Designing Microsoft Azure Infrastructure Solutions (AZ-305) — Questions and Answers
Question 1: You need to design a network that segments Azure resources into isolated tiers (web, app, data) with controlled traffic flow between tiers. What is the foundational design pattern?
- Use separate Azure regions for each tier
- Deploy all tiers in separate Azure subscriptions
- Use separate subnets with NSGs and UDRs between each tier (Correct answer)
- Use VNet peering between each tier's dedicated VNet
Correct answer: Use separate subnets with NSGs and UDRs between each tier
Separate subnets per tier with NSGs controlling allowed ports and UDRs optionally routing through an NVA is the standard n-tier Azure network design.
Question 2: A workload spans two Azure regions and needs fast, low-latency failover routing for TCP/UDP traffic. Which Azure service provides this?
- Azure Traffic Manager (DNS-based routing)
- Azure Cross-Region Load Balancer (Correct answer)
- Azure Front Door (HTTP/S only)
- Azure Application Gateway v2
Correct answer: Azure Cross-Region Load Balancer
Azure Cross-Region Load Balancer provides Layer 4 global load balancing across regions with ultra-low latency failover for non-HTTP workloads.
Question 3: Your data engineering team needs a storage account that supports hierarchical namespace for big data analytics workloads using Apache Spark. Which storage type should you enable?
- Azure Blob Storage with GRS replication
- Azure Data Lake Storage Gen2 (ADLS Gen2) with hierarchical namespace enabled (Correct answer)
- Azure Table Storage
- Azure Files Premium tier
Correct answer: Azure Data Lake Storage Gen2 (ADLS Gen2) with hierarchical namespace enabled
Enabling the hierarchical namespace on an Azure Storage account creates ADLS Gen2, which provides directory semantics and atomic operations optimized for analytics engines.
Question 4: Which Azure AD license tier is required to use both Privileged Identity Management and Identity Protection features?
- Azure AD Premium P1
- Azure AD Premium P2 (Correct answer)
- Azure AD Free
- Microsoft 365 E3
Correct answer: Azure AD Premium P2
Both PIM and Identity Protection are Azure AD Premium P2 features that require that specific license tier.
Question 5: You need to provide stakeholders with personalized recommendations to reduce Azure spending, improve reliability, and address security vulnerabilities without building custom queries. Which service should you use?
- Azure Monitor alerts
- Azure Policy initiatives
- Microsoft Defender for Cloud alerts
- Azure Advisor (Correct answer)
Correct answer: Azure Advisor
Azure Advisor analyzes your resource configurations and usage telemetry to provide prioritized, actionable recommendations across cost, reliability, security, performance, and operational excellence.
Question 6: You need to design an auto-scaling solution for Azure VMs that scales out based on custom application metrics from Azure Monitor. Which service enables this?
- Azure App Service autoscale
- Virtual Machine Scale Sets with Azure Monitor autoscale rules (Correct answer)
- Azure Load Balancer health probes
- Azure Automation runbooks on a schedule
Correct answer: Virtual Machine Scale Sets with Azure Monitor autoscale rules
VMSS autoscale rules integrate with Azure Monitor custom metrics to trigger scale-out or scale-in events based on any metric you instrument.
Question 7: You want to reuse the same set of email, SMS, and webhook notifications across multiple alert rules. Which Azure Monitor feature enables this?
- Alert processing rules
- Action groups (Correct answer)
- Alert rule sets
- Notification templates
Correct answer: Action groups
Action groups are reusable collections of notification and action preferences (email, SMS, webhook, ITSM, etc.) that can be referenced by multiple alert rules.
Question 8: A company wants to prevent users from enrolling personal devices in Azure AD and require only compliant corporate devices for cloud app access. Which two features should you combine?
- Azure AD Domain Services + Group Policy
- Azure Policy + Azure AD B2C
- Intune device compliance policies + Conditional Access (Correct answer)
- Azure AD Connect + Conditional Access
Correct answer: Intune device compliance policies + Conditional Access
Intune enforces device compliance standards and Conditional Access can then require a compliant device before granting access to cloud apps.
Question 9: Which Azure AD feature would you use to automatically grant or revoke users' access to applications based on their job role attributes?
- Conditional Access policies
- Entitlement Management access packages (Correct answer)
- Azure AD Privileged Identity Management
- Dynamic groups with automatic licensing
Correct answer: Entitlement Management access packages
Entitlement Management access packages bundle resources and define policies for who can request them and how long they retain access.
Question 10: You need to inspect and control traffic flowing between spoke VNets in a hub-and-spoke architecture. What must you configure in addition to deploying Azure Firewall in the hub?
- Network Security Groups on each spoke subnet
- Azure Policy network deny rules
- User-Defined Routes (UDRs) to redirect spoke traffic through the firewall (Correct answer)
- ExpressRoute gateway in the hub
Correct answer: User-Defined Routes (UDRs) to redirect spoke traffic through the firewall
UDRs (custom route tables) on spoke subnets must point the next hop to the Azure Firewall private IP to force traffic through inspection.
Question 11: You are designing a solution where Azure VMs need outbound internet access but must not have public IP addresses. Which managed service provides this?
- Azure NAT Gateway (Correct answer)
- Azure VPN Gateway
- Azure Load Balancer outbound rules
- Azure Bastion
Correct answer: Azure NAT Gateway
Azure NAT Gateway provides outbound internet connectivity for VMs in a subnet without requiring public IPs on each VM.
Question 12: You must suggest a remedy that satisfies App1's data specifications. Which deployment strategy should you advise for each availability zone that houses an instance of App1?
- An Azure Data Lake store that uses geo-zone-redundant storage (GZRS)
- An Azure Storage account that uses geo-zone-redundant storage (GZRS)
- An Azure SQL database that uses active geo-replication
- An Azure Cosmos DB that uses multi-region writes (Correct answer)
Correct answer: An Azure Cosmos DB that uses multi-region writes
For an application requiring high availability across multiple availability zones and low-latency data access, especially with data modification restrictions and the need for a robust database, Azure Cosmos DB with multi-region writes is the optimal choice. It provides global distribution, automatic failover, and guarantees low-latency reads and writes across multiple regions/zones, ensuring data consistency and resilience. This capability is superior for distributed write scenarios compared to other options.
Question 13: When deploying a resource on Azure, what choice do you frequently have to make?
- Choose the region where you want your resource deployed (Correct answer)
- Choose the network where you want your resource deployed
- Choose the datacenter where you want your resource deployed
- Choose the server where you want your resource deployed
Correct answer: Choose the region where you want your resource deployed
When deploying a resource on Azure, you frequently have to choose the region where you want your resource deployed. This decision is crucial as it determines the physical location of your resources, impacting factors like data residency, latency for users, and available services. Selecting the appropriate region helps optimize performance, meet regulatory requirements, and manage costs effectively.
Question 14: You need to stream Azure Monitor logs in near-real-time to Microsoft Sentinel for SIEM analysis. Which Azure service is the recommended streaming pipeline?
- Azure Event Hubs (Correct answer)
- Azure Storage Queue
- Azure Relay
- Azure Service Bus
Correct answer: Azure Event Hubs
Azure Event Hubs is the recommended high-throughput streaming pipeline for exporting Azure Monitor logs to external systems like Microsoft Sentinel and third-party SIEMs.
Question 15: Which Azure SQL Database feature automatically redirects application connections to the secondary replica during a regional failure without requiring connection string changes?
- Azure SQL Managed Instance link feature
- Azure Traffic Manager with SQL endpoints
- Geo-replication with manual failover and secondary endpoint
- Auto-failover group listener endpoint (Correct answer)
Correct answer: Auto-failover group listener endpoint
Auto-failover group listener endpoints (read-write and read-only) remain constant; after failover, they automatically point to whichever replica is now the primary.
Question 16: A database workload requires sub-millisecond disk latency with guaranteed IOPS for mission-critical OLTP. Which Azure Disk type should you choose?
- Ultra Disk Managed Disks (Correct answer)
- Standard SSD Managed Disks
- Premium SSD Managed Disks
- Standard HDD Managed Disks
Correct answer: Ultra Disk Managed Disks
Ultra Disks provide sub-millisecond latency and allow you to dynamically configure IOPS and throughput without detaching the disk.
Question 17: A developer needs read access to a specific Azure Storage account but must not have any permissions on other resources in the resource group. Which scope should you use for the role assignment?
- Resource group scope
- Subscription scope
- Management group scope
- Resource scope (Correct answer)
Correct answer: Resource scope
Assigning a role at the individual resource scope limits the permissions to only that specific Storage account.
Question 18: A company needs to allow users from a partner organization to access Azure resources without creating new accounts. Which Azure AD feature should you recommend?
- Azure AD B2B collaboration (Correct answer)
- Azure AD Domain Services
- Azure AD B2C
- Azure AD Connect
Correct answer: Azure AD B2B collaboration
Azure AD B2B collaboration lets you invite external users from partner organizations to access your Azure resources using their existing identities.
Question 19: You are designing storage for an IoT application that ingests millions of small messages per second and needs a hot path for immediate analytics. Which combination is recommended?
- Azure Service Bus + Azure Databricks + Azure Cosmos DB
- Azure Event Hubs + Azure Stream Analytics + Azure Data Lake Storage Gen2 (Correct answer)
- Azure Queue Storage + Azure Functions + Azure SQL Database
- Azure Blob Storage + Azure Synapse Analytics
Correct answer: Azure Event Hubs + Azure Stream Analytics + Azure Data Lake Storage Gen2
Event Hubs captures the high-throughput stream, Stream Analytics processes data in real time, and ADLS Gen2 stores the cold path for batch analytics.
Question 20: Your analytics pipeline requires transactional consistency for writes but also needs to run OLAP queries over the same data without impacting OLTP performance. Which Azure Cosmos DB feature enables this?
- Cosmos DB Analytical Store (HTAP with Azure Synapse Link) (Correct answer)
- Cosmos DB multi-region writes
- Cosmos DB change feed
- Cosmos DB automatic indexing
Correct answer: Cosmos DB Analytical Store (HTAP with Azure Synapse Link)
Azure Synapse Link with the Cosmos DB Analytical Store provides a fully isolated columnar store updated in near real-time from the transactional store for HTAP scenarios.
Question 21: Which Azure Firewall feature allows it to perform deep packet inspection and decrypt TLS traffic to detect and block hidden threats?
- Azure Firewall Premium with TLS inspection and IDPS (Correct answer)
- Azure Firewall Standard with application rules
- Azure WAF with custom rules
- Azure DDoS Protection Standard
Correct answer: Azure Firewall Premium with TLS inspection and IDPS
Azure Firewall Premium includes TLS inspection (MITM decryption) and IDPS (Intrusion Detection and Prevention System) for deep packet analysis.
Question 22: You have an Azure SQL database with the name SQL l and a multi-tier app with the name Appl. Users utilize the Appl client to read data from SQL 1 that is written by the backend service of the App. <br> <br> During periods of high utilization the users experience delays retrieving the data <br> <br> You need to minimize how long it takes for data requests <br> <br> What should you include in the solution?
- Azure Content Delivery Network (CON)
- Azure Data Factory
- Azure Synapse Analytics
- Azure Cache for Redis (Correct answer)
Correct answer: Azure Cache for Redis
Azure Cache for Redis is an in-memory data store designed to significantly improve application performance by caching frequently accessed data. When users experience delays retrieving data from an Azure SQL database during high utilization, implementing Redis cache can store copies of this data closer to the application. This reduces the load on the primary database, minimizes latency, and speeds up data retrieval for users, effectively addressing performance bottlenecks.
Question 23: An application writes large files to Azure Blob Storage and needs to ensure files are only visible to readers after the entire upload is complete. Which upload method ensures this?
- Block Blob upload with Commit Block List as the final step (Correct answer)
- Put Blob for small files; multipart upload for large files
- Page Blob upload
- Append Blob upload
Correct answer: Block Blob upload with Commit Block List as the final step
Block Blob staging uploads data in blocks using Put Block, and only the final Commit Block List operation makes the complete blob visible to readers.
Question 24: You need to deploy an application to Azure that requires low-latency GPU processing for AI inference workloads. Which VM series should you select?
- Mv2-series (memory optimized)
- Lsv3-series (storage optimized)
- Dv5-series (general purpose)
- NCv3 or NDv2-series (GPU compute) (Correct answer)
Correct answer: NCv3 or NDv2-series (GPU compute)
NC and ND-series VMs are equipped with NVIDIA GPUs (V100, A100) specifically designed for AI/ML training and inference workloads.
Question 25: Your organization needs to reduce Azure VM costs by up to 72% for workloads that can tolerate interruptions. Which pricing model should you use?
- On-demand VMs with auto-shutdown
- Reserved VM Instances (1-year)
- Dev/Test pricing
- Azure Spot Virtual Machines (Correct answer)
Correct answer: Azure Spot Virtual Machines
Azure Spot VMs use unused Azure capacity at up to 90% discount but can be evicted with 30 seconds' notice when Azure needs the capacity back.
Question 26: Which Azure Backup feature ensures that backups cannot be deleted for a specified retention period, protecting against ransomware or malicious administrators?
- Immutable vault with locked policy (Correct answer)
- Soft delete for Azure Backup
- Azure Backup geo-redundancy
- Resource lock on the Recovery Services vault
Correct answer: Immutable vault with locked policy
Immutable vault with a locked policy prevents any modification or deletion of backup data and policies for the configured retention window, even by subscription administrators.
Question 27: You need to document your DR strategy with defined RTO and RPO targets. Which statement correctly defines these two terms?
- RTO and RPO are both measured as the time since last backup
- RTO is the maximum acceptable data loss; RPO is the time to recover services
- RPO is the recovery point in a secondary datacenter; RTO is the recovery time objective for primary
- RTO is the time to restore services to operation; RPO is the maximum acceptable data loss measured in time (Correct answer)
Correct answer: RTO is the time to restore services to operation; RPO is the maximum acceptable data loss measured in time
RTO (Recovery Time Objective) defines how quickly systems must be restored; RPO (Recovery Point Objective) defines how much data loss is acceptable, measured as time since last backup/replication.
Question 28: You are designing a multi-region architecture and need to ensure that DNS automatically fails over to the secondary region when the primary becomes unhealthy. Which Azure service provides this?
- Azure Private DNS zones
- Azure Front Door with origin health probes
- Azure DNS with manual TTL management
- Azure Traffic Manager with health endpoint monitoring (Correct answer)
Correct answer: Azure Traffic Manager with health endpoint monitoring
Azure Traffic Manager monitors endpoint health and automatically updates DNS responses to route traffic to healthy endpoints when a primary region fails.
Question 29: You need to ensure that a Storage account's data cannot be deleted or modified for 7 years to comply with financial regulations. Which feature should you configure?
- Immutable storage with time-based retention policies (WORM) (Correct answer)
- Azure Storage versioning
- Azure Backup for storage accounts
- Soft delete with 7-day retention
Correct answer: Immutable storage with time-based retention policies (WORM)
Immutable Blob Storage with time-based retention (WORM) policies prevents any deletion or modification of blobs for the specified retention period.
Question 30: You need to design a solution where your application continues operating with zero downtime and zero data loss even if an entire Azure region becomes unavailable. Which deployment model achieves this?
- Geo-redundant storage with read-only secondary
- Active-active multi-region deployment with Azure Traffic Manager or Front Door (Correct answer)
- Single region with Availability Zones
- Active-passive with Azure Site Recovery and manual failover
Correct answer: Active-active multi-region deployment with Azure Traffic Manager or Front Door
An active-active multi-region deployment serves live traffic from multiple regions simultaneously; if one region fails, Traffic Manager or Front Door routes all traffic to the remaining healthy region with no downtime.
Question 31: Your application needs to store petabytes of unstructured data with tiered access: frequently accessed data served quickly and archival data stored cheaply. Which Azure Storage configuration best meets this need?
- Azure Disk Storage with Ultra tier
- Azure Data Lake Storage Gen2 with ZRS replication
- Azure Files with Premium tier
- Azure Blob Storage with Hot, Cool, and Archive tiers using lifecycle management policies (Correct answer)
Correct answer: Azure Blob Storage with Hot, Cool, and Archive tiers using lifecycle management policies
Azure Blob Storage lifecycle management policies automatically move data between Hot, Cool, Cold, and Archive tiers based on last-modified or last-accessed time.
Question 32: Your web application is hosted in Azure and needs to be protected against OWASP top-10 web vulnerabilities at the network edge. Which service should you enable?
- Azure DDoS Protection Standard
- Azure Web Application Firewall (WAF) (Correct answer)
- Azure Firewall Premium with IDPS
- Network Security Groups
Correct answer: Azure Web Application Firewall (WAF)
Azure WAF, deployable on Application Gateway or Front Door, inspects HTTP/S traffic against OWASP rule sets to block common web attacks.
Question 33: Your security team requires that stale guest accounts be automatically removed after 90 days of inactivity. Which feature enables this?
- Azure AD Conditional Access
- Azure AD Identity Protection
- Azure AD Access Reviews (Correct answer)
- Azure Policy guest user restrictions
Correct answer: Azure AD Access Reviews
Azure AD Access Reviews can be configured to periodically evaluate guest account activity and automatically remove inactive accounts.
Question 34: A multi-tenant SaaS application needs to authenticate users from thousands of different Azure AD tenants. What is the recommended design?
- Create guest accounts in a single tenant for all users
- Use Azure AD B2C for all tenants
- Register the app as a multi-tenant application in Azure AD (Correct answer)
- Deploy a separate Azure AD tenant per customer
Correct answer: Register the app as a multi-tenant application in Azure AD
Registering an app as multi-tenant allows users from any Azure AD tenant to consent and sign in without requiring guest account creation.
Question 35: You need to design an identity solution for a consumer-facing mobile application where users can sign in with Google or Facebook. Which service is most appropriate?
- Azure AD B2C (Correct answer)
- Azure Active Directory Domain Services
- Azure AD External Identities (workforce)
- Azure AD B2B collaboration
Correct answer: Azure AD B2C
Azure AD B2C is designed for customer-facing applications and supports social identity providers like Google and Facebook out of the box.
Question 36: You need to grant a third-party application temporary read access to specific blobs in a private storage container without exposing the account key. Which mechanism should you use?
- Azure Storage account key
- Azure AD managed identity
- Shared Access Signature (SAS) token with limited permissions and expiry (Correct answer)
- Storage account public access level
Correct answer: Shared Access Signature (SAS) token with limited permissions and expiry
A SAS token can be scoped to specific containers or blobs, limited to read permissions, and set to expire at a specific time, providing secure temporary access.
Question 37: You need to create interactive, shareable visual reports that combine Azure Monitor metrics, logs, and Azure Resource Graph data in a single view. Which feature should you use?
- Azure Monitor workbooks (Correct answer)
- Azure Monitor dashboards
- Power BI Embedded reports
- Azure Metrics Explorer
Correct answer: Azure Monitor workbooks
Azure Monitor workbooks provide a flexible, interactive canvas that can combine data from multiple sources—metrics, logs, Azure Resource Graph—into parameterized reports for sharing.
Question 38: You need to design a solution where service-to-service authentication happens without storing credentials in code or configuration files. Which approach is recommended?
- Create a shared service principal with a certificate
- Store credentials in Azure Key Vault secrets and retrieve them at runtime
- Use Azure Managed Identities (Correct answer)
- Use Azure AD B2B for service accounts
Correct answer: Use Azure Managed Identities
Managed Identities eliminate the need to manage credentials by providing Azure resources with an automatically managed identity in Azure AD.
Question 39: To create a monthly report of all new Azure Resource Manager (ARM) resource deployments in your Azure subscription, you must suggest a solution. What should you include in the recommendation?
- Azure Analysis Services
- Azure Advisor
- Azure Activity Log (Correct answer)
- Azure Monitor action groups
Correct answer: Azure Activity Log
The Azure Activity Log records all subscription-level events, including the creation, update, and deletion of Azure Resource Manager (ARM) resources. To generate a monthly report of all new ARM resource deployments, the Activity Log is the definitive source as it captures these management plane operations. You can query and export data from the Activity Log to compile the required report, making it the ideal solution for auditing resource deployment activities.
Question 40: A solution for the Azure IoT Hub that will contain 50,000 IoT devices is what you are designing. Temperature, device ID, and time data will all be streamed by each device. <br> <br> Every second, 50,000 records will be written on average. Near real-time visualization of the data will be used. You must suggest a service that can store and search the data. <br> <br> Which two services would you suggest?
- Azure Time Series Insights (Correct answer)
- Azure Cosmos DB SQL API (Correct answer)
- Azure Event Grid
- Azure Table Storage
Correct answer: Azure Time Series Insights
For streaming IoT data from 50,000 devices with high write volume and near real-time visualization, Azure Time Series Insights is ideal for storing, visualizing, and analyzing time-series data at scale. Azure Cosmos DB SQL API is also a strong choice due to its ability to handle high-volume, low-latency writes and reads, support for SQL queries, and global distribution capabilities, making it suitable for storing and searching the raw or processed IoT data.
Question 41: Your organization uses Azure Backup for VMs and needs to ensure backup data stored in the Recovery Services vault remains available even if the primary Azure region fails. Which vault replication setting should you choose?
- Locally Redundant Storage (LRS) — 3 copies in same datacenter
- Zone-Redundant Storage (ZRS) — 3 zones in same region
- Read-Access Geo-Redundant Storage (RA-GRS)
- Geo-Redundant Storage (GRS) — primary + secondary region copies (Correct answer)
Correct answer: Geo-Redundant Storage (GRS) — primary + secondary region copies
GRS replicates vault data to a paired region, ensuring backup data survives a complete primary region failure and can be used for cross-region restore.
Question 42: You are creating a program that will run on Azure. The program will store video files with sizes varying from 50 MB to 12 GB. Users will be able to access the application online and it will employ certificate-based authentication. You must suggest a location for the video files to be stored. The solution must minimize storage costs while offering the quickest read speed. What ought to you suggest?
- Azure SQL Database
- Azure Data Lake Storage Gen2
- Azure Blob Storage (Correct answer)
- Azure Files
Correct answer: Azure Blob Storage
Azure Blob Storage is the ideal solution for storing large video files ranging from 50 MB to 12 GB due to its scalability, cost-effectiveness, and optimization for unstructured data. It offers different access tiers, where the "Hot" tier provides the quickest read speeds, aligning with the requirement for fast access. Blob Storage is accessible online via HTTP/HTTPS and supports certificate-based authentication, making it a comprehensive and efficient choice for this scenario while minimizing storage costs.
Question 43: You are creating a sales application that will manage many transactional components and include several Azure cloud services. The processing of customer orders, billing, payments, inventory, and shipping will be handled by various cloud services. You must suggest a solution that will allow the cloud services to asynchronously exchange transactional data using XML messages. What should the recommendation contain?
- Azure Service Bus (Correct answer)
- Azure Service Fabric
- Azure Data Lake
- Azure Traffic Manager
Correct answer: Azure Service Bus
Azure Service Bus is a robust enterprise message broker designed for asynchronous communication between decoupled applications and services. It provides reliable message queuing and publish/subscribe capabilities, making it ideal for exchanging transactional data like XML messages between various cloud services. This ensures that customer orders, billing, and other components can communicate efficiently and reliably without direct dependencies, even during peak loads.
Question 44: Your data warehouse needs to query petabytes of data with massively parallel processing (MPP). Which Azure service is designed for this workload?
- Azure Cosmos DB analytical store
- Azure SQL Database Hyperscale
- Azure Synapse Analytics dedicated SQL pool (Correct answer)
- Azure SQL Managed Instance
Correct answer: Azure Synapse Analytics dedicated SQL pool
Azure Synapse Analytics dedicated SQL pool uses MPP architecture to distribute query processing across compute nodes for petabyte-scale analytical queries.
Question 45: Your company is implementing a Zero Trust architecture. Which Azure AD capability most directly supports the 'verify explicitly' principle?
- Azure AD Application Proxy
- Azure AD Password Hash Synchronization
- Azure AD Connect cloud sync
- Conditional Access with device compliance, location, and risk signals (Correct answer)
Correct answer: Conditional Access with device compliance, location, and risk signals
Conditional Access 'verify explicitly' by evaluating all available signals (user identity, device state, location, risk) before granting access.
Question 46: You need to ensure that diagnostic settings are automatically configured on all newly created Azure resources to forward logs to a Log Analytics workspace. Which approach should you implement?
- Azure Automation runbook on a schedule
- Azure Policy with deployIfNotExists effect (Correct answer)
- Azure Logic Apps triggered by Activity Log
- Azure Monitor alert with auto-remediation
Correct answer: Azure Policy with deployIfNotExists effect
Azure Policy with the deployIfNotExists effect automatically deploys diagnostic settings to compliant resources, including newly created ones, without manual intervention.
Question 47: You need to design a disaster recovery test plan for Azure VMs protected by Azure Site Recovery that does not impact production workloads. Which ASR capability supports this?
- Unplanned failover with commit
- Reprotection after failover
- Planned failover to the secondary region
- Test failover using an isolated Azure VNet (Correct answer)
Correct answer: Test failover using an isolated Azure VNet
ASR Test Failover spins up replicated VMs in an isolated VNet without disrupting replication to the primary, allowing full DR validation without production impact.
Question 48: You need an alert that fires when CPU utilization on a VM exceeds 80% for five consecutive minutes. Which Azure Monitor alert type should you use?
- Metric alert (Correct answer)
- Smart detection alert
- Activity log alert
- Log search alert
Correct answer: Metric alert
Metric alerts evaluate numeric resource metrics at regular intervals and trigger when a threshold is crossed, making them ideal for CPU utilization monitoring.
Question 49: What do Azure regions' availability zones do?
- Different datacenters owned by competitors
- Different regions of Azure
- Different Azure datacenters within a region (Correct answer)
- Virtual locations within an Azure datacenter
Correct answer: Different Azure datacenters within a region
Azure regions' Availability Zones are physically separate, independent datacenters located within a single Azure region. Each zone has its own independent power, cooling, and networking, providing isolation from failures in other zones within the same region. This architecture ensures high availability and fault tolerance for applications and data by distributing resources across these distinct physical locations.
Question 50: A solution requires managing access to hundreds of Azure resources for groups of users whose membership changes frequently. Which approach minimizes administrative overhead?
- Assign RBAC roles directly to each user
- Create a separate subscription per user group
- Use Azure Policy for identity management
- Use Azure AD groups with RBAC role assignments (Correct answer)
Correct answer: Use Azure AD groups with RBAC role assignments
Assigning RBAC roles to Azure AD groups means you only manage group membership rather than updating individual role assignments as users change.
Question 51: A storage account must only accept connections from a specific set of Azure VNet subnets and deny all other traffic including from the internet. Which two features should you configure?
- Storage account firewall with allowed public IPs only
- Private Endpoints only
- Azure Firewall DNAT + Storage account private endpoint
- Service Endpoints on subnets + Storage account network firewall deny rule with VNet subnet exceptions (Correct answer)
Correct answer: Service Endpoints on subnets + Storage account network firewall deny rule with VNet subnet exceptions
Enabling service endpoints on the subnets and adding those subnets to the storage account's firewall allow list while setting the default action to Deny restricts access to only those subnets.
Question 52: A customer needs to migrate an on-premises Oracle database to Azure with minimal re-engineering and maximum compatibility. Which Azure database service should you recommend?
- Azure SQL Managed Instance (Correct answer)
- Azure Database for Oracle (fully managed)
- Azure SQL Database
- Azure Database for PostgreSQL – Flexible Server
Correct answer: Azure SQL Managed Instance
Azure SQL Managed Instance provides near 100% SQL Server engine compatibility and supports features like SQL Agent, CLR, and linked servers needed for lift-and-shift migrations.
Question 53: You need to host a stateful microservice that requires persistent storage volumes, custom scheduling, and runs multiple replicas with automatic restarts. Which service is best suited?
- Azure Container Instances
- Azure Logic Apps
- Azure Kubernetes Service (AKS) (Correct answer)
- Azure Functions Durable Functions
Correct answer: Azure Kubernetes Service (AKS)
AKS provides full Kubernetes orchestration including StatefulSets with persistent volumes, pod scheduling controls, and self-healing with restart policies.
Question 54: Your organization needs automated, policy-driven backup for all Azure VMs across 20 subscriptions from a single interface. Which Azure service provides this centralized management?
- Azure Backup Center with a Backup policy at management group scope (Correct answer)
- Azure Site Recovery centralized console
- Individual Recovery Services vaults per subscription
- Azure Policy with DeployIfNotExists for backup
Correct answer: Azure Backup Center with a Backup policy at management group scope
Azure Backup Center provides a unified view and governance console to monitor, manage, and enforce backup policies across multiple vaults and subscriptions.
Question 55: Which Azure Cosmos DB feature provides continuous backup and allows you to restore your database to any point in the past 30 days?
- Geo-redundant backup with 4-hour snapshot intervals
- Manual backup export to Storage Account
- Continuous backup mode with point-in-time restore (PITR) (Correct answer)
- Multi-region writes with regional failover
Correct answer: Continuous backup mode with point-in-time restore (PITR)
Cosmos DB Continuous backup mode captures changes continuously allowing point-in-time restore to any second within the past 30 days.
Question 56: You need to design a caching layer to reduce read latency for an Azure SQL Database backing a high-traffic web application. Which service should you add?
- Azure Cache for Redis (Correct answer)
- Azure SQL Database read replicas
- Azure Content Delivery Network (CDN)
- Azure Cosmos DB as a cache
Correct answer: Azure Cache for Redis
Azure Cache for Redis provides an in-memory key-value store that dramatically reduces database read latency by caching frequently queried data.
Question 57: Which Azure Load Balancer SKU is required to support cross-zone load balancing, global load balancing, and availability zones?
- Basic SKU
- Gateway SKU
- Premium SKU
- Standard SKU (Correct answer)
Correct answer: Standard SKU
Azure Load Balancer Standard SKU supports availability zones, cross-zone load balancing, and HTTPS health probes that the Basic SKU does not.
Question 58: You have an on-premises Active Directory domain that is synchronized with an Azure Active Directory (Azure AD) tenant. WebApp1 is an internal web application that is hosted on your premises. WebApp1 makes use of Windows Integrated authentication. Some users access the on-premises network via remote access but do not have VPN access. You must grant single sign-on (SSO) access to WebApp1 to the remote users. What two features ought to be incorporated into the solution?
- Azure AD Privileged Identity Management (PIM)
- Azure Arc
- Azure AD enterprise applications (Correct answer)
- Azure AD Application Proxy (Correct answer)
- Azure Application Gateway
- Conditional Access policies
Correct answer: Azure AD enterprise applications
Azure AD Application Proxy is essential for securely publishing on-premises web applications, like WebApp1, to external users without requiring VPN access. By integrating with Azure AD enterprise applications, it enables single sign-on (SSO) for these remote users, leveraging their Azure AD credentials to access the internal application that uses Windows Integrated Authentication. This combination allows seamless and secure access from outside the corporate network.
Question 59: Your organization runs a legacy application that uses LDAP for authentication. You want to migrate it to Azure without rewriting the app. Which service should you use?
- Azure AD Connect
- Azure Active Directory Domain Services (Azure AD DS) (Correct answer)
- Azure AD External Identities
- Azure AD B2C
Correct answer: Azure Active Directory Domain Services (Azure AD DS)
Azure AD DS provides managed domain services including LDAP, Kerberos, and NTLM so legacy apps can authenticate without code changes.
Question 60: What is the key difference between Azure Site Recovery's 'planned failover' and 'unplanned failover' options?
- Planned failover costs more than unplanned
- Planned failover requires manual steps while unplanned is automatic
- Planned failover ensures zero data loss by flushing changes to secondary first; unplanned may have minimal data loss (Correct answer)
- Unplanned failover creates a new replication link automatically
Correct answer: Planned failover ensures zero data loss by flushing changes to secondary first; unplanned may have minimal data loss
A planned failover waits for all pending replication changes to sync to the secondary before cutting over, ensuring zero data loss, while unplanned failover immediately promotes the secondary at the risk of losing recent unsynced changes.
Question 61: Your application requires that Azure PaaS services like Azure SQL Database be accessible only from within your VNet and not over the public internet. Which feature should you use?
- Azure Private Link service
- Private Endpoints (Correct answer)
- VNet Integration
- Service endpoints
Correct answer: Private Endpoints
Private Endpoints assign a private IP from your VNet to a PaaS service, making it accessible only from your VNet while the public endpoint can be disabled.
Question 62: You need to design a backup strategy for Azure Blob Storage where accidental deletions can be recovered within 30 days. Which feature provides this at no additional storage cost for the retention period?
- Blob Storage versioning
- Azure Blob soft delete (Correct answer)
- Azure Backup for Blob Storage
- Object replication to a secondary account
Correct answer: Azure Blob soft delete
Blob soft delete retains deleted blobs for a configurable retention period and is built into Azure Blob Storage without requiring a separate backup vault.
Question 63: You need to design a relational database solution in Azure that automatically scales compute independently of storage for unpredictable workloads. Which service tier should you choose?
- Azure SQL Managed Instance Business Critical
- Azure SQL Database Hyperscale
- Azure SQL Database General Purpose
- Azure SQL Database Serverless (Correct answer)
Correct answer: Azure SQL Database Serverless
Azure SQL Database Serverless tier auto-pauses when idle and auto-scales compute vCores based on workload demand, billed per second of compute used.
Question 64: You intend to distribute several Azure web app instances across various Azure regions. <br> <br> * Support rate limiting. <br> <br> * Balance requests between all instances. <br> <br> * Ensure that users can access the app in the event of a regional outage. <br> Solution: You use Azure Front Door to provide access to the app. <br> <br> Does this meet the goal?
- No
- Yes (Correct answer)
Correct answer: Yes
Azure Front Door is a global, scalable entry-point that effectively meets all the specified requirements. It provides Layer 7 load balancing across multiple Azure web app instances deployed in different regions, ensuring optimal traffic distribution. Furthermore, Azure Front Door supports rate limiting through its Web Application Firewall (WAF) capabilities, and its global failover mechanism ensures that users can access the application even in the event of a regional outage, providing high availability and resilience.
Question 65: You need to design a shared file system for a legacy Windows application that requires SMB access from Azure VMs and on-premises servers simultaneously. Which solution is appropriate?
- Azure Files with SMB shares (Correct answer)
- Azure Data Lake Storage Gen2
- Azure NetApp Files
- Azure Blob Storage with NFS mount
Correct answer: Azure Files with SMB shares
Azure Files provides fully managed SMB file shares accessible from both Azure VMs and on-premises via Azure File Sync or direct SMB over the internet.
Designing Microsoft Azure Infrastructure Solutions (AZ-305)
The AZ-305 exam validates expertise in designing cloud and hybrid Azure solutions, covering identity and governance, data storage, business continuity, and infrastructure design. It is required for the Microsoft Certified: Azure Solutions Architect Expert certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds