOps service is designed specifically for this?
- Azure Pipelines
- Azure Boards
- Azure Test Plans (Correct answer)
- Azure Repos
Correct answer: Azure Test Plans
Azure Test Plans provides a browser-based interface for planning, executing, and tracking manual and exploratory tests.
Question 55: A solution architect needs to implement API management with throttling, caching, and developer portal features across multiple backend services. Which Azure service should be used?
- Azure Traffic Manager
- Azure Application Gateway
- Azure API Management (Correct answer)
- Azure Front Door
Correct answer: Azure API Management
Azure API Management provides throttling, caching, transformation policies, and a developer portal for managing APIs across multiple backends.
Microsoft Azure Architect Design (AZ-301)
AZ-301 measured candidates' ability to design Azure solutions covering identity and security, data platforms, business continuity, and infrastructure strategies. It was required alongside AZ-300 to earn the Microsoft Certified: Azure Solutions Architect Expert credential before being retired in June 2021.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds