Exam AZ-204: Developing Solutions for Microsoft Azure — Questions and Answers
Question 1: You work for your company as a developer. For an existing Logic App, the definitions need to be updated. Which should you employ?
- the Logic Apps Designer
- the Logic App Code View (Correct answer)
- the API Connections
- the Enterprise Integration Pack (EIP)
Correct answer: the Logic App Code View
While the Logic Apps Designer provides a visual interface for building and modifying workflows, the Logic App Code View offers direct access to the underlying JSON definition of the Logic App. This view is essential for making precise, bulk, or advanced updates to the workflow's structure, actions, and triggers that might be difficult or impossible through the graphical designer alone. It provides granular control over the Logic App's definition.
Question 2: Which Azure CLI command deploys a local ZIP file to an Azure App Service web app?
- az appservice deploy app.zip
- az webapp zip-deploy --file app.zip
- az webapp publish app.zip
- az webapp deploy --src-path app.zip (Correct answer)
Correct answer: az webapp deploy --src-path app.zip
`az webapp deploy --src-path app.zip` is the current recommended command for ZIP deployment to App Service.
Question 3: What command initializes a new Azure Functions project using the Azure Functions Core Tools?
- func create
- func new
- func start
- func init (Correct answer)
Correct answer: func init
`func init` scaffolds a new Azure Functions project with the appropriate host configuration for the chosen runtime.
Question 4: Which Azure App Service feature isolates your app in a dedicated virtual network for compliance and security?
- Hybrid Connections
- VNet Integration
- App Service Environment (ASE) (Correct answer)
- Private Link
Correct answer: App Service Environment (ASE)
App Service Environment (ASE) deploys App Service infrastructure inside a customer-managed VNet for full network isolation.
Question 5: After moving the application to Azure, you must make sure to establish the backup solution. For this need, which of the following would you develop first?
- Create a recovery services vault (Correct answer)
- Create a recovery plan
- Create a backup policy
- Create an Azure Backup Server
Correct answer: Create a recovery services vault
To implement a backup solution for an application after it is moved to Azure, the first step would be to create a Recovery Services vault.
Question 6: In an Azure Function, what interface should the injected logger implement for structured logging?
- TraceWriter
- ILogger (Correct answer)
- DiagnosticSource
- EventLog
Correct answer: ILogger
Azure Functions supports `ILogger` (from Microsoft.Extensions.Logging) for structured, leveled log output that integrates with Application Insights.
Question 7: What is the purpose of a stored procedure in Azure Cosmos DB?
- To schedule recurring maintenance tasks on a container
- To execute a batch of operations as an ACID transaction within a single partition (Correct answer)
- To manage container throughput dynamically
- To replicate data between regions automatically
Correct answer: To execute a batch of operations as an ACID transaction within a single partition
Stored procedures in Cosmos DB are JavaScript functions executed server-side and provide ACID transaction guarantees, but only within a single logical partition.
Question 8: What is the purpose of the `local.settings.json` file in Azure Functions development?
- Stores connection strings and app settings for local development only (Correct answer)
- Sets the runtime version for deployment
- Defines production environment variables
- Configures binding extensions
Correct answer: Stores connection strings and app settings for local development only
`local.settings.json` holds app settings and connection strings used only during local development and should never be committed to source control.
Question 9: Which Azure Functions Premium plan feature keeps at least one warm instance ready to eliminate cold starts?
- Instance pooling
- Pre-warmed instances (Correct answer)
- Always On setting
- Reserved instances
Correct answer: Pre-warmed instances
The Premium plan's pre-warmed instances maintain at least one initialized host ready to respond instantly, eliminating cold start latency.
Question 10: You create a solution that stores user data for a mobile app in an Azure SQL Database. Sensitive information about users is stored in the app. Sensitive information needs to be kept hidden from developers who access the data for the mobile app. When configuring dynamic data masking, which three things must you specify? Each accurate response offers a piece of the answer. NOTE: There are three (3) answers in this question.
- Table (Correct answer)
- Index
- Column (Correct answer)
- Schema (Correct answer)
Correct answer: Table
Dynamic Data Masking (DDM) in Azure SQL Database is configured to obscure sensitive data from non-privileged users without altering the actual data. To implement DDM, you must specify the exact location of the sensitive data: the (C) Schema, the (D) Table within that schema, and the (B) Column within that table that needs to be masked. This granular specification ensures only the intended sensitive fields are protected.
Question 11: You manage an Azure solution that is presently experiencing performance problems. <br> <br> You need to find the cause of the performance issues pertaining to metrics on the Azure infrastructure. <br> <br> Which of the following is the tool you should use?
- Azure Monitor (Correct answer)
- Azure Activity Log
- Azure Traffic Analytics
- Azure Advisor
Correct answer: Azure Monitor
The time-series database that stores metrics in Azure Monitor is designed for time-stamped data analysis. Metrics are, therefore, particularly well suited for alerting and quick issue discovery.
Question 12: Azure Active Directory (Azure AD) is a subscription owned by your business. <br> You wish to establish a conditional access policy for Azure AD. <br> When connecting to Azure AD from untrusted places, members of the Global Administrators group must utilize Multi-Factor Authentication and a device that is connected to Azure AD. <br> Solution: To change the user settings, go to the multi-factor authentication page. <br> Is the aim being met by the solution?
- Yes
- No (Correct answer)
Correct answer: No
The multi-factor authentication page only lets you enable or disable MFA on a per-user basis — it cannot enforce MFA based on conditions like sign-in location or require an Azure AD-joined device. Those conditional requirements (untrusted locations, Global Administrators, device state) can only be enforced with an Azure AD Conditional Access policy, so changing user settings on the MFA page does not meet the goal.
Question 13: You use an Azure AD-joined device to control your company's Azure Kubernetes Service (AKS) cluster. The resource group in which the cluster is situated. MyApp is a program that developers have made. A container image containing MyApp was created. The application's YAML manifest file has to be deployed. Solution: You perform the kubectl apply '""f myapp.yaml command after installing the Azure CLI on the device. Is the objective being met?
- Yes (Correct answer)
- No
Correct answer: Yes
The `kubectl apply -f myapp.yaml` command is the standard and correct method for deploying an application defined in a YAML manifest file to a Kubernetes cluster. By installing the Azure CLI and configuring `kubectl` to interact with the Azure Kubernetes Service (AKS) cluster, a developer can successfully deploy the containerized application, thus meeting the objective.
Question 14: What Azure Service Bus entity allows publish-subscribe messaging where multiple subscribers each receive a copy of the message?
- Event stream
- Relay
- Queue
- Topic with subscriptions (Correct answer)
Correct answer: Topic with subscriptions
Service Bus topics with subscriptions implement the pub/sub pattern: each subscription gets its own independent copy of every message published to the topic.
Question 15: Which Azure Functions trigger fires a function on a schedule defined by a CRON expression?
- Timer trigger (Correct answer)
- Event Grid trigger
- HTTP trigger
- Queue trigger
Correct answer: Timer trigger
The Timer trigger executes a function at intervals or on specific times defined by a NCRONTAB expression.
Question 16: What happens when you set Time to Live (TTL) to -1 on an Azure Cosmos DB container?
- The container is deleted automatically
- Items expire immediately after creation
- Items expire after 1 second
- TTL is disabled and items never expire (Correct answer)
Correct answer: TTL is disabled and items never expire
Setting TTL to -1 on the container enables TTL at the container level but items only expire if they have an explicit _ttl property set on them; without it they live forever.
Question 17: In Azure Cosmos DB, what is a logical partition?
- A subset of items in a container that share the same partition key value (Correct answer)
- A read-only copy of the container for reporting purposes
- A separate billing unit within a Cosmos DB account
- A geographic replica of the container in another Azure region
Correct answer: A subset of items in a container that share the same partition key value
A logical partition is the set of all items in a container that have the same partition key value; Cosmos DB distributes logical partitions across physical partitions to scale throughput.
Question 18: Which setting in `host.json` configures the Application Insights instrumentation key for a Functions app?
- host.json insights.key
- APPLICATIONINSIGHTS_CONNECTION_STRING app setting (Correct answer)
- APPINSIGHTS_INSTRUMENTATIONKEY in local.settings.json
- logging.applicationInsights.samplingSettings
Correct answer: APPLICATIONINSIGHTS_CONNECTION_STRING app setting
Azure Functions connects to Application Insights via the `APPLICATIONINSIGHTS_CONNECTION_STRING` application setting (preferred over instrumentation key).
Question 19: In Azure Container Registry, which command authenticates the Docker CLI to a private registry?
- az acr login --name <registry> (Correct answer)
- az acr authenticate
- docker login azure
- az login --container
Correct answer: az acr login --name <registry>
`az acr login --name <registry>` uses Azure CLI credentials to authenticate Docker with the specified ACR instance.
Question 20: You have a tenant called contoso.com in your production Azure Active Directory (Azure AD). You deploy a development Azure Active Directory (AD) tenant and provide the development tenant with several unique administrative roles. The roles must be copied to the production tenant. What ought you start with?
- From the development tenant, export the custom roles to JSON. (Correct answer)
- From the production tenant, create a new custom role.
- From the production tenant, create an administrative unit.
- From the development tenant, perform a backup.
Correct answer: From the development tenant, export the custom roles to JSON.
To copy the custom administrative roles from the development Azure AD tenant to the production Azure AD tenant, you should first export the custom roles to JSON from the development tenant. This will create a JSON representation of the roles and their configurations.
Question 21: Which Azure Cosmos DB conflict resolution policy automatically picks the write with the highest value of a user-defined property?
- Custom procedure
- First-Write-Wins
- Merge policy
- Last-Write-Wins (LWW) (Correct answer)
Correct answer: Last-Write-Wins (LWW)
Last-Write-Wins (LWW) uses a user-defined integer property (_ts by default) to resolve conflicts, keeping the write with the highest value.
Question 22: In Azure Cosmos DB, what NuGet package is used for the modern .NET SDK v3?
- Microsoft.Azure.Cosmos (Correct answer)
- Azure.Data.Cosmos
- Microsoft.Azure.CosmosDB.SDK
- Microsoft.Azure.DocumentDB
Correct answer: Microsoft.Azure.Cosmos
The Microsoft.Azure.Cosmos NuGet package is the official v3 SDK for .NET, replacing the older Microsoft.Azure.DocumentDB package.
Question 23: In Azure Event Grid, what is an 'event domain' used for?
- Routing events to an on-premises endpoint
- Managing thousands of topics for multi-tenant event routing at scale (Correct answer)
- Grouping event subscriptions by region
- Defining security policies for event subscribers
Correct answer: Managing thousands of topics for multi-tenant event routing at scale
Event domains let you manage up to 100,000 topics as a single resource, making per-tenant event routing scalable for SaaS applications.
Question 24: What OAuth 2.0 flow should a confidential server-side web app use to authenticate users via Azure AD?
- Implicit flow
- Authorization code flow (Correct answer)
- Device code flow
- Client credentials flow
Correct answer: Authorization code flow
The authorization code flow is the recommended OAuth flow for server-side apps, exchanging a code for tokens securely on the back channel.
Question 25: Your business has a subscription to Azure. Several Azure virtual machines must be deployed to the subscription using Azure Resource Manager (ARM) templates. One availability set will contain all of the virtual machines. In the event of a fabric failure or maintenance, you must make sure the ARM template enables access to as many virtual machines as possible. Which of the following should you provide as the platformUpdateDomainCount property's value?
- 30
- 40 (Correct answer)
- 20
- 10
Correct answer: 40
To ensure maximum accessibility of virtual machines during planned maintenance, the `platformUpdateDomainCount` property in an Azure Availability Set should be set to its maximum value. For many regions, this maximum is 20, but for specific scenarios or larger scale deployments, Azure allows up to 40 update domains. This distributes VMs across different groups that are updated sequentially, preventing all VMs from being offline simultaneously during host updates.
Question 26: What Event Hubs checkpoint mechanism stores the last processed event offset so a consumer can resume after a restart?
- Consumer group offset file
- Redis offset cache
- Event Hub partition cursor
- Checkpointing via a blob storage checkpoint store (Correct answer)
Correct answer: Checkpointing via a blob storage checkpoint store
The `EventProcessorClient` stores checkpoints as blobs in Azure Blob Storage, recording the last processed offset per partition.
Question 27: What Durable Functions feature enables long-running workflows to pause and wait for an external event?
- callActivityAsync
- continueAsNew
- createTimer
- waitForExternalEvent (Correct answer)
Correct answer: waitForExternalEvent
`waitForExternalEvent` suspends an orchestration and resumes it when a named external event is raised via the client API.
Question 28: The LabelMaker application security requirement must be met. Make a RoleBinding and assign it to the Azure AD account as a solution. Is the aim being met by the solution?
- Neither Yes or No
- No (Correct answer)
- Yes
Correct answer: No
A `RoleBinding` in Kubernetes grants permissions to a subject (like an Azure AD account) within the cluster, defining what actions they can perform on Kubernetes resources. However, it does not address the broader application security requirements, such as how the Azure AD account authenticates to the cluster or how the application itself is secured beyond Kubernetes authorization. Therefore, simply creating a `RoleBinding` is an incomplete solution for overall application security involving an Azure AD account.
Question 29: What Azure Key Vault object type stores sensitive string values like API keys and connection strings?
- Token
- Secret (Correct answer)
- Key
- Certificate
Correct answer: Secret
Key Vault Secrets store arbitrary string values such as connection strings, passwords, and API keys with access control and audit logging.
Question 30: You must assess the underlined text in this question to decide if it is accurate. An Azure subscription is connected to your Azure Active Directory (Azure AD) tenant. Your developer has produced a mobile application that uses the OAuth 2 implicit grant type to acquire Azure AD access tokens. The mobile app has to be added to Azure AD. For registration purposes, you need the developer to provide a redirect URI. Review the text that has been underlined. If it makes the assertion true, choose ""No change is needed,"" whereas if it makes the statement false, choose the appropriate response."
- a client ID
- a login hint
- a secret
- No change required. (Correct answer)
Correct answer: No change required.
For mobile applications utilizing the OAuth 2 implicit grant type to obtain Azure AD access tokens, a redirect URI is a mandatory component during application registration. This URI specifies the exact location where Azure AD should send the authentication response, including the access token, after a user successfully authenticates. Therefore, no change is needed to the statement.
Question 31: What Azure AD consent type allows an administrator to grant permissions for all users in a tenant at once?
- Application consent
- User consent
- Admin consent (Correct answer)
- Delegated consent
Correct answer: Admin consent
Admin consent grants an application's requested permissions to all users in the tenant, bypassing per-user consent for sensitive or organization-wide scopes.
Question 32: What Azure Functions feature allows you to inject dependencies like database clients using the built-in IoC container?
- Dependency injection via Startup class (Correct answer)
- Function filters
- Middleware pipeline
- Extension bundles
Correct answer: Dependency injection via Startup class
Azure Functions supports dependency injection by registering services in a `Startup` class that inherits `FunctionsStartup`, mirroring ASP.NET Core DI.
Question 33: When using Azure Cosmos DB with multi-region writes enabled, which consistency levels are supported?
- All five consistency levels including Strong
- Only Eventual consistency
- All levels except Strong and Bounded Staleness (Correct answer)
- Only Session and Eventual
Correct answer: All levels except Strong and Bounded Staleness
With multi-region writes, Strong consistency and Bounded Staleness are not supported because they require single-master coordination; the other three levels (Session, Consistent Prefix, Eventual) are available.
Question 34: You are creating a solution for an API with a public interface. An Azure App Service instance serves as the home for the API back end. For the API's back end, you have created a RESTful service. For the API Management service instance, back-end authentication needs to be configured. Solution: For the Azure resource, you configure Basic gateway credentials. Is the aim being met by the solution?
- Yes
- No (Correct answer)
Correct answer: No
Configuring 'Basic gateway credentials' for API Management backend authentication typically refers to using username and password. While this provides a form of authentication, it is generally not considered a robust or secure solution for production-grade public APIs, especially when the backend is an Azure App Service. Modern best practices for Azure API Management backend authentication often involve more secure methods like Managed Identities, client certificates, or OAuth/JWT, which offer better security, manageability, and integration with Azure's identity ecosystem.
Question 35: What Durable Functions pattern is used to fan out work across multiple parallel activity functions and then aggregate results?
- Chaining
- Async HTTP API
- Fan-out/fan-in (Correct answer)
- Monitor
Correct answer: Fan-out/fan-in
The fan-out/fan-in pattern starts multiple activity functions in parallel and uses `Task.WhenAll` to wait for all results before aggregating.
Question 36: What is a managed identity in Azure, and what problem does it solve?
- An identity for VM guest OS logins only
- A user account managed by Azure AD for service-to-service auth, eliminating stored credentials (Correct answer)
- A role assignment for resource groups
- A service principal with a client certificate
Correct answer: A user account managed by Azure AD for service-to-service auth, eliminating stored credentials
Managed identities are Azure AD identities automatically managed by Azure for services, removing the need to store and rotate credentials in code.
Question 37: Which Azure AD application registration element proves the app's identity to Azure AD when requesting tokens?
- Application (client) ID
- Client secret or certificate (credential) (Correct answer)
- Redirect URI
- Tenant ID
Correct answer: Client secret or certificate (credential)
A client secret or certificate is the credential that proves the application's identity to Azure AD during the OAuth 2.0 client credentials flow.
Question 38: Which partition key choice would result in the BEST throughput distribution in a Cosmos DB container storing IoT sensor readings?
- readingDate
- deviceId (Correct answer)
- deviceRegion
- sensorType
Correct answer: deviceId
Using deviceId distributes data evenly across logical partitions since each device generates a unique stream of readings, avoiding hot partitions.
Question 39: What property on a `ServiceBusMessage` enables deferred processing so a receiver can retrieve it later by sequence number?
- ScheduledEnqueueTime
- ContentType
- Defer() method on the receiver (Correct answer)
- MessageId
Correct answer: Defer() method on the receiver
Calling `DeferAsync()` on the receiver moves the message to a deferred state; it can be retrieved later using its sequence number with `ReceiveDeferredMessageAsync`.
Question 40: In Azure Event Hubs, what is a 'consumer group'?
- A logical view of an Event Hub that enables multiple independent readers to read the same stream (Correct answer)
- A group of publishers sharing an access key
- A batch of events processed together
- A set of partitions assigned to a single reader
Correct answer: A logical view of an Event Hub that enables multiple independent readers to read the same stream
Consumer groups allow multiple downstream applications to read the full event stream independently at their own pace without interfering with each other.
Exam AZ-204: Developing Solutions for Microsoft Azure
This exam certifies candidates' expertise in designing, building, testing, and maintaining cloud applications and services on Microsoft Azure.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds