Mixed Deck — All Microsoft Certified: Azure Developer Associate Topics Flashcards
100 cards from real Microsoft Certified: Azure Developer Associate practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All Microsoft Certified: Azure Developer Associate Topics flashcards as text
To pull a container image from Azure Container Registry into an App Service Web App, which identity type is recommended?
Answer: System-assigned managed identity
A system-assigned managed identity on the App Service eliminates stored credentials and grants ACR pull permissions via RBAC.
Which consistency level in Azure Cosmos DB provides the strongest consistency guarantee?
Answer: Strong
Strong consistency ensures linearizability, meaning reads always return the most recent committed version of an item.
What is the recommended approach for rotating a Key Vault secret used by an Azure Function without downtime?
Answer: Use Key Vault secret versioning with the latest version URI and allow App Service Key Vault references to auto-refresh
Using the `latest` version URI in Key Vault references lets App Service/Functions automatically pick up the new secret version without restarts.
Which Azure Service Bus class in the .NET SDK is used to send and receive messages in the modern (`Azure.Messaging.ServiceBus`) package?
Answer: ServiceBusClient with ServiceBusSender/ServiceBusReceiver
The modern SDK uses `ServiceBusClient` to create `ServiceBusSender` and `ServiceBusReceiver` instances, replacing the legacy `QueueClient`.
Your business has a Recovery Services vault as part of their Azure subscription. The virtual machines (VMs) your business uses should be backed up to the Recovery Services vault using Azure Backup. Which of the following VMs can you back up? Choose all that apply.
Answer: VMs that run Windows Server 2012 or higher.
Windows Server 2008's 64-bit operating system may be backed up using Azure Backup Windows 10 64-bit backup is supported by Azure Backup Debian 64-bit operating systems starting with Debian 7.9 and later are supported by Azure Backup Virtual machines that are offline or inactive can be backed up using Azure Backup
What is the default maximum execution timeout for an Azure Function running on the Consumption plan?
Answer: 10 minutes
On the Consumption plan, Azure Functions default to a 5-minute timeout but the maximum allowed is 10 minutes.
Which partition key choice would result in the BEST throughput distribution in a Cosmos DB container storing IoT sensor readings?
Answer: deviceId
Using deviceId distributes data evenly across logical partitions since each device generates a unique stream of readings, avoiding hot partitions.
Which Azure App Service deployment slot feature allows you to swap a staging slot into production without downtime?
Answer: Slot swap
Azure App Service slot swap moves the staging slot into production instantly, swapping routing without downtime.
Azure Active Directory (Azure AD) is a service that your business subscribes to. You wish to establish a conditional access policy for Azure AD. When connecting to Azure AD from untrusted places, members of the Global Administrators group must utilize Multi-Factor Authentication and a device that is connected to Azure AD. Solution: To change the session control of the Azure AD conditional access policy, log in to the Azure portal. Does the solution meet the goal?
Answer: No
MFA and device requirements are enforced through GRANT controls, not session controls — session controls only manage the experience after access is already granted (e.g., app-enforced restrictions, sign-in frequency). Because this solution edits the session control instead, it does not meet the goal, so the answer is No.
You work for your company as a developer. The workflows for an existing Logic App need to be changed. Which should you employ?
Answer: the Enterprise Integration Pack (EIP)
The Enterprise Integration Pack (EIP) in Azure Logic Apps provides a suite of connectors and capabilities specifically designed for complex B2B and enterprise integration scenarios. If the changes to an existing Logic App workflow involve integrating with enterprise systems, handling EDI, AS2, X12, or XML messages, or performing advanced data transformations, then the components and features provided by the EIP would be employed to implement these specific workflow modifications.
Your company's Azure solution uses multi-factor authentication when users are not in the office. The use model has been set to the Per Authentication option. You are notified that these workers should also utilize Multi-Factor Authentication after purchasing a smaller firm and enrolling the new workforce in Azure Active Directory (Azure AD). To achieve this, the Per Enabled User setting must be set for the usage model. Solution: You make a backup of the data from the current Multi-Factor Authentication provider and use it to construct a new Multi-Factor Authentication provider. Does the solution meet the goal?
Answer: No
You cannot change the usage model (for example from Per Authentication to Per Enabled User) on an existing MFA provider, and simply backing up data to build a new provider does not, by itself, transition the new workforce onto the required model — the answer is No because the described action doesn't accomplish the stated billing/enforcement change. The correct approach is to create a new provider configured with the desired usage model and link it to the directory.
In Azure Event Grid, what resource subscribes to events from a source and routes them to a handler endpoint?
Answer: Event subscription
An event subscription defines the filter criteria and the destination endpoint (e.g., webhook, Function, or queue) that receives matching events.
What is the purpose of the `on-behalf-of` (OBO) OAuth 2.0 flow in Azure AD?
Answer: Allows a service to acquire tokens to call downstream APIs using the user's identity passed via an incoming token
The OBO flow lets a middle-tier API exchange the user's incoming access token for a new token to call a downstream API, propagating the user's identity.
Azure Active Directory (Azure AD) is a service that your business subscribes to. You wish to establish a conditional access policy for Azure AD. When connecting to Azure AD from untrusted places, members of the Global Administrators group must utilize Multi-Factor Authentication and a device that is connected to Azure AD. Solution: You access the Azure portal to alter the grant control of the Azure AD conditional access policy. Does the solution meet the goal?
Answer: Yes
Requirements like enforcing Multi-Factor Authentication and requiring an Azure AD–joined/compliant device are configured under the GRANT controls of a Conditional Access policy. Since the solution modifies the grant control, it meets the goal, so the answer is Yes.
You have a tenant called contoso.com in your production Azure Active Directory (Azure AD). You deploy a development Azure Active Directory (AD) tenant and provide the development tenant with several unique administrative roles. The roles must be copied to the production tenant. What ought you start with?
Answer: From the development tenant, export the custom roles to JSON.
To copy the custom administrative roles from the development Azure AD tenant to the production Azure AD tenant, you should first export the custom roles to JSON from the development tenant. This will create a JSON representation of the roles and their configurations.
What health check path setting in Azure App Service marks an instance as unhealthy and removes it from the load balancer?
Answer: The path configured under Health Check that returns non-2xx for 10+ consecutive pings
App Service Health Check removes an instance from the load balancer when the configured path returns a non-2xx status for 10 consecutive pings.
Which file defines the bindings and trigger configuration for an Azure Function in the non-isolated worker model?
Answer: function.json
`function.json` contains the trigger, input binding, and output binding definitions for each Azure Function.
What App Service plan tier is required to use custom domains and SSL certificates?
Answer: Basic or higher
Custom domains and SSL/TLS bindings require at least the Basic (B1) tier in Azure App Service.
What is the maximum message size for Azure Service Bus in the Premium tier?
Answer: 100 MB
The Premium tier of Azure Service Bus supports message sizes up to 100 MB, compared to 256 KB in the Standard tier.
You intend to add a virtual machine running Ubuntu Server to your company's Azure subscription. You must implement a unique deployment that includes the addition of a specific trusted root certification authority (CA) Which of the following should you use to create the virtual machine?
Answer: The Create-AzVM cmdlet.
Deploying a VM with a unique configuration like a specific trusted root certification authority requires the scripting and granular control of PowerShell, using the New-AzVM cmdlet. The az CLI command and the deprecated New-AzureRmVm don't provide the same setup here. ⚠ The stored key ('Create-AzVM') is wrong — no such cmdlet exists; the correct cmdlet is New-AzVM.