AZ-104 Implement and Manage Storage Practice Question
A compliance team stores signed contract scans in Azure Blob Storage. The data must remain available if one zone in the primary region fails. If the entire primary region is unavailable, the team also needs to read the secondary copy while recovery work is underway. Which redundancy option should you choose for the storage account?
⚠ Common exam trap
Candidates often confuse GZRS with RA-GZRS, overlooking that GZRS does not provide read access to the secondary region unless a failover is performed, while the question explicitly requires the ability to read the secondary copy immediately during primary region unavailability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RA-GZRS, because it combines zone redundancy, geo-replication, and read access to the secondary region.
RA-GZRS (Read-Access Geo-Zone-Redundant Storage) is the correct choice because it provides synchronous zone-level redundancy within the primary region (protecting against a single zone failure) and asynchronous geo-replication to a secondary region. Additionally, it enables read access to the secondary region at all times, allowing the compliance team to read the secondary copy immediately if the primary region becomes unavailable, without waiting for a failover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ZRS, because it protects against a single zone failure in one region.
Why it's wrong here
ZRS replicates data synchronously across three Azure availability zones within a single region, so it survives a zone-wide outage locally. However, it does not create any copy in a geographically separate paired region, meaning there is no geo-replication for disaster recovery. The compliance team's requirement for a secondary-region failover copy with read access remains completely unmet.
When this WOULD be correct
A question where the requirement is only to protect against a zone failure within a single region, with no need for geo-replication or read access to a secondary region, such as a high-availability application within one Azure region.
- ✗
GRS, because it keeps a geo-replicated copy but does not provide zone redundancy in the primary region.
Why it's wrong here
GRS asynchronously replicates blobs to a paired secondary region for disaster recovery, but inside the primary region it uses only locally redundant storage (LRS), which does not protect against an availability zone failure. If the entire primary zone or datacenter is lost, the write endpoint becomes unavailable even though a read-only geo-copy exists (or will exist after failover). Thus it addresses geo-replication but not zone redundancy, so it falls short of the stated requirements.
When this WOULD be correct
A scenario where the requirement is only to protect against a region-level disaster and read access to the secondary region is not needed. For example: 'You need to ensure data is durable across regions but can tolerate downtime during failover.'
- ✗
GZRS, because it combines zone redundancy with geo-replication and supports failover recovery.
Why it's wrong here
GZRS does combine zone-redundant primary storage with asynchronous geo-replication to a secondary region, giving resilience to both zone and regional failures. However, the geo-replicated copy in the secondary region is not readable until a formal failover is initiated, so the requirement to read from the secondary endpoint is not satisfied. RA-GZRS adds that read access, which is precisely why it is required here.
When this WOULD be correct
A scenario where the requirement is to protect against a zone failure in the primary region and have a geo-replicated copy for disaster recovery, but read access to the secondary region is not needed until a failover is performed. For example, an organization that only needs to fail over to the secondary region during a regional disaster and does not require immediate read access during recovery.
- ✓
RA-GZRS, because it combines zone redundancy, geo-replication, and read access to the secondary region.
Why this is correct
RA-GZRS is the only option listed that satisfies both requirements simultaneously. It protects against a zone failure in the primary region through zone-redundant storage and also keeps a geo-replicated secondary copy in another region. The read-access feature lets administrators or applications read from the secondary endpoint during a regional outage or while validating recovery, which is exactly what the scenario requires.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓RA-GZRS, because it combines zone redundancy, geo-replication, and read access to the secondary region.Correct answer▾
Why this is correct
RA-GZRS is the only option listed that satisfies both requirements simultaneously. It protects against a zone failure in the primary region through zone-redundant storage and also keeps a geo-replicated secondary copy in another region. The read-access feature lets administrators or applications read from the secondary endpoint during a regional outage or while validating recovery, which is exactly what the scenario requires.
✗ZRS, because it protects against a single zone failure in one region.Wrong answer — click to see why▾
Why this is wrong here
ZRS only protects against a single zone failure in the primary region, but does not provide a secondary copy for recovery if the entire primary region fails, which is required by the compliance team.
★ When this WOULD be the correct answer
A question where the requirement is only to protect against a zone failure within a single region, with no need for geo-replication or read access to a secondary region, such as a high-availability application within one Azure region.
Why candidates choose this
Candidates may choose ZRS because it offers zone redundancy, but they overlook the additional requirement for geo-redundancy and read access to the secondary region during a regional outage.
✗GRS, because it keeps a geo-replicated copy but does not provide zone redundancy in the primary region.Wrong answer — click to see why▾
Why this is wrong here
GRS does not provide zone redundancy in the primary region, so if a zone fails, data may become unavailable until failover is initiated. The question requires availability during a zone failure, which GRS cannot guarantee.
★ When this WOULD be the correct answer
A scenario where the requirement is only to protect against a region-level disaster and read access to the secondary region is not needed. For example: 'You need to ensure data is durable across regions but can tolerate downtime during failover.'
Why candidates choose this
Candidates may think GRS is sufficient because it provides geo-redundancy, overlooking the need for zone-level availability in the primary region as specified in the question.
✗GZRS, because it combines zone redundancy with geo-replication and supports failover recovery.Wrong answer — click to see why▾
Why this is wrong here
GZRS provides zone redundancy and geo-replication but does not allow read access to the secondary region unless a failover is initiated. The question requires the ability to read the secondary copy while recovery is underway, which necessitates read-access geo-redundant storage (RA-GZRS).
★ When this WOULD be the correct answer
A scenario where the requirement is to protect against a zone failure in the primary region and have a geo-replicated copy for disaster recovery, but read access to the secondary region is not needed until a failover is performed. For example, an organization that only needs to fail over to the secondary region during a regional disaster and does not require immediate read access during recovery.
Why candidates choose this
Candidates may see 'zone redundancy' and 'geo-replication' in GZRS and assume it meets all requirements, overlooking the specific need for read access to the secondary region without failover.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Replication
Replication is the process of copying and synchronizing data across multiple servers or storage devices to ensure availability, reliability, and fault tolerance.
Key term
Region
A region is a distinct geographic location where a cloud provider operates multiple data centers that are connected by low-latency networks and provide cloud services.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.