Courseiva

Microsoft Azure Solutions Architect Expert AZ-305 (AZ-305) — Questions 1–75

795 questions total · 11pages · All types, answers revealed

Page 1 of 11

Page 2
1
Multi-Selecteasy

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to collect logs from on-premises firewalls and send them to Sentinel. Which TWO connectors can you use? (Choose two.)

Select 2 answers
A.DNS
B.Syslog
C.Common Event Format (CEF)
D.Azure Activity Log
E.Windows Security Events via AMA
AnswersB, C

Syslog is a ubiquitous standard protocol (RFC 5424) supported by virtually all enterprise firewalls, including Palo Alto, Fortinet, Cisco ASA, and Check Point. The Microsoft Sentinel Syslog connector collects these raw syslog messages and normalizes them for detection and investigation, making it the correct and most flexible choice for ingesting firewall logs.

Why this answer

Syslog is a standard protocol for sending log messages from network devices, including firewalls, to a central collector. Common Event Format (CEF) is a syslog-based format that normalizes logs from different security products, making them easier to parse and analyze in Sentinel. Both connectors allow on-premises firewalls to forward their logs to a Log Analytics agent or AMA, which then sends them to Sentinel.

Exam trap

The trap here is that candidates may confuse 'Syslog' with 'DNS' or 'Windows Security Events' because they think any log source can be collected via a generic connector, but Sentinel requires specific connectors for each data source type.

2
MCQmedium

A company runs a legacy on-premises application that relies on a SQL Server database. They want to use Azure as a disaster recovery site with a recovery point objective of less than 15 minutes. They need to be able to fail back to the on-premises environment after a disaster. Which Azure service should they use?

A.Azure Site Recovery
B.Azure Backup
C.Azure SQL Database
D.Azure Traffic Manager
AnswerA

Azure Site Recovery is the correct DR solution because it continuously replicates on-premises VMs and physical servers to Azure using asynchronous replication, typically achieving a recovery point objective (RPO) of 30 seconds or less. It provides orchestrated failover to Azure and failback to on-premises, enabling the legacy application to run on Azure during a disaster while maintaining application consistency through multi-VM consistency groups.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of on-premises SQL Server workloads to Azure, supporting a Recovery Point Objective (RPO) of less than 15 minutes through continuous replication. It enables failback to the original on-premises environment after a disaster, which is a critical requirement for this scenario.

Exam trap

The trap here is that candidates often confuse Azure Backup (which is for archival backups) with Azure Site Recovery (which is for replication and failover), leading them to select Azure Backup despite its inability to meet the sub-15-minute RPO or support failback.

How to eliminate wrong answers

Option B (Azure Backup) is wrong because it provides point-in-time backups with a typical RPO of hours or daily, not sub-15-minute continuous replication, and it does not support orchestrated failback to on-premises. Option C (Azure SQL Database) is wrong because it is a PaaS database service that cannot replicate an on-premises SQL Server instance for failback; it would require migrating the database schema and data, not providing disaster recovery replication. Option D (Azure Traffic Manager) is wrong because it is a DNS-based traffic load balancer that routes user traffic, not a replication or disaster recovery service for SQL Server databases.

3
MCQhard

You are designing a disaster recovery solution for a multi-tier application. The application consists of a web tier, an application tier, and a database tier running SQL Server on Azure VMs. The RPO must be 5 seconds, and the RTO must be 15 minutes. You need to recommend a SQL Server availability solution that meets these requirements. What should you use?

A.Azure SQL Database Managed Instance automatic backups
B.Azure Site Recovery with replication of SQL Server VMs
C.SQL Server log shipping
D.SQL Server Always On Availability Groups with synchronous commit and automatic failover
AnswerD

SQL Server Always On Availability Groups with synchronous commit mode writes the transaction to the primary and at least one secondary replica before acknowledging the commit, guaranteeing zero data loss and an RPO of 0 seconds. Automatic failover, when configured with two synchronous replicas and a quorum of validators, can complete in seconds to a few minutes, comfortably meeting the RTO of under 15 minutes. This is the only option that satisfies both the 5-second RPO and 15-minute RTO requirements.

Why this answer

SQL Server Always On Availability Groups with synchronous commit and automatic failover provides near-zero data loss (RPO of 5 seconds) and rapid automatic failover (RTO of 15 minutes) by replicating data synchronously across replicas. This solution meets the stringent RPO/RTO requirements for a multi-tier application running SQL Server on Azure VMs, as it ensures transactions are committed on both primary and secondary replicas before acknowledging success, and automatic failover occurs within seconds if the primary fails.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery's VM-level replication with database-level replication, overlooking that ASR's RPO/RTO are typically higher and not suitable for sub-minute RPO requirements, while log shipping is dismissed due to its manual failover and higher RPO.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database Managed Instance automatic backups have an RPO of up to 5 minutes (not 5 seconds) and an RTO measured in hours, not 15 minutes. Option B is wrong because Azure Site Recovery with replication of SQL Server VMs typically has an RPO of 30 seconds to several minutes and an RTO of 30 minutes or more, and it does not guarantee synchronous replication or automatic failover at the database level. Option C is wrong because SQL Server log shipping has an RPO of minutes (depending on backup/restore intervals) and an RTO of minutes to hours, as it requires manual failover and does not support automatic failover or synchronous replication.

4
MCQmedium

Refer to the exhibit. An organization deploys this ARM template to create a storage account. They need to ensure that data is replicated synchronously across two Azure regions. Does this template meet the requirement?

A.No, the template uses RA-GRS
B.Yes, GRS provides synchronous replication
C.No, the template uses LRS
D.No, GRS provides asynchronous replication
AnswerD

The correct answer is 'No' because GRS replicates data asynchronously to a secondary region, meaning there is a lag between writes to the primary and their availability in the secondary. Azure's GRS and RA-GRS are always asynchronous for cross-region copies, unlike LRS/ZRS which are synchronous within the primary region. This asynchronous behavior introduces a recovery point objective (RPO) that can be minutes or hours, so GRS does not provide synchronous replication.

Why this answer

The template uses GRS (Geo-Redundant Storage), which replicates data asynchronously from the primary region to the secondary region. Because the replication is asynchronous, there is a potential for data loss if a regional disaster occurs before the secondary region is fully updated. The requirement specifies synchronous replication across two Azure regions, which is only provided by Azure Storage’s geo-zone-redundant storage (GZRS) with read-access (RA-GZRS) or by using Azure Files with synchronous replication via Azure File Sync or a third-party solution.

Therefore, GRS does not meet the synchronous requirement.

Exam trap

The trap here is that candidates often confuse GRS’s geo-redundancy with synchronous replication, not realizing that GRS uses asynchronous replication to the secondary region, while synchronous replication is only available within a single region (LRS, ZRS) or across availability zones (ZRS).

How to eliminate wrong answers

Option A is wrong because RA-GRS (Read-Access Geo-Redundant Storage) is not used in the template; the template specifies GRS, and RA-GRS also uses asynchronous replication, so it would not meet the synchronous requirement either. Option B is wrong because GRS provides asynchronous replication, not synchronous; synchronous replication across regions is not a feature of standard Azure Storage replication options. Option C is wrong because the template does not use LRS (Locally Redundant Storage); it uses GRS, which replicates to a secondary region, but the core issue is that GRS is asynchronous, not synchronous.

5
MCQhard

A company runs a critical database on Azure SQL Database in the West US region. They need to implement disaster recovery to East US with an RPO of 1 minute and RTO of 1 hour. They also want to use the secondary database for read-only workloads during normal operations. The solution must be fully managed. Which Azure SQL Database feature should they enable?

A.Active geo-replication with failover group
B.Auto-failover group with read-scale
C.Geo-restore
D.Zone-redundant configuration
AnswerB

Auto-failover groups manage failover for one or more databases, support read-only access to the secondary, and meet the RPO/RTO requirements.

Why this answer

Auto-failover groups with read-scale (Option B) provide a fully managed disaster recovery solution with an RPO of 1 minute and RTO of 1 hour. They allow the secondary database in East US to be used for read-only workloads during normal operations via the read-scale listener endpoint. This meets all requirements: fully managed, low RPO/RTO, and read-only access to the secondary.

Option A (Active geo-replication with failover group) does not support automatic failover and does not provide a read-scale endpoint for the secondary, so it does not meet the RTO requirement or the read-only workload requirement.

Exam trap

The trap here is confusing Active geo-replication (manual failover, no read-scale) with Auto-failover groups (automatic failover, read-scale), leading candidates to pick Option A even though it lacks the read-scale capability and automatic RTO guarantee.

How to eliminate wrong answers

Option A is wrong because Active geo-replication alone does not include a failover group; without the failover group, you cannot achieve the 1-hour RTO (manual failover takes longer) and you lose the automatic orchestration of read-scale endpoints. Option C is wrong because Geo-restore is a point-in-time recovery method with an RPO of 1 hour and RTO of 12-24 hours, far exceeding the required 1-minute RPO and 1-hour RTO, and it does not support read-only workloads on a secondary. Option D is wrong because Zone-redundant configuration provides high availability within a single region, not disaster recovery across regions, and does not offer a secondary for read-only workloads.

6
MCQmedium

A company runs a data analytics application that stores large volumes of structured data in a relational format. The data is write-intensive and the application needs to scale horizontally for high throughput. The solution must support SQL queries, including joins and ACID transactions. Which Azure database service should they choose?

A.Azure Database for PostgreSQL - Hyperscale (Citus)
B.Azure SQL Database Hyperscale
C.Azure Cosmos DB (SQL API)
D.Azure Synapse Analytics
AnswerA

Azure Database for PostgreSQL - Hyperscale (Citus) extends PostgreSQL by sharding tables across multiple worker nodes using a coordinator node, allowing the cluster to handle both large analytical scans and high-throughput OLTP queries without abandoning relational semantics. It supports full SQL including multi-table joins and ACID transactions across distributed tables, making it the only listed option that combines horizontal write scalability with strong consistency and relational query power. This fits a data analytics application that needs to ingest and query data at scale while preserving transactional integrity.

Why this answer

Azure Database for PostgreSQL - Hyperscale (Citus) is correct because it provides horizontal scaling (sharding) across multiple nodes while preserving full SQL support, including JOINs and ACID transactions. Citus distributes data across worker nodes using a coordinator node, enabling write-intensive workloads to achieve high throughput through parallelized writes. This makes it ideal for large-volume, relational, write-heavy analytics applications that require relational integrity.

Exam trap

The trap here is that candidates often confuse Azure SQL Database Hyperscale's 'scale-out' read replicas with true horizontal write scaling, or they assume Cosmos DB's SQL API supports relational queries and transactions, when in fact it is a NoSQL store with limited consistency and no JOIN support.

How to eliminate wrong answers

Option B (Azure SQL Database Hyperscale) is wrong because it scales compute and storage vertically, not horizontally for write throughput; it is designed for large databases with high read scalability, not write-intensive horizontal scaling. Option C (Azure Cosmos DB SQL API) is wrong because it is a NoSQL database that does not support SQL JOINs or ACID transactions across multiple documents; it uses eventual consistency by default and lacks relational integrity. Option D (Azure Synapse Analytics) is wrong because it is a massively parallel processing (MPP) data warehouse optimized for analytical queries on large datasets, not for transactional, write-intensive workloads with ACID compliance; it uses a columnar store and does not support point-write transactions with the same isolation levels as a relational OLTP database.

7
MCQeasy

You have an Azure SQL Database that stores sales data. You need to ensure that the database can recover to any point in time within the last 35 days. What should you configure?

A.Configure the point-in-time restore (PITR) retention period to 35 days
B.Configure long-term retention (LTR) backups with a retention of 35 days
C.Create a secondary database in the same region
D.Enable geo-replication with a readable secondary
AnswerA

Point-in-time restore (PITR) is the native Azure SQL Database feature designed to recover a database to any precise point within a configurable retention window, with a maximum retention of 35 days. Automatic full, differential, and transaction log backups (taken every 5–10 minutes) let you restore to nearly any second in that window, making a 35-day PITR setting exactly what is needed to recover sales data lost or changed up to 35 days ago.

Why this answer

Point-in-time restore (PITR) for Azure SQL Database allows you to restore a database to any point within the configured retention period. The default retention is 7 days, but you can increase it up to 35 days. By setting the PITR retention period to 35 days, you meet the requirement to recover to any point in time within the last 35 days.

Exam trap

The trap here is confusing long-term retention (LTR) with point-in-time restore (PITR); candidates often think LTR provides point-in-time recovery, but LTR only retains full backups at fixed intervals and cannot restore to an arbitrary point within the retention window.

How to eliminate wrong answers

Option B is wrong because long-term retention (LTR) backups are designed for retaining full backups for extended periods (up to 10 years) and do not support point-in-time recovery; they only allow restoration to specific full backup timestamps, not any point in time. Option C is wrong because creating a secondary database in the same region provides high availability and failover capability but does not enable point-in-time recovery to any arbitrary time within the last 35 days. Option D is wrong because geo-replication with a readable secondary provides disaster recovery and read-scale out, but it does not offer point-in-time restore functionality; it replicates data asynchronously and cannot recover to an arbitrary past point.

8
MCQeasy

You need to store semi-structured data from IoT devices in Azure. The data has varying schemas and high write throughput. Which Azure service should you use?

A.Azure Blob Storage.
B.Azure SQL Database.
C.Azure Cosmos DB.
D.Azure Table Storage.
AnswerC

Azure Cosmos DB is a multi-model, schema-agnostic NoSQL database designed specifically for globally distributed, semi-structured data such as JSON documents emitted by IoT devices. Its automatic indexing of every property enables flexible, ad-hoc queries without requiring schema changes, while partitions provide horizontal scaling for high write throughput and sub-10-ms responses. Cosmos DB also supports multiple consistency levels and turnkey global distribution, making it ideal for IoT workloads that need low-latency reads and writes across regions. This combination of schema flexibility, elastic scaling, and query capability is why it is the correct choice.

Why this answer

Azure Cosmos DB is the correct choice because it is a globally distributed, multi-model database service designed for high write throughput and semi-structured data with varying schemas. It supports multiple APIs (e.g., SQL, MongoDB, Cassandra) and offers single-digit millisecond latency at any scale, making it ideal for IoT scenarios where device telemetry has inconsistent fields and requires rapid ingestion.

Exam trap

The trap here is that candidates often confuse Azure Table Storage with Cosmos DB because both are NoSQL, but Table Storage lacks the global distribution, multi-model APIs, and guaranteed high throughput that Cosmos DB provides, making it a weaker choice for high-write IoT workloads.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage is optimized for unstructured binary or text data (e.g., images, logs) and lacks native querying capabilities for semi-structured data with varying schemas; it does not provide the high write throughput and schema flexibility needed for IoT device data. Option B is wrong because Azure SQL Database is a relational database that enforces a fixed schema, requiring schema changes for each new device field, and its write throughput is limited compared to Cosmos DB's horizontal scaling for high-velocity IoT ingestion. Option D is wrong because Azure Table Storage is a NoSQL key-value store that can handle semi-structured data, but it lacks the global distribution, multi-model support, and guaranteed low-latency write throughput that Cosmos DB offers; it is also limited to a single index on partition and row keys, making it less suitable for complex query patterns.

9
MCQeasy

A company uses Microsoft Entra ID for identity management. They need to automate the process of granting access to resources for employees and external partners, and require periodic access reviews to ensure compliance. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Entra ID Entitlement Management
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Identity Protection
AnswerB

Microsoft Entra ID Entitlement Management is the correct choice because it creates access packages that bundle resources—groups, apps, SharePoint sites, and Teams—and define policies for who can request, who must approve, when access expires, and which access reviews are required. It automates the end-to-end lifecycle of access assignments and lets external partners request time-limited access through the Microsoft Entra admin center or a custom portal, satisfying both automation and periodic recertification.

Why this answer

Microsoft Entra ID Entitlement Management is the correct feature because it enables automation of access request workflows for employees and external partners, including time-limited access packages and periodic access reviews to enforce compliance. This directly matches the requirement for granting access and ensuring ongoing governance through reviews.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Entitlement Management because both involve access and reviews, but PIM is strictly for privileged roles, not for general resource access automation for employees and partners.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation and oversight for admin roles, not on automating general resource access for employees and partners or managing access reviews for non-privileged users. Option C is wrong because Conditional Access enforces real-time access policies based on signals like location or device compliance, but it does not automate the initial granting of access or provide periodic review capabilities. Option D is wrong because Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies), but it does not handle access request workflows or compliance-driven access reviews.

10
MCQeasy

A company runs an Azure SQL Database in a single region. They need to ensure that the database can be restored to any point in time within the last 90 minutes with a granularity of 1 minute. Which feature should they enable?

A.Active geo-replication
B.Auto-failover groups
C.Point-in-time restore
D.Long-term backup retention
AnswerC

Point-in-time restore leverages Azure SQL Database's automatic backups—full, differential, and transaction log backups taken every 5–10 minutes—to recreate a database at any second within the configured retention period (default 7 days, up to 35 days). You specify a target timestamp, and Azure calculates the precise log sequence number, restores the nearest full backup, and replays transaction logs to that point. This exactly matches the 1-minute granularity requested, making it the correct solution for recovering a recent data corruption or accidental deletion.

Why this answer

Point-in-time restore (PITR) for Azure SQL Database automatically creates backups every 5-10 minutes and retains them for the default retention period of 7 days (configurable up to 35 days). This allows restoring the database to any second within the retention window, meeting the requirement of 1-minute granularity for the last 90 minutes. The feature is built-in and does not require any additional configuration beyond setting the desired retention period.

Exam trap

The trap here is that candidates often confuse point-in-time restore with disaster recovery features like geo-replication or failover groups, but the question specifically asks for restoring to a point in time within 90 minutes with 1-minute granularity, which is exclusively provided by PITR.

How to eliminate wrong answers

Option A is wrong because Active geo-replication is designed for continuous data replication to a secondary region for disaster recovery, not for point-in-time restores within a single region. Option B is wrong because Auto-failover groups manage automatic failover of multiple databases across regions, but they do not provide point-in-time restore capability. Option D is wrong because Long-term backup retention (LTR) extends backup retention beyond 35 days (up to 10 years) using weekly, monthly, or yearly backups, but it does not offer the 1-minute granularity required for the last 90 minutes; LTR backups are taken at coarser intervals.

11
MCQeasy

Your organization plans to deploy Microsoft Entra ID Governance. You need to ensure that access to critical applications is reviewed quarterly by the application owners. Which Microsoft Entra ID feature should you use?

A.Microsoft Entra ID Privileged Identity Management
B.Microsoft Entra ID Entitlement Management
C.Microsoft Entra ID Terms of Use
D.Microsoft Entra ID Access Reviews
AnswerD

Microsoft Entra ID Access Reviews is the correct service because it provides recurring, owner-driven attestation workflows where designated reviewers—such as application owners or managers—are asked to confirm whether a user, group, or application role assignment should continue. Administrators can configure the review frequency (e.g., weekly, monthly, quarterly), specify the scope to all users or only guest users, and enable auto-apply settings that remove denied access automatically after the review period ends. It also supports self-review and multi-stage reviews, giving organizations a complete control loop for regularly proving that access is still necessary. In this scenario, the requirement for owners to periodically attest to whether users still need access directly maps to Access Reviews, not to a request, consent, or privileged-role feature.

Why this answer

Microsoft Entra ID Access Reviews (Option D) is the correct feature because it enables recurring, delegated review of user access to applications, groups, or roles. By configuring an access review with quarterly frequency and assigning application owners as reviewers, you directly meet the requirement for periodic attestation of access to critical applications. This is the specific Entra ID capability designed for governance-driven access recertification.

Exam trap

The trap here is that candidates confuse Entitlement Management (which includes access packages and can trigger reviews) with the dedicated Access Reviews feature, but the question explicitly asks for the feature that ensures reviews are conducted quarterly by application owners, which is the core purpose of Access Reviews, not a secondary function of Entitlement Management.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Privileged Identity Management (PIM) is focused on just-in-time privileged role activation and approval workflows, not on recurring access reviews for all users of critical applications. Option B is wrong because Microsoft Entra ID Entitlement Management handles automated access request and approval workflows via access packages, but it does not natively provide the recurring review cycle that Access Reviews offer. Option C is wrong because Microsoft Entra ID Terms of Use is a policy acceptance feature that requires users to consent to terms before accessing an application, but it does not perform any periodic review or attestation of existing access.

12
MCQhard

An organization is migrating on-premises Oracle databases to Azure. They require minimal code changes and support for Oracle PL/SQL stored procedures. Which Azure data service best meets these requirements?

A.Azure Database for MySQL
B.Azure Database for PostgreSQL with Oracle compatibility
C.Azure SQL Database
D.Azure Cosmos DB
AnswerB

Azure Database for PostgreSQL can be configured with an Oracle compatibility mode via the orafce extension, which emulates Oracle built-in functions, data types, and PL/SQL constructs. This compatibility layer allows many existing PL/SQL stored procedures, triggers, and functions to run with minimal or no modifications, significantly reducing migration effort. It is not a perfect one-to-one replacement, but it is the most viable managed service for preserving Oracle code logic in Azure, making it the correct choice for this migration.

Why this answer

Azure Database for PostgreSQL with the Oracle compatibility extension (e.g., orafce) provides support for Oracle PL/SQL stored procedures and syntax, minimizing code changes during migration. This service is designed to handle Oracle workloads with minimal re-engineering, unlike other Azure database options that lack native Oracle compatibility.

Exam trap

The trap here is that candidates often assume Azure SQL Database is the natural choice for Oracle migrations due to its relational nature, but it lacks native PL/SQL support, whereas PostgreSQL with Oracle compatibility is the correct service for minimizing code changes.

How to eliminate wrong answers

Option A is wrong because Azure Database for MySQL does not support Oracle PL/SQL stored procedures or Oracle-specific syntax, requiring significant code rewrites. Option C is wrong because Azure SQL Database uses T-SQL, not PL/SQL, and lacks direct compatibility with Oracle stored procedures, necessitating manual conversion. Option D is wrong because Azure Cosmos DB is a NoSQL database that does not support relational Oracle PL/SQL stored procedures or schema-based migrations.

13
MCQeasy

You need to design a solution to store log data from multiple Azure services. The data must be retained for 7 years for compliance purposes and should be queryable for analysis. Which Azure service should you use as the primary storage for these logs?

A.Azure Data Lake Storage
B.Azure SQL Database
C.Azure Blob Storage
D.Azure Log Analytics workspace
AnswerD

An Azure Log Analytics workspace is the correct destination because it is a purpose-built, managed log data store within Azure Monitor, where agents and other sources natively send data as structured tables. It provides Kusto Query Language (KQL) for powerful time-series filtering and joins, built-in alerting, dashboards, and configurable retention/archive policies (up to 730 days online) with long-term storage to cheaper tiers. This makes it the central repository for multi-source logs that require continuous querying and monitoring.

Why this answer

Azure Log Analytics workspace is the correct choice because it is purpose-built for ingesting, storing, and querying log data from Azure services. It supports long-term retention up to 7 years (via the Basic Logs tier or data archiving with Azure Data Explorer) and provides Kusto Query Language (KQL) for interactive analysis, meeting both compliance and queryability requirements.

Exam trap

The trap here is that candidates often choose Azure Blob Storage because it is cheap and can store logs for 7 years, but they overlook the requirement that the data must be 'queryable for analysis'—Blob Storage alone does not provide native querying, whereas Log Analytics does.

How to eliminate wrong answers

Option A is wrong because Azure Data Lake Storage is optimized for big data analytics and unstructured data at scale, not for structured log querying with built-in search capabilities; it lacks native log analytics query features. Option B is wrong because Azure SQL Database is a relational database for transactional workloads, not designed for high-volume, append-only log ingestion; it would be cost-prohibitive and inefficient for long-term log retention and querying. Option C is wrong because Azure Blob Storage is an object store for unstructured data; while it can store logs, it does not provide native querying capabilities—you would need additional services like Azure Data Lake or Log Analytics to analyze the data.

14
MCQeasy

A company plans to deploy a web application on Azure App Service that will be accessed by users worldwide. The application must have a single endpoint and use Azure Web Application Firewall (WAF) policies. Which Azure service should be placed in front of the App Service to meet these requirements?

A.Azure Application Gateway
B.Azure Load Balancer
C.Azure Front Door
D.Azure Traffic Manager
AnswerC

Azure Front Door is a global, HTTP(S)-aware application delivery and security service that offers a single anycast endpoint, global routing, TLS termination, and an integrated Web Application Firewall (WAF) that applies policies at edge locations. It can route traffic across multiple Azure regions or on-premises origins with health probes and instant failover, making it the most complete answer for a globally deployed web app. It supports path-based routing, SSL offload, and can even be layered in front of Application Gateways for deeper regional WAF/DDoS protection.

Why this answer

Azure Front Door is the correct choice because it provides a single, global endpoint with built-in Web Application Firewall (WAF) policies at the edge. It operates at Layer 7 (HTTP/HTTPS) and uses anycast routing to route user traffic to the nearest App Service instance, ensuring low latency and high availability worldwide.

Exam trap

The trap here is that candidates often confuse Azure Application Gateway with Azure Front Door, not realizing that Application Gateway is regional and cannot serve a single global endpoint, while Front Door is the only global Layer 7 service with integrated WAF.

How to eliminate wrong answers

Option A is wrong because Azure Application Gateway is a regional Layer 7 load balancer, not a global service, so it cannot provide a single endpoint for worldwide users. Option B is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and does not support WAF policies or HTTP-level routing. Option D is wrong because Azure Traffic Manager is a DNS-based traffic router that does not terminate HTTP traffic or support WAF policies; it only directs DNS queries to endpoints.

15
Multi-Selecthard

A solution stores critical VM backups in Azure. The company wants protection against accidental or malicious deletion of backups. Which two controls should be included?

Select 2 answers
A.Disabling backup alerts
B.Storing all backups on the original VM disk
C.Soft delete for Azure Backup
D.Multi-user authorization or resource locks where applicable
AnswersC, D

Soft delete for Azure Backup adds a mandatory 14-day (by default) retention window for any deleted backup data, during which the recovery point can be recovered even if a user, script, or attacker deletes it. This protects against accidental deletes and malicious actions because the data is not immediately purged; an administrator can restore it by selecting 'Undelete' while the vault has soft delete enabled. It also raises the bar for ransomware operators by preventing them from erasing backup history in one operation, making it a core data-recovery safeguard for critical VM backups.

Why this answer

Soft delete for Azure Backup (Option C) is correct because it retains backup data for an additional 14 days after deletion, allowing recovery from accidental or malicious deletion. This feature is enabled by default for Recovery Services vaults and protects backup data even if the backup itself is deleted, providing a critical safety net against data loss.

Exam trap

The trap here is that candidates may overlook the need for both a data-level protection (soft delete) and a resource-level protection (resource locks), assuming one control is sufficient, or they may mistakenly think disabling alerts or storing backups on the same disk provides any deletion protection.

16
Multi-Selectmedium

A company uses Azure Site Recovery to replicate VMs from the primary region to the secondary region. During a disaster, they want to ensure that the failover process is automated and includes runbooks to perform post-failover actions. Which TWO components are required? (Choose two.)

Select 2 answers
A.Azure Automation runbooks
B.Azure Site Recovery Recovery Plans
C.Azure Monitor alerts
D.Azure Logic Apps
E.Azure Backup
AnswersA, B

Azure Automation runbooks are PowerShell or Python scripts that ASR executes as steps inside a Recovery Plan, enabling custom post-failover actions such as updating DNS records, changing IP addresses, or reconfiguring application dependencies. They are correct because they provide the scripted logic that makes failover automation truly workload-aware, and they run either on an Azure Hybrid Worker or in Azure after the VMs start.

Why this answer

Azure Automation runbooks are required because they contain the PowerShell or Python scripts that execute post-failover actions, such as updating DNS records, reconfiguring network settings, or starting dependent services. Azure Site Recovery Recovery Plans are required because they orchestrate the failover sequence, including grouping VMs into ordered groups and invoking runbooks at specific steps. Together, they enable automated, scripted post-failover tasks within a structured failover workflow.

Exam trap

The trap here is that candidates often confuse Azure Logic Apps with Azure Automation runbooks, but only runbooks are directly supported within Azure Site Recovery Recovery Plans for post-failover automation.

17
MCQhard

A healthcare organization is migrating a regulatory-compliant application to Azure. The application must be isolated from the internet and accessible only from on-premises networks via a private IP address. The solution must minimize latency and maximize throughput for large data transfers. Which Azure networking solution should the organization implement?

A.Azure Private Link
B.Azure VPN Gateway
C.Azure Virtual WAN
D.Azure ExpressRoute
AnswerD

Azure ExpressRoute establishes a dedicated private connection between an on-premises network and Azure through a telecommunications provider, completely bypassing the public internet and providing consistent lower latency, higher throughput, and a guaranteed SLA. This makes it the preferred choice for healthcare organizations that need to transfer large volumes of sensitive regulatory data reliably and securely. ExpressRoute also supports private peering for services such as virtual machines, and optional Microsoft peering for Azure PaaS, making it the right solution.

Why this answer

Azure ExpressRoute provides a dedicated private connection from on-premises networks to Azure, bypassing the public internet. This ensures the application is isolated from the internet, uses private IP addresses, and offers the lowest latency and highest throughput for large data transfers due to dedicated bandwidth and no internet congestion.

Exam trap

The trap here is that candidates often confuse Azure Private Link (which provides private access to PaaS services) with a private network connection from on-premises, overlooking that Private Link still requires an underlying connectivity method like ExpressRoute or VPN for on-premises access, and does not itself guarantee low latency or high throughput for large transfers.

How to eliminate wrong answers

Option A is wrong because Azure Private Link exposes Azure services over a private endpoint within a virtual network, but it does not provide a dedicated connection from on-premises; it still requires a VPN or ExpressRoute for on-premises access and does not inherently minimize latency or maximize throughput for large data transfers. Option B is wrong because Azure VPN Gateway uses encrypted tunnels over the public internet, which introduces higher latency, variable throughput, and potential internet congestion, failing to meet the requirements for minimized latency and maximized throughput. Option C is wrong because Azure Virtual WAN is a networking service that aggregates connectivity (including VPN and ExpressRoute), but by itself it does not provide a dedicated private connection; it is a management and orchestration layer, not the direct connectivity solution for isolated, low-latency, high-throughput data transfers.

18
MCQmedium

A company runs a three-tier application on Azure VMs in the West US region. They want to enable disaster recovery to East US using Azure Site Recovery. The application requires that the web tier starts first, then the application tier, and finally the database tier after a consistency check. They also need to be able to perform non-disruptive DR drills. Which Azure Site Recovery capabilities should they use together?

A.Recovery Plan with pre/post actions and Test Failover
B.Network mapping and IP customization
C.Replication policy with crash-consistent snapshots
D.Azure Automation runbooks and Azure Monitor alerts
AnswerA

An Azure Site Recovery Recovery Plan is the only construct that explicitly determines failover behavior across multiple VMs: you group VMs into ordered groups, and attach pre/post actions via Azure Automation runbooks or custom scripts to stop or start tiers in dependency order (for example, database before middleware before web). The Test Failover feature then executes that exact plan against an isolated Azure Virtual Network, validating scripts, IP assignments, and application startup without affecting the production endpoint. This combination directly addresses both the startup sequencing requirement and the need for periodic non-disruptive drills.

Why this answer

A Recovery Plan in Azure Site Recovery allows you to define the startup order of tiers (web, app, database) using pre-actions and post-actions, which can invoke Azure Automation runbooks or scripts to perform the consistency check. Test Failover enables non-disruptive DR drills by creating an isolated copy of the replicated VMs in East US without impacting the production environment. Together, these capabilities meet both the ordered startup and drill requirements.

Exam trap

The trap here is that candidates may confuse general Azure automation or networking features (like runbooks or network mapping) with the specific ASR capabilities required for ordered startup and drills, overlooking that Recovery Plan and Test Failover are the exact ASR features designed for these purposes.

How to eliminate wrong answers

Option B is wrong because network mapping and IP customization handle network connectivity and IP address assignment during failover, but they do not control the startup order of tiers or enable non-disruptive drills. Option C is wrong because a replication policy with crash-consistent snapshots provides a point-in-time copy of VMs, but it does not orchestrate the sequence of tier startup or support test failovers. Option D is wrong because Azure Automation runbooks and Azure Monitor alerts can automate tasks and monitor health, but they are not native ASR capabilities for defining recovery plan steps or performing DR drills; runbooks can be used within recovery plans, but the question asks for ASR capabilities, and alerts alone do not enable drills.

19
MCQhard

A company uses Microsoft Entra ID (Microsoft Entra ID) and Microsoft Intune. They want to block access to all corporate cloud applications (e.g., Office 365, Azure portal) from devices that are not enrolled in Intune or do not meet the company's compliance policies. The solution must work seamlessly for all cloud apps without requiring per-app configuration. Which Microsoft Entra ID feature should they configure?

A.Conditional Access policy with 'Require device to be marked as compliant' grant control
B.Microsoft Entra ID Identity Protection
C.Privileged Identity Management (PIM)
D.Microsoft Entra ID B2C
AnswerA

Conditional Access is the correct control because it evaluates signals at sign-in, including device compliance state that Intune/MDM reports via the DeviceManagement service. By creating a policy scoped to 'All cloud apps' with the 'Require device to be marked as compliant' grant control, you force any access to corporate resources to come only from devices that have been enrolled, inventoried, and found compliant with your policies such as OS version, encryption, and jailbreak detection. If a device isn't compliant, access is blocked or conditional re-authentication is triggered, directly satisfying the requirement.

Why this answer

A Conditional Access policy with the 'Require device to be marked as compliant' grant control enforces device compliance across all cloud apps (Office 365, Azure portal, etc.) without per-app configuration. This works by integrating with Intune compliance policies and checking device enrollment status at the time of authentication, blocking non-compliant or unenrolled devices at the Entra ID level.

Exam trap

The trap here is that candidates often confuse Identity Protection (risk-based) with Conditional Access (policy-based), or assume that per-app configuration is required, when in fact Conditional Access applies globally to all cloud apps registered in Entra ID.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection is designed to detect and respond to identity-based risks (e.g., leaked credentials, anonymous IP addresses), not to enforce device compliance or enrollment for cloud app access. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not device-level access controls. Option D is wrong because Microsoft Entra ID B2C is a customer-facing identity service for external users (e.g., social logins), not for blocking corporate cloud apps based on device compliance.

20
MCQeasy

A company needs to provide secure remote administration access to Azure virtual machines for their IT team. The VMs are in a virtual network with no public IP addresses. The IT team uses browsers to connect. The solution should not require any custom software on the client machines. Which Azure service should they use?

A.Azure Bastion
B.Just-in-Time VM access
C.Azure VPN Gateway
D.Microsoft Entra ID Domain Services
AnswerA

Azure Bastion is a fully managed PaaS service that provides browser-based RDP and SSH connectivity to virtual machines directly through the Azure portal over TLS. It is deployed inside a virtual network and brokers the connection from the portal to the VM, so the VMs do not need public IP addresses and no client software is required on the user's machine. The management ports (RDP 3389 and SSH 22) are never exposed to the public internet, and the session is rendered securely over SSL, fully satisfying the requirements for secure remote administration.

Why this answer

Azure Bastion provides secure, seamless RDP/SSH connectivity to Azure virtual machines directly in the Azure portal over TLS. Because the VMs have no public IP addresses, Bastion acts as a jump server that is deployed inside the virtual network, eliminating the need for any public exposure. Since the IT team uses browsers and cannot install custom software, Bastion's native browser-based HTML5 client meets the requirement perfectly.

Exam trap

The trap here is that candidates often confuse Just-in-Time VM access (which still requires a public IP and a client) with Bastion's fully browser-based, no-public-IP solution, or they mistakenly think a VPN gateway provides browser-based RDP/SSH without client software.

How to eliminate wrong answers

Option B (Just-in-Time VM access) is wrong because it only reduces the attack surface by temporarily opening ports on existing public IPs or NSGs; it does not eliminate the need for public IPs and still requires a client-side RDP/SSH client, not a browser. Option C (Azure VPN Gateway) is wrong because it requires installing a VPN client on each IT team member's machine and does not provide browser-based access; it also requires a public endpoint for the VPN gateway itself. Option D (Microsoft Entra ID Domain Services) is wrong because it provides managed domain services (LDAP, Kerberos, NTLM) for authentication and group policy, not remote desktop or SSH connectivity to VMs.

21
MCQeasy

You are designing a monitoring solution for a critical application hosted on Azure Virtual Machines. The application is latency-sensitive and you need to be alerted when CPU usage exceeds 90% for more than 5 minutes. Which Azure Monitor feature should you use?

A.Service health alert
B.Metric alert
C.Log alert
D.Activity log alert
AnswerB

Metric alerts are the native Azure Monitor alert type for continuously tracking numeric time-series data, such as a VM's "Percentage CPU" or memory bytes. You can define a threshold condition that is evaluated at a specified frequency, with alert activation when the metric crosses the threshold for a configured aggregation window. This provides near-real-time, low-latency detection of performance issues, which exactly matches the requirement to monitor an application's operational health by watching VM metric values.

Why this answer

Metric alerts in Azure Monitor evaluate resource metrics (like CPU percentage) at regular intervals and trigger actions when a threshold is breached for a specified duration. Since the question involves a latency-sensitive application and a numeric threshold (CPU > 90% for 5 minutes), a metric alert is the correct choice because it provides near-real-time, low-latency evaluation directly from the VM's performance counters.

Exam trap

The trap here is that candidates often confuse Log alerts (which are powerful for complex queries) with Metric alerts, forgetting that Log alerts introduce latency from log ingestion and indexing, making them inappropriate for time-sensitive, threshold-based CPU monitoring.

How to eliminate wrong answers

Option A is wrong because Service Health alerts notify about Azure service-level issues (e.g., regional outages, planned maintenance), not about the performance of your specific virtual machines. Option C is wrong because Log alerts query log data (e.g., from Azure Monitor Logs or Application Insights) and have inherent ingestion and query latency, making them unsuitable for sub-5-minute, latency-sensitive CPU threshold alerts. Option D is wrong because Activity Log alerts monitor changes to Azure resources (e.g., VM creation, deletion, or configuration changes), not the operational metrics like CPU usage.

22
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. When such risks are detected, they want to require multi-factor authentication (MFA) or block the sign-in. They also need a dashboard to review risk events and generate reports. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Identity Governance
AnswerB

Identity Protection is the correct answer because it is Entra ID's risk detection engine, using signals like leaked credentials, anonymous IP addresses, impossible travel, malware-linked IPs, and unfamiliar sign-in properties to compute per-user and per-risk assignments. It provides an interactive risk dashboard, programmatic risk detection APIs, and supports risk-based Conditional Access policies, such as requiring MFA or blocking access when risk levels exceed a threshold, and can auto-remediate via self-service password reset for confirmed compromised users.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. It provides risk-based conditional access policies that can require MFA or block sign-ins, and it includes a dashboard for reviewing risk events and generating reports. This aligns directly with the scenario's requirements for detection, automated response, and reporting.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, not realizing that Conditional Access is the enforcement mechanism while Identity Protection is the detection and risk-scoring engine that provides the necessary risk signals.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is focused on managing, controlling, and monitoring access to privileged roles, not on detecting or responding to sign-in risks like leaked credentials or malware-linked IPs. Option C is wrong because Conditional Access is a policy engine that enforces access controls (like MFA) based on conditions, but it does not itself detect risk events or provide a risk dashboard; it relies on Identity Protection to supply risk signals. Option D is wrong because Identity Governance handles access reviews, entitlement management, and lifecycle workflows, not real-time risk detection or automated response to high-risk sign-ins.

23
MCQhard

You deploy the above ARM template. The deployment succeeds. However, you cannot access the storage account from the Azure portal. What is the most likely reason?

A.The storage account is configured to require HTTPS traffic only.
B.The network ACLs deny all traffic by default, and no allow rules are configured.
C.The minimum TLS version is set to TLS 1.2, which is not supported by the portal.
D.The encryption key source is set to Microsoft.Storage, which prevents portal access.
AnswerB

The network ACLs are the key culprit. In the ARM template, the default action is explicitly set to 'Deny' and no IP rules or virtual network rules are included, so the public endpoint is effectively locked down. When you open the storage account in the Azure portal, the portal's management pane uses the control plane to show settings, but trying to view or edit containers, blobs, or data relies on a data plane request from your client's public IP address, which is not permitted by the ACLs. Thus, the deployment succeeds but data operation access from the portal is impossible.

Why this answer

The ARM template likely includes a network ACL configuration that, by default, denies all traffic. Without explicit allow rules for the Azure portal's IP ranges or the 'Allow trusted Microsoft services' exception, the portal cannot reach the storage account's management endpoints, resulting in an inability to access it from the portal despite a successful deployment.

Exam trap

The trap here is that candidates often overlook network ACLs as a cause for portal access failure, mistakenly focusing on TLS versions or encryption settings, which do not affect basic connectivity from the Azure portal.

How to eliminate wrong answers

Option A is wrong because requiring HTTPS traffic only does not block portal access; the portal uses HTTPS to communicate with storage accounts, so this setting would not prevent access. Option C is wrong because the Azure portal fully supports TLS 1.2; setting the minimum TLS version to 1.2 does not block portal access, as the portal uses TLS 1.2 or higher. Option D is wrong because setting the encryption key source to Microsoft.Storage is the default and does not affect portal access; portal connectivity is independent of encryption key management.

24
Multi-Selectmedium

Which TWO of the following are valid Azure Policy effects that can be used to enforce compliance?

Select 2 answers
A.DeployIfNotExists
B.Deny
C.AuditIfNotExists
D.Modify
E.AutoRemediate
AnswersA, B

DeployIfNotExists is a valid effect that enforces compliance by deploying resources to remediate non-compliant resources after creation.

Why this answer

DeployIfNotExists (A) is a valid Azure Policy effect that enforces compliance by deploying a related resource when a specified resource does not exist, using a managed identity to perform the deployment. Deny (B) is also a valid effect that enforces compliance by blocking a resource request that violates the policy definition, causing the deployment to fail. AuditIfNotExists (C) is a real effect, but it only logs a non-compliance warning rather than enforcing compliance, so it is not one of the two enforcement effects.

Modify (D) is a valid effect that adds or updates properties during deployment, but it is not marked correct here. AutoRemediate (E) is not an Azure Policy effect; remediation is a separate task performed via remediation tasks, not an effect name.

Exam trap

Candidates often incorrectly think that AuditIfNotExists enforces compliance, but it only audits. Additionally, some may think AutoRemediate is a real effect when it is not. Deny is a straightforward enforcement effect that is sometimes overlooked.

25
MCQeasy

Your company has a hybrid identity environment with Microsoft Entra ID and an on-premises Active Directory. You need to enable single sign-on (SSO) for users accessing Microsoft 365 applications from domain-joined devices. Which authentication method should you configure?

A.Microsoft Entra Pass-through Authentication
B.Microsoft Entra password hash synchronization
C.Microsoft Entra Seamless SSO
D.Active Directory Federation Services (AD FS)
AnswerC

Microsoft Entra Seamless SSO is the correct feature because it automatically signs in domain-joined devices when users access Azure AD resources while they are connected to the corporate network. It uses the on-premises Active Directory computer account of the user's device to obtain a Kerberos ticket, which is then presented to Azure AD through a non-interactive flow, eliminating the need for password prompts. Seamless SSO can be combined with either PHS or PTA and specifically addresses the hybrid identity need for frictionless access without deploying additional federation infrastructure.

Why this answer

Microsoft Entra Seamless SSO (C) is the correct choice because it automatically signs users in when they are on domain-joined devices connected to the corporate network, without requiring any additional prompts. It integrates with password hash synchronization or pass-through authentication to provide a true single sign-on experience for Microsoft 365 applications, leveraging Kerberos delegation to validate the user's identity against on-premises Active Directory.

Exam trap

The trap here is that candidates often confuse authentication methods that validate credentials (like Pass-through Authentication or password hash sync) with methods that provide single sign-on, forgetting that SSO requires a separate mechanism like Seamless SSO or federation to eliminate credential prompts.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Pass-through Authentication validates passwords directly against on-premises Active Directory but does not provide SSO; it still requires user interaction for credential entry. Option B is wrong because Microsoft Entra password hash synchronization synchronizes password hashes to the cloud for authentication but does not enable SSO; users must still enter their credentials unless combined with Seamless SSO. Option D is wrong because Active Directory Federation Services (AD FS) is a federated identity solution that can provide SSO, but it is more complex and heavyweight than needed for domain-joined devices accessing Microsoft 365; Seamless SSO is the simpler, recommended approach for this specific scenario.

26
Multi-Selecthard

Your organization is designing a governance solution for multiple Azure subscriptions. You need to enforce that all resources are created in specific Azure regions (East US and West Europe only). Additionally, any resource group must have a cost center tag. Which THREE Azure components should you use? (Choose three.)

Select 3 answers
A.Azure Policy
B.Azure Blueprints
C.Policy Initiative
D.Management Groups
E.Role-Based Access Control (RBAC)
AnswersA, C, D

Azure Policy is the correct service for implementing resource governance rules such as allowed region constraints and mandatory tags. It evaluates resources against business rules and can automatically deny non-compliant resource creation, audit existing resources, or remediate drift. Policies are assigned at management group, subscription, or resource group scopes, making it the primary tool in a multi-subscription governance architecture.

Why this answer

Azure Policy is correct because it allows you to define and enforce rules for resource creation, such as restricting allowed locations to East US and West Europe. By assigning a built-in or custom policy definition to a management group or subscription, you can prevent any resource from being created outside the specified regions. This directly addresses the requirement to enforce regional compliance.

Exam trap

The trap here is that candidates often confuse Azure Blueprints (which packages and deploys resources) with Azure Policy (which enforces rules), or they overlook that Management Groups are needed to apply policies across multiple subscriptions efficiently.

27
MCQmedium

A company is deploying a multi-tier application on Azure. The web tier runs on Azure App Service, and the database tier runs on Azure SQL Database. The company wants to secure the connection between the web tier and the database by using a private endpoint for Azure SQL Database. They also want to ensure that the web tier can resolve the private endpoint's DNS name. What should you recommend?

A.Configure a private endpoint for Azure SQL Database and use Azure Firewall to redirect DNS queries.
B.Configure a private endpoint for Azure SQL Database and integrate an Azure Private DNS zone with the virtual network used by the web tier.
C.Configure a service endpoint for Azure SQL Database and enable Azure Private Link.
D.Configure a private endpoint for Azure SQL Database and add a custom DNS record in the Azure DNS zone for the web tier's domain.
AnswerB

A private endpoint for Azure SQL Database creates a private IP address within a virtual network. To resolve the private endpoint's DNS name, you must integrate an Azure Private DNS zone with the virtual network. This ensures that the web tier can resolve the database's FQDN to the private IP, enabling secure connectivity.

Why this answer

To securely connect to Azure SQL Database using a private endpoint, you must create the private endpoint and integrate an Azure Private DNS zone with the virtual network. The Private DNS zone automatically creates the necessary A record for the SQL server's FQDN, resolving to the private IP. This allows the web tier to connect securely without exposing traffic to the public internet.

Exam trap

The trap here is assuming that service endpoints or custom DNS records are sufficient for private endpoint resolution, but only an Azure Private DNS zone linked to the virtual network provides the correct DNS resolution.

28
MCQmedium

A company is designing a disaster recovery solution for Azure VMs running a critical application. They need a Recovery Time Objective (RTO) of less than 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The solution should be cost-effective and allow testing without affecting production. Which Azure service should they use?

A.Azure Migrate
B.Azure Backup
C.Azure Front Door
D.Azure Site Recovery
AnswerD

Azure Site Recovery orchestrates continuous, block-level replication of Azure VMs, VMware, Hyper-V, or physical servers to Azure or to a secondary site, with application-consistent snapshots that support RPOs in the single-digit minutes range. It provides automated failover and failback, alongside non-disruptive recovery drills (test failovers) that validate the recovery plan without impacting production workloads. This combination of continuous replication, orchestrated failover, and testability is why Azure Site Recovery meets the DR requirements where the other options do not.

Why this answer

Azure Site Recovery (ASR) is the correct choice because it provides orchestrated replication and failover for Azure VMs, supporting RPOs as low as 15 minutes (with continuous replication) and RTOs under 1 hour. It also enables non-disruptive test failovers in isolated networks, meeting the requirement for testing without affecting production. ASR is cost-effective for critical workloads as it only charges for replication storage and compute during failover, unlike always-on redundancy solutions.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for long-term data retention with higher RPO/RTO) with Azure Site Recovery (which is for rapid failover and replication), often overlooking the specific RPO/RTO thresholds stated in the question.

How to eliminate wrong answers

Option A is wrong because Azure Migrate is a discovery and migration tool, not a disaster recovery solution; it cannot provide ongoing replication or meet RTO/RPO targets. Option B is wrong because Azure Backup is designed for data backup with typical RPOs of 12-24 hours (or 4 hours for enhanced policy) and RTOs measured in hours to days, failing the 15-minute RPO and sub-1-hour RTO requirements. Option C is wrong because Azure Front Door is a global load balancer and application delivery controller for HTTP/S traffic, not a VM-level disaster recovery service; it does not replicate VM state or provide failover for compute resources.

29
MCQeasy

A company uses Microsoft Entra ID. They need to automatically block sign-ins from users whose accounts have been identified as high-risk for compromise. They also want users to be prompted to reset their password when the risk is detected. Which Microsoft Entra ID feature should they use?

A.Identity Protection with user risk policy
B.Conditional Access with location policy
C.Microsoft Entra ID MFA
D.Microsoft Entra ID Privileged Identity Management
AnswerA

Identity Protection with a user risk policy is the appropriate solution because it continuously analyzes signals such as leaked credentials and anomalous sign-in patterns to assign a risk score to each user. You can configure a user risk policy to automatically block sign-ins or require MFA and a password change when the risk level is high. This directly meets the need to automatically react to user risk without requiring manual intervention.

Why this answer

Identity Protection with a user risk policy is the correct feature because it allows automatic blocking of sign-ins when a user's account is flagged as high-risk by Microsoft's machine learning models. Additionally, the policy can be configured to require a secure password reset (self-service password reset) as a remediation action, directly meeting both requirements.

Exam trap

The trap here is that candidates often confuse Conditional Access (which handles location, device, and app conditions) with Identity Protection's risk-based policies, but only Identity Protection directly evaluates user risk and triggers automated password reset remediation.

How to eliminate wrong answers

Option B is wrong because Conditional Access with a location policy controls access based on geographic location (e.g., blocking sign-ins from untrusted countries), not on user risk level. Option C is wrong because Microsoft Entra ID MFA adds a second authentication factor but does not automatically block sign-ins based on risk or force a password reset. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and oversight, not risk-based sign-in blocking or password reset prompts.

30
MCQeasy

A company deploys a web application on Azure VMs in a single region. They need to distribute incoming HTTPS traffic across multiple VMs, offload SSL termination, and provide session persistence. Which Azure load balancing solution should they choose?

A.Azure Load Balancer (Standard SKU)
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a Layer 7 load balancer that natively performs SSL termination, offloading the decryption workload from the VMs and enabling efficient certificate management. It also offers URL-based routing, cookie-based session persistence, and HTTP health probes, allowing application-aware traffic distribution across VMs within a single Azure region. These Layer 7 capabilities directly align with the web application's need for secure, sticky sessions and advanced routing.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that supports SSL termination, session persistence (via cookie-based affinity), and HTTP/HTTPS traffic distribution. Unlike Azure Load Balancer (Layer 4), it can inspect application-layer headers and offload SSL decryption, meeting all three requirements.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers handle SSL termination, but only Layer 7 solutions like Application Gateway or Front Door can offload HTTPS traffic and provide cookie-based session persistence.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL termination or application-layer session persistence; it only distributes traffic based on IP and port. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not handle SSL termination or session persistence; it directs clients to endpoints based on DNS resolution, not proxying traffic. Option D is wrong because Azure Front Door is a global Layer 7 service with SSL termination and session affinity, but it is designed for multi-region distribution and CDN scenarios, not for a single-region VM deployment where Application Gateway is the more appropriate and cost-effective choice.

31
MCQmedium

You need to monitor Azure resources and send alerts when the CPU usage of a virtual machine exceeds 90% for 5 minutes. Which two Azure services should you use? (Select TWO.)

A.Azure Monitor Action Groups
B.Log Analytics
C.Azure Monitor
D.Application Insights
E.Event Grid
AnswerA, C

An Azure Monitor Action Group is the notification endpoint that alert rules invoke when a condition fires—it defines delivery channels such as email, SMS, voice, webhook, ITSM, or an automation runbook. Without an action group, an alert rule may log the hitting state but cannot actually send an email or SMS to operations staff. Therefore, for the specific goal of 'sending alerts,' the action group is the direct, correct component that carries out the notification.

Why this answer

Azure Monitor is the core service for collecting and analyzing metrics and logs from Azure resources. It can be configured with metric alerts that trigger when CPU usage exceeds 90% for 5 minutes. Action Groups define the notification and response actions (e.g., email, SMS, webhook) that are executed when the alert fires, making them essential for sending alerts.

Exam trap

The trap here is that candidates often confuse Log Analytics (a log query tool) with Azure Monitor (the alerting engine), or mistakenly think Application Insights can monitor VM-level metrics, when it is designed for application-level telemetry.

How to eliminate wrong answers

Option B is wrong because Log Analytics is a tool for querying and analyzing log data, not for creating metric-based alerts or sending notifications directly. Option D is wrong because Application Insights is focused on application performance monitoring (APM) for web applications, not infrastructure-level VM CPU metrics. Option E is wrong because Event Grid is a serverless event routing service used for reacting to Azure resource state changes (e.g., VM creation), not for monitoring CPU thresholds or sending alerts.

32
MCQeasy

Your company has a Azure subscription with multiple resource groups. You need to ensure that all resources are tagged with a 'CostCenter' tag. What should you use?

A.Azure Policy
B.Azure Blueprints
C.Management Groups
D.Azure RBAC
AnswerA

Azure Policy is the correct answer because it is a native governance service that can evaluate and enforce resource properties such as tags at scale. You can define a policy with an effect like 'deny' or 'modify' to either reject non-compliant tags or automatically append missing ones via a remediation task. Unlike RBAC, the policy engine runs independently of access control, directly inspecting each resource for compliance.

Why this answer

Azure Policy is the correct choice because it enforces organizational standards and compliance by evaluating resources for non-compliance with defined rules, such as requiring a specific tag. You can create a policy that audits or denies resources missing the 'CostCenter' tag, ensuring all resources are tagged automatically or during deployment.

Exam trap

The trap here is that candidates often confuse Azure Policy with Azure Blueprints, thinking Blueprints can enforce tags directly, but Blueprints only define the initial state and do not enforce ongoing compliance like Policy does.

How to eliminate wrong answers

Option B is wrong because Azure Blueprints is used for orchestrating the deployment of resource groups, policies, role assignments, and ARM templates as a repeatable environment, not for enforcing tags on individual resources. Option C is wrong because Management Groups provide a hierarchical structure for organizing subscriptions and applying policies at scale, but they are not the direct enforcement mechanism for tagging resources. Option D is wrong because Azure RBAC manages access control by assigning roles to users, groups, or applications, and does not enforce resource tagging.

33
MCQhard

Your company is deploying a critical application on Azure VMs. The application requires a static private IP address that does not change even if the VM is stopped and deallocated. The VM must be placed in an availability zone for high availability. Which networking approach should you use?

A.Use Azure Firewall to provide static private IP and load balancing.
B.Assign a static private IP address to the VM's NIC and use a standard public load balancer.
C.Use Azure Traffic Manager to assign static private IP.
D.Use Application Gateway with a static private IP.
AnswerB

Assigning a static private IP to the VM's NIC guarantees the address is retained even when the VM is deallocated, preserving internal DNS mappings and dependent integrations. A standard public load balancer provides a public frontend IP, uses health probes to verify backend availability, and forwards traffic according to load-balancing rules. Together, these two mechanisms give the application a stable private identity and robust external accessibility, which is the correct approach for a critical workload.

Why this answer

A static private IP address assigned to the VM's NIC persists even when the VM is stopped and deallocated, ensuring the application always uses the same private IP. Placing the VM in an availability zone provides high availability by protecting against zonal failures, and a standard public load balancer can distribute traffic across VMs in different zones while preserving the static private IP for each VM.

Exam trap

The trap here is that candidates often confuse the static IP assignment at the VM NIC level with the static IP of a load balancer or gateway, mistakenly thinking that a load balancer or firewall can provide a static private IP to the VM itself, when in fact the VM's NIC must be explicitly configured with a static private IP address.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a managed network security service that provides outbound/inbound filtering and SNAT, not a mechanism to assign a static private IP to a VM; it cannot guarantee a static private IP for the VM itself. Option C is wrong because Azure Traffic Manager is a DNS-based traffic routing service that operates at the DNS level and does not assign IP addresses to VMs; it directs traffic based on DNS resolution, not static private IP assignment. Option D is wrong because Application Gateway is a layer-7 load balancer that can have a static private IP, but it does not assign static private IPs to the backend VMs; the VM's NIC must be configured separately for a static private IP, and the question specifically requires the VM to have a static private IP that does not change.

34
MCQhard

Refer to the exhibit. You are reviewing an ARM template for deploying a storage account. The template is missing the storage account name parameter definition. What will happen when you attempt to deploy this template?

A.The deployment will prompt the user to provide the missing parameter.
B.The deployment will fail with a validation error because the parameter is not defined.
C.The deployment will succeed using a default name based on the resource group.
D.The deployment will create a storage account with a random name.
AnswerB

During the pre-deployment validation phase, Azure Resource Manager parses the template and evaluates all expressions that reference parameters. If a parameter is used in the resources section but is not declared in the parameters section—or has no default and is not provided—the template is considered malformed and the validation error rejection happens before any resource group changes are attempted.

Why this answer

In Azure Resource Manager (ARM) templates, all parameters must be explicitly defined in the `parameters` section of the template. If a parameter is referenced (e.g., in the `resources` section) but not defined, the deployment fails with a validation error before any resource provisioning begins. This is because ARM validates the template structure and parameter definitions during the pre-deployment validation phase, and an undefined parameter is considered a syntax error.

Exam trap

The trap here is that candidates may assume Azure will automatically prompt for or generate a missing parameter, similar to how some Azure Portal experiences handle missing inputs, but ARM templates strictly enforce parameter definitions and fail fast on validation.

How to eliminate wrong answers

Option A is wrong because ARM templates do not prompt the user for missing parameters; they fail validation if a referenced parameter is not defined. Option C is wrong because there is no default name generation based on the resource group; storage account names must be explicitly provided or generated via a defined parameter or variable. Option D is wrong because ARM does not automatically assign random names; the deployment fails before any resource creation occurs.

35
MCQmedium

A media company needs to store large video files that are frequently accessed for the first month, then infrequently after that. They want to minimize storage costs while ensuring files are instantly accessible when needed. Which storage strategy should they implement?

A.Store all files in the hot access tier
B.Manually move files between tiers using AzCopy
C.Store all files in the archive access tier
D.Use Azure Blob Storage lifecycle management to move files from hot to cool after 30 days
AnswerD

Azure Blob Storage lifecycle management lets you define a policy that automatically transitions blobs from the hot tier to the cool tier after 30 days since last modification, matching the stated access pattern. This is the correct approach because it is server-side, transparent, and eliminates manual intervention while reducing storage costs as content ages. The cool tier still offers low-latency reads, so any occasional access to older videos remains convenient without paying hot-tier storage rates. Because lifecycle management manipulates tier metadata rather than copying data, it avoids the network and compute overhead associated with manual moves.

Why this answer

Azure Blob Storage lifecycle management allows you to define rules that automatically transition blobs from the hot tier (frequent access) to the cool tier (infrequent access) after a specified number of days. This meets the requirement of instant accessibility for the first month and cost minimization thereafter, as the cool tier offers lower storage costs with the same low-latency access as the hot tier.

Exam trap

The trap here is that candidates may choose manual tiering (Option B) thinking it offers more control, but the exam tests the understanding that Azure's built-in lifecycle management is the automated, cost-optimized solution for predictable access patterns, and that archive tier (Option C) is not instantly accessible.

How to eliminate wrong answers

Option A is wrong because storing all files in the hot access tier incurs higher storage costs for the infrequently accessed period after the first month, failing to minimize costs. Option B is wrong because manually moving files between tiers using AzCopy is not a scalable or automated solution; it requires ongoing operational overhead and does not provide a policy-driven, cost-effective strategy for large volumes of files. Option C is wrong because the archive access tier has a retrieval latency of several hours (up to 15 hours for rehydration), which violates the requirement for instant accessibility when files are needed.

36
MCQmedium

A company is designing a solution for storing sensitive documents in Azure Blob Storage. They require that all data be encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, they want to prevent any accidental deletion of the key vault and its keys. Which combination of actions should they take?

A.Assign the Key Vault Contributor role to only the security team
B.Configure firewall rules to restrict network access
C.Enable soft-delete and purge protection on the key vault
D.Enable diagnostic settings and send logs to a Log Analytics workspace
AnswerC

Soft-delete retains deleted vaults and keys for a recovery window, while purge protection blocks permanent deletion during that period. Together they satisfy the requirement to prevent accidental deletion of the key vault and its keys.

Why this answer

Enabling soft-delete and purge protection on the Azure Key Vault prevents accidental or malicious deletion of the key vault and its keys, which is essential when using customer-managed keys for encryption at rest. Soft-delete allows recovery of deleted vaults and keys within a retention period, while purge protection prevents permanent deletion until the retention period expires. Option A is incorrect because Key Vault Contributor role allows management of the vault but does not prevent deletion; in fact, it could allow authorized users to delete the vault.

Option B is incorrect because firewall rules restrict network access but do not prevent deletion of the vault itself. Option D is incorrect because diagnostic settings and logging only provide monitoring and auditing, not protection against deletion.

Exam trap

Candidates might mistakenly choose RBAC roles (Option A) believing that restricting role assignments prevents deletion, but RBAC does not block deletion by users who are assigned the Contributor role. The actual protection against deletion comes from soft-delete and purge protection.

37
Multi-Selecthard

Which THREE of the following are best practices for designing a business continuity solution using Azure Site Recovery? (Select THREE.)

Select 3 answers
A.Configure automatic failover for all VMs without manual intervention
B.Perform test failovers regularly to validate the recovery plan
C.Use recovery plans to orchestrate failover of multi-tier applications
D.Use a single target region for all VMs to simplify management
E.Enable replication for all VMs that are critical to the application
AnswersB, C, E

Perform test failovers regularly to validate the recovery plan and ensure your documented RTOs and RPOs remain achievable. Test failovers in Azure Site Recovery spin up replicated copies in an isolated Azure virtual network, so you can verify application startup, networking, and dependencies without impacting production. Regular testing surfaces broken scripts, outdated credentials, or misconfigured DNS that would otherwise only appear during a real disaster.

Why this answer

Azure Site Recovery (ASR) recommends performing test failovers regularly to validate that the recovery plan works as expected without impacting production workloads. Test failovers use isolated networks to verify replication health, application consistency, and RTO/RPO targets, ensuring the actual failover process is reliable.

Exam trap

The trap here is that candidates may confuse 'automatic failover' with 'automated recovery plans' and select Option A, not realizing that ASR deliberately avoids automatic failover to prevent accidental disruption, and instead relies on manual or scripted triggers.

38
Multi-Selectmedium

Which TWO of the following are valid design considerations for implementing Azure SQL Database geo-replication? (Choose two.)

Select 2 answers
A.Geo-replication ensures zero data loss during failover
B.Geo-replication supports up to four readable secondary replicas
C.Geo-replication provides automatic failover without manual intervention
D.Geo-replication requires a listener for client connections
E.Geo-replication can be used to offload read-only workloads
AnswersB, E

Azure SQL Database active geo-replication is a valid design consideration because it supports establishing up to four readable secondary replicas. This technical mechanism allows organisations to distribute read workloads across multiple Azure regions, significantly enhancing disaster recovery capabilities and regional resilience. Designing with multiple secondaries facilitates robust business continuity planning and global read-scale scenarios, directly addressing the need for resilient database architectures.

Why this answer

Azure SQL Database geo-replication supports up to four readable secondary replicas, which can be used for read-only query offloading and disaster recovery. Option E is correct because these secondary replicas are fully readable, allowing you to distribute read-only workloads to reduce load on the primary database.

Exam trap

The trap here is that candidates confuse geo-replication with Auto-Failover Groups, assuming geo-replication alone provides automatic failover and zero data loss, when in fact it only supports manual failover with asynchronous replication.

39
MCQeasy

You are reviewing the data protection settings of an Azure Blob Storage container using the above JSON. Which of the following is true?

A.Deleted blobs are retained for 30 days
B.Blobs can be restored to any point within the last 7 days
C.Previous versions of blobs are retained
D.Versioning is disabled
AnswerC

This statement is correct because the account has blob versioning enabled (isVersioningEnabled is true). When versioning is enabled, every modification or deletion of a blob creates a new version, and all previous versions are preserved. This allows you to retrieve or restore an earlier version of a blob at any time, independent of soft-delete or point-in-time restore policies.

Why this answer

The JSON shows that the `versioning` property is set to `Enabled` for the Blob Storage container. When versioning is enabled, every modification to a blob creates a new version, and previous versions are retained indefinitely (or until explicitly deleted or a lifecycle management policy removes them). This directly supports the statement that previous versions of blobs are retained.

Exam trap

The trap here is that candidates may confuse versioning with soft delete or point-in-time restore, assuming that versioning alone provides a specific retention period or point-in-time recovery capability, when in fact versioning retains all versions indefinitely unless a lifecycle policy is applied.

How to eliminate wrong answers

Option A is wrong because the JSON does not specify a soft-delete retention period; the `deleteRetentionPolicy` is not shown or is set to a different value, and the default soft-delete retention for blobs is 7 days, not 30 days. Option B is wrong because point-in-time restore requires both versioning and change feed to be enabled, and the JSON does not indicate that change feed is enabled; additionally, point-in-time restore has a maximum retention period of 30 days, not 7 days. Option D is wrong because the JSON explicitly shows `"versioning": "Enabled"`, meaning versioning is enabled, not disabled.

40
MCQmedium

A software company hosts 100 small Azure SQL databases for different clients. Each database has low average usage but experiences unpredictable spikes. The company wants to minimize costs while allowing each database to burst up to a maximum resource limit during spikes. They also need to easily add new databases without manual sizing. Which Azure SQL Database deployment option should they use?

A.Elastic pools
B.Single databases with DTU-based tiers
C.Managed Instance
D.Hyperscale single database
AnswerA

Elastic pools are ideal for managing multiple databases with unpredictable, variable usage because they let a set of databases share a single pool of eDTUs or vCores. Each database can burst up to its per-database maximum using resources released by idle databases, while you set a per-database minimum to guarantee performance. This pooling model significantly reduces cost compared to provisioning dedicated resources per database, and adding or removing databases is an automated, simple operation. It is precisely the right fit for a large fleet of small, spiky workloads.

Why this answer

Elastic pools allow multiple databases with low average usage and unpredictable spikes to share a fixed pool of resources (eDTUs or eVCores), enabling each database to burst up to a maximum limit while minimizing overall cost. This model also supports easy addition of new databases without manual sizing, as they are simply added to the pool and share its allocated resources.

Exam trap

The trap here is that candidates may choose single databases with DTU-based tiers because they think 'bursting' requires dedicated resources, but they overlook the cost inefficiency and manual sizing overhead of managing many small databases individually.

How to eliminate wrong answers

Option B is wrong because single databases with DTU-based tiers require individual sizing and do not share resources, leading to higher costs for many low-usage databases that need burst capacity. Option C is wrong because Managed Instance is designed for lift-and-shift scenarios with full SQL Server instance-level features, not for cost-efficient multi-tenant database management with burst behavior. Option D is wrong because Hyperscale single database is optimized for very large databases (up to 100 TB) with high throughput and fast scaling, not for many small databases with unpredictable spikes where resource sharing is more cost-effective.

41
MCQmedium

A company stores unstructured data such as documents and images in Azure Blob Storage. The data is accessed frequently for the first month, then only rarely for the next year, and after that must be retained for 10 years for compliance. The company wants to minimize storage costs by automatically moving data to the most cost-effective storage tiers. Which Azure Blob Storage feature should they implement?

A.Lifecycle management policies
B.Azure Data Lake Storage access tiers
C.Soft delete
D.Immutability policies
AnswerA

Azure Blob Storage lifecycle management policies enable automatic transition of blobs to cooler tiers (Cool, Archive) based on age. The policy can move data from Hot to Cool after 30 days, then to Archive after one year, meeting the access pattern and minimizing costs.

Why this answer

Lifecycle management policies in Azure Blob Storage allow you to automatically transition blobs to cooler tiers (e.g., from Hot to Cool, then to Archive) based on age or last modification time. This directly matches the requirement to move data from frequent access (first month) to rare access (next year) and then to long-term retention (10 years) while minimizing costs.

Exam trap

The trap here is that candidates confuse storage tiers (Hot, Cool, Archive) with the automation feature (lifecycle management) that moves data between them, assuming tiers alone handle cost optimization without explicit policies.

How to eliminate wrong answers

Option B is wrong because Azure Data Lake Storage access tiers (Hot, Cool, Archive) are storage tiers themselves, not an automated policy; they require manual tier selection or lifecycle rules to move data between them. Option C is wrong because soft delete is a data protection feature that recovers accidentally deleted blobs, not a cost-optimization mechanism for tier transitions. Option D is wrong because immutability policies (WORM) prevent data modification or deletion for compliance, but do not automate tier transitions or reduce storage costs.

42
MCQhard

A healthcare company is designing a new Azure solution that must comply with HIPAA. The solution will store patient records in Azure Blob Storage and must ensure that data is encrypted at rest using customer-managed keys. The company also requires that the encryption keys be stored in a hardware security module (HSM) and that they have full control over key rotation. Which Azure service should the solutions architect use to meet these requirements?

A.Azure Disk Encryption
B.Azure Dedicated HSM
C.Azure Key Vault Managed HSM
D.Azure Key Vault (standard tier)
AnswerC

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant HSM service that enables you to store cryptographic keys in FIPS 140-2 Level 3 validated HSMs. It supports customer-managed keys for Azure Storage encryption and provides full control over key rotation, directly satisfying the HIPAA compliance and HSM requirements.

Why this answer

Azure Key Vault Managed HSM provides HSM-backed keys with full customer control, meeting the HIPAA and key rotation requirements. It integrates with Azure Storage for customer-managed keys, allowing the healthcare company to encrypt Blob Storage using keys stored in a hardware security module. Other options either lack HSM backing, are not integrated with Blob Storage, or are intended for different purposes.

Exam trap

The trap here is confusing Azure Key Vault standard tier with Managed HSM; standard tier uses software-protected keys and does not satisfy the HSM requirement.

43
MCQhard

A multinational company uses Microsoft Entra ID and several Azure subscriptions. Security administrators need to review privileged role assignments every month and require justification for continued access. Which design should be recommended?

A.Azure Monitor metric alerts
B.Management group locks
C.Microsoft Entra Privileged Identity Management with access reviews
D.Azure Policy guest configuration
AnswerC

Privileged Identity Management (PIM) enables just-in-time activation of eligible roles with time-bound assignments, mandatory multi-factor authentication, and a rule-based justification that must be supplied prior to elevation. Access reviews in PIM run on a schedule to confirm whether users still need privileged roles, automatically removing stale or unjustified assignments and generating compliance reports. Together, they directly address the requirement to require and review justifications for privileged access.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) with access reviews is the correct design because it provides time-bound, just-in-time privileged role assignments and requires users to periodically justify their continued access through automated access reviews. This directly meets the monthly review and justification requirement for privileged roles, as PIM integrates with Entra ID to enforce approval workflows and expiration policies.

Exam trap

The trap here is that candidates often confuse Azure RBAC management tools (like management locks or Azure Policy) with identity governance tools, mistakenly thinking they can control user role assignments, when in fact only Entra ID PIM provides the required review and justification workflow for privileged roles.

How to eliminate wrong answers

Option A is wrong because Azure Monitor metric alerts are used to detect and notify on performance or operational metrics (e.g., CPU usage, response times) and cannot enforce or review privileged role assignments. Option B is wrong because management group locks prevent accidental deletion or modification of Azure resources at the management group scope but do not manage identity or role assignments in Entra ID. Option D is wrong because Azure Policy guest configuration audits and configures settings inside virtual machines (e.g., OS compliance) and has no capability to review or justify privileged role assignments in Entra ID.

44
MCQmedium

A company runs a mission-critical multi-tier application on Azure VMs in West US. The application consists of database VMs, application VMs, and web VMs. During a disaster, the VMs must be recovered in a specific order: database tier first, then application tier, then web tier. The recovery point objective (RPO) is 5 minutes and recovery time objective (RTO) is 15 minutes. The company wants to periodically test the recovery process without impacting production. After failover to East US, the VMs must retain their private IP addresses to avoid DNS propagation delays. Which combination of Azure Site Recovery features should they configure?

A.A recovery plan, planned failover, and network mapping
B.A recovery plan, test failover, and network mapping
C.A recovery plan, test failover, and static IP address assignment
D.A recovery plan, planned failover, and static IP address assignment
AnswerC

Recovery Plan defines the order of VM group failover and can incorporate Automation runbooks for post-failover customizations, such as updating DNS records. Test failover enables you to validate the entire recovery flow in an isolated test network safely, without any impact to the production source VMs. By explicitly assigning a static IP address to each VM in the target subnet, you guarantee the same IP is used after failover, which is crucial for applications with hard-coded IP dependencies. This combination fully meets the requirement: orchestrated, tested, and IP-preserving failover.

Why this answer

A recovery plan enforces the required startup order (database → application → web), test failover allows non-disruptive validation of the recovery process, and static IP address assignment ensures VMs retain their private IP addresses after failover to East US, avoiding DNS propagation delays. This combination meets the RPO of 5 minutes and RTO of 15 minutes while satisfying the requirement for periodic testing without impacting production.

Exam trap

The trap here is that candidates confuse network mapping (which only maps source to target networks) with static IP address assignment (which preserves the exact private IP), leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because planned failover is used for zero-data-loss migrations or planned downtime scenarios, not for disaster recovery testing, and it does not support non-disruptive validation of the recovery process. Option B is wrong because network mapping only maps source and target networks for IP address assignment but does not guarantee that VMs retain their exact private IP addresses after failover; static IP assignment is required for that. Option D is wrong because planned failover is not suitable for periodic testing of disaster recovery, as it assumes a controlled shutdown and can impact production if used incorrectly.

45
Multi-Selecthard

You are designing a disaster recovery (DR) solution for a critical application hosted on Azure VMs. The solution must meet the following requirements: - Recovery Point Objective (RPO) of 15 minutes. - Recovery Time Objective (RTO) of 1 hour. - Automatically fail over to a secondary region in the event of a regional outage. - Support for non-disruptive DR testing. Which THREE components should you include in the solution? (Choose three.)

Select 3 answers
A.Azure Backup
B.Azure Site Recovery test failover capability
C.Azure Site Recovery
D.Azure Traffic Manager
E.Azure Front Door
AnswersB, C, D

Azure Site Recovery's test failover capability lets you perform a real failover of replicated VMs into an isolated Network Security Group-backed test network, without affecting the production environment or the ongoing replication stream. This exercise validates the orchestration of your recovery plan, as well as the boot order, IP addressing, DNS resolution, and connectivity of your recovered workloads — essentially a no-cost dress rehearsal of DR. It directly satisfies the need to prove that a DR solution actually works before a real outage occurs.

Why this answer

Azure Site Recovery's test failover capability allows you to perform non-disruptive DR testing by isolating the test failover in a separate virtual network, ensuring no impact on the production environment. This meets the explicit requirement for non-disruptive DR testing while validating replication and failover processes.

Exam trap

The trap here is that candidates often confuse Azure Backup (data protection) with Azure Site Recovery (disaster recovery), or mistakenly think Azure Front Door can handle VM-level failover when it only operates at the application layer with HTTP/HTTPS traffic.

46
Multi-Selecthard

Which THREE considerations are important when designing a highly available Azure SQL Database solution?

Select 3 answers
A.Auto-failover groups
B.Transparent Data Encryption
C.Active geo-replication
D.Zone redundancy
E.Read scale-out
AnswersA, C, D

Auto-failover groups provide a listener endpoint and automatic failover of one or more databases to a secondary region, addressing regional outage resilience. They satisfy the high-availability design consideration for cross-region database failover in Azure SQL Database.

Why this answer

Auto-failover groups (A) are correct because they enable automatic, policy-driven failover of one or more databases to a secondary region, providing a readable/writable listener endpoint and reducing RTO/RPO for a highly available Azure SQL Database solution. Active geo-replication (C) is correct because it lets you create up to four readable secondaries in different regions and manually fail over, which is a core mechanism for cross-region high availability and disaster recovery. Zone redundancy (D) is correct because it distributes the database across availability zones within a region, protecting against datacenter-level failures and improving local availability with an SLA up to 99.995%.

Transparent Data Encryption (B) is not a high-availability consideration; it is a data-at-rest encryption feature that protects confidentiality but does not affect failover or uptime. Read scale-out (E) is a performance/read-offload capability using read-only replicas, not a high-availability design consideration, since it does not provide failover or redundancy.

Exam trap

The trap here is that candidates often confuse security features (like TDE) or performance features (like read scale-out) with high availability mechanisms, leading them to select options that do not actually provide automatic failover or regional resilience.

47
MCQhard

Refer to the exhibit. Your team deploys this ARM template to a resource group in West US. After deployment, you need to ensure the storage account is geo-redundant. What is the most efficient way to modify the template to achieve this?

A.Add a second storage account resource with Geo-redundant replication.
B.Change the 'kind' property to 'BlobStorage'.
C.Change the 'apiVersion' to a newer version.
D.Change the 'sku.name' property from 'Standard_LRS' to 'Standard_GRS'.
AnswerD

Set `sku.name` to `Standard_GRS` because this SKU explicitly configures geo-redundant storage (GRS) for the account. With GRS, data is synchronously replicated three times within the primary region and asynchronously replicated three times in the paired secondary region, providing higher durability than LRS. In the ARM template, `sku.name` is the authoritative property for the replication strategy, and `Standard_GRS` meets the geo-redundancy requirement.

Why this answer

Changing the 'sku.name' property from 'Standard_LRS' to 'Standard_GRS' directly modifies the replication type of the existing storage account to geo-redundant storage (GRS). This is the most efficient approach as it updates the single resource in-place without adding extra resources or altering the storage account's kind or API version.

Exam trap

The trap here is that candidates may think adding a new resource or changing the API version is necessary, but the most efficient way is to modify the existing resource's 'sku.name' property, which directly controls replication redundancy.

How to eliminate wrong answers

Option A is wrong because adding a second storage account with Geo-redundant replication does not make the existing storage account geo-redundant; it creates a separate resource, which is inefficient and does not meet the requirement. Option B is wrong because changing the 'kind' property to 'BlobStorage' changes the storage account type to blob-only storage, which does not affect replication redundancy; replication is controlled by the 'sku.name' property. Option C is wrong because changing the 'apiVersion' to a newer version does not alter the replication setting; the 'apiVersion' only defines the schema version for the template and does not impact resource properties like redundancy.

48
MCQmedium

Your company is migrating a legacy application to Azure. The application uses a proprietary database that requires file-level access to data files. You need to minimize changes to the application. Which Azure storage solution should you recommend?

A.Azure Files
B.Azure Disk Storage
C.Azure Blob Storage
D.Azure NetApp Files
AnswerA

Azure Files provides fully managed SMB (and optionally NFS) file shares in the cloud, accessible via standard file-sharing protocols such as SMB 3.0. Because the legacy application expects file-level access over a shared filesystem, Azure Files can be mounted as a network drive on the target VM without modifying application code, preserving existing file semantics and minimizing migration changes. It also integrates with Azure Active Directory for Kerberos-based authentication, making it a low-friction drop-in for file-level dependencies.

Why this answer

Azure Files provides fully managed SMB and NFS file shares that offer file-level access over the network, which is exactly what a legacy application requiring file-level access to data files needs. By mapping a drive to an Azure file share, the application can continue using standard file I/O APIs with minimal or no code changes, making it the correct choice for this migration scenario.

Exam trap

The trap here is that candidates often confuse Azure Disk Storage (which is block-level and attached to a single VM) with file-level access, or they overcomplicate the solution by choosing Azure NetApp Files when Azure Files is simpler and sufficient for the stated requirement of minimizing changes.

How to eliminate wrong answers

Option B (Azure Disk Storage) is wrong because it provides block-level storage attached to a single VM as a virtual hard disk (VHD), not file-level network access; the application would need to be rewritten to use block I/O instead of file APIs. Option C (Azure Blob Storage) is wrong because it is an object storage solution accessed via REST APIs, not file-level protocols like SMB or NFS, requiring significant application changes. Option D (Azure NetApp Files) is wrong because while it does offer file-level access via NFS and SMB, it is an enterprise-grade, high-performance solution that is overkill for a simple migration requiring minimal changes and introduces unnecessary complexity and cost.

49
MCQeasy

Your organization runs a web application on Azure App Service (Standard tier) in the West US region. The application uses Azure Blob Storage for static content and Azure SQL Database (Standard tier) for dynamic data. The compliance requirements specify a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 4 hours. You need to design a disaster recovery solution that meets these requirements with minimal cost. Which option should you recommend?

A.Deploy App Service in two regions with Azure Traffic Manager. Use Azure Site Recovery to replicate the App Service and SQL Database. Enable geo-redundant storage for Blob Storage.
B.Deploy App Service in two regions with Azure Front Door. Use active geo-replication for Azure SQL Database. Enable read-access geo-redundant storage (RA-GRS) for Blob Storage.
C.Use Azure Traffic Manager to distribute traffic. Manually copy Blob Storage to a secondary region. Use Azure SQL Database export to bacpac and import in secondary region.
D.Configure App Service backup to a geo-redundant storage account. Use geo-redundant storage (GRS) for Blob Storage. Enable geo-restore for Azure SQL Database.
AnswerD

Configuring App Service backup to a geo-redundant storage account ensures that application content, including code and configuration, is automatically replicated to the paired region, which is essential because App Service itself has no built-in geo-replication. GRS for Blob Storage automatically replicates blobs to the secondary region, providing a synchronous (or async, depending on service tier) copy that can be used for failover without manual intervention. Enabling geo-restore for Azure SQL Database uses the geo-redundant backups that Azure maintains automatically, offering an RPO of up to 1 hour, which aligns exactly with the stated requirement. Together these components give a fully automated, PaaS-native disaster recovery approach with no need for Site Recovery, Front Door, or manual data copies.

Why this answer

Meets the RPO of 1 hour and RTO of 4 hours at minimal cost by using App Service backup to geo-redundant storage (which can be restored within the RTO), geo-redundant storage (GRS) for Blob Storage (providing automatic replication to a paired region), and geo-restore for Azure SQL Database (which restores from geo-replicated backups with an RPO of 1 hour and RTO typically under 4 hours). This approach avoids the cost and complexity of running active secondary instances.

Exam trap

The trap here is that candidates often assume active-active or active-passive multi-region deployments (like Traffic Manager or Front Door) are required for DR, but Azure's built-in geo-restore and geo-redundant storage features can meet moderate RPO/RTO targets at a fraction of the cost without running duplicate resources.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery does not support replicating Azure App Service or Azure SQL Database (it is for IaaS VMs and physical servers); also, using Traffic Manager with two active App Service instances incurs higher cost than needed. Option B is wrong because active geo-replication for Azure SQL Database requires a Premium or Business Critical tier, not the Standard tier, and Azure Front Door adds unnecessary cost and complexity for a passive DR scenario. Option C is wrong because manually copying Blob Storage and using bacpac export/import cannot achieve an RPO of 1 hour (bacpac exports are point-in-time and can take hours) and the manual process exceeds the RTO of 4 hours.

50
Multi-Selecteasy

Which TWO of the following Azure storage services support hosting static websites?

Select 2 answers
A.Azure Storage Account (general-purpose v2)
B.Azure Cosmos DB
C.Azure NetApp Files
D.Azure Blob Storage
E.Azure Files
AnswersA, D

A general-purpose v2 storage account is the management object that exposes the static website feature. When you enable the 'Static website' property, Azure provisions a dedicated web endpoint and a hidden `$web` blob container that serves your HTML, CSS, and JavaScript files with HTTP GET requests, supporting custom domains and CDN integration.

Why this answer

Azure Storage Account (general-purpose v2) supports hosting static websites by enabling the 'Static website' feature, which configures a container named '$web' to serve static content (HTML, CSS, JS) directly via a public endpoint. This feature is built into the storage account's blob service and provides automatic routing for index and error documents, making it a cost-effective solution for static site hosting.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage (which supports static websites when part of a general-purpose v2 account) with Azure Files or Azure NetApp Files, assuming any storage service can serve web content, but only the blob service with the static website feature enabled provides the necessary HTTP endpoint and routing logic.

51
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). External partners need temporary access to an internal application. The process must be self-service: partners request access, the request goes through an approval workflow managed by a manager from the partner's organization, and access automatically expires after 30 days. The company also wants to send reminder emails 7 days before expiration. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Governance - Access Reviews
B.Microsoft Entra ID Identity Governance - Entitlement Management
C.Microsoft Entra ID Privileged Identity Management (PIM)
D.Microsoft Entra ID Conditional Access
AnswerB

Entitlement Management provides access packages that external users can request. It includes approval workflows, automatic expiration after a defined duration, and email reminders before expiration. It is designed for managing external identities and time-limited access.

Why this answer

Microsoft Entra ID Identity Governance - Entitlement Management is specifically designed to manage access for external users through self-service access packages. It supports approval workflows with external managers, automatic time-bound access (e.g., 30-day expiration), and lifecycle notifications like reminder emails 7 days before expiry. This aligns perfectly with the requirement for partner-managed, temporary, self-service access.

Exam trap

The trap here is confusing Entitlement Management (designed for external user access lifecycle) with Access Reviews (which is for periodic recertification, not self-service provisioning) or PIM (which is for internal privileged roles, not application access for partners).

How to eliminate wrong answers

Option A is wrong because Access Reviews are used for periodic attestation of existing access, not for self-service request workflows with automatic expiration and reminders. Option C is wrong because Privileged Identity Management (PIM) is focused on just-in-time privileged role activation for internal administrators, not for granting temporary access to external partners for an application. Option D is wrong because Conditional Access enforces policies (e.g., MFA, location) during sign-in but does not provide self-service request, approval workflows, or automatic expiration management.

52
MCQhard

A company runs a critical application on Azure SQL Database in the West US region. They need a disaster recovery solution with an RPO of 5 seconds and an RTO of 1 hour. They also need to be able to perform patching and maintenance on the primary without downtime. Which configuration should they implement?

A.Active geo-replication with auto-failover group
B.Azure SQL Database backup to geo-redundant storage
C.Azure SQL Database with zone-redundant configuration
D.Azure SQL Database with failover group using manual failover
AnswerA

Active geo-replication with auto-failover group continuously streams transaction log changes from the primary database to a secondary replica in a paired region, providing a recovery point objective (RPO) of up to 5 seconds and a recovery time objective (RTO) of about 1 hour. The auto-failover group adds an orchestration layer that monitors health and triggers failover automatically, and also enables a planned failover that fully synchronizes before switching so no data is lost during maintenance. For a critical application, this combination meets stringent RPO/RTO requirements while keeping downtime minimal.

Why this answer

Active geo-replication with auto-failover group meets the RPO of 5 seconds (typically under 5 seconds for active geo-replication) and RTO of 1 hour (auto-failover groups can fail over in minutes). It also supports patching and maintenance on the primary without downtime by failing over to a secondary replica during planned maintenance, leveraging the continuous data synchronization between primary and secondary databases in different Azure regions.

Exam trap

The trap here is that candidates confuse zone-redundant configuration (which only protects within a region) with geo-redundant disaster recovery, or they assume manual failover can meet strict RTOs without considering the human delay factor.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database backup to geo-redundant storage (RA-GRS) provides an RPO of up to 12 hours and RTO of 12-24 hours, far exceeding the required 5-second RPO and 1-hour RTO, and does not support zero-downtime patching. Option C is wrong because zone-redundant configuration protects against zonal failures within a single region, not against regional disasters, and cannot meet the RPO/RTO for cross-region DR. Option D is wrong because a failover group using manual failover requires human intervention to trigger failover, which cannot achieve the 1-hour RTO reliably and does not support automated zero-downtime patching without manual steps.

53
Multi-Selectmedium

You are designing a solution to monitor and analyze security events across your Azure environment. Which TWO Azure services should you include in your design to provide centralized logging and threat detection? (Choose two.)

Select 2 answers
A.Azure Firewall
B.Azure Log Analytics
C.Microsoft Sentinel
D.Azure Policy
E.Azure Network Watcher
AnswersB, C

Azure Log Analytics is the core data-collection and querying service within Azure Monitor, ingesting log data from virtually all Azure resources, virtual machines, and applications into a centralized workspace. It supports Kusto Query Language (KQL) queries that let you correlate security events, identify patterns, and troubleshoot incidents from a single pane of glass. This makes it the correct foundational service for monitoring and analyzing security-related logs, especially before layering on more advanced analytics like Sentinel.

Why this answer

B is correct because Azure Log Analytics is the central repository for log data in Azure Monitor, enabling you to collect, correlate, and query security events from multiple sources using Kusto Query Language (KQL). C is correct because Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests logs from Log Analytics and provides advanced threat detection, investigation, and automated response. Together, they form the foundation for centralized logging and threat detection in Azure.

Exam trap

The trap here is that candidates often confuse Azure Firewall (a network security appliance) or Azure Network Watcher (a diagnostic tool) with logging and threat detection services, when in fact they are not designed for centralized log analysis or SIEM functionality.

54
MCQmedium

A company runs a web application on Azure App Service with a Standard tier plan. The application uses an Azure SQL Database (DTU-based) for storage. The business requires that the application remain available in the event of a single Azure region outage. Which solution meets the requirement with the least administrative effort?

A.Use an App Service Environment (ASE) in a single region with App Service plans in multiple availability zones
B.Use Azure Front Door to route traffic to a secondary App Service in the same region
C.Configure Azure Backup for the App Service and SQL Database
D.Deploy an additional App Service in a secondary region and use Azure SQL Database active geo-replication
AnswerD

Deploying a second App Service in a secondary Azure region and configuring active geo-replication for Azure SQL Database is the standard, simplest disaster recovery pattern. Active geo-replication continuously replicates up to four readable secondary databases to the paired or chosen region, enabling a failover group that can automatically or manually promote the secondary to primary with minimal downtime. The additional App Service in that secondary region can then serve traffic once DNS records are switched (for example, via Azure Traffic Manager or Azure Front Door), meeting a cross-region disaster recovery requirement without needing a full standby environment.

Why this answer

Deploying an additional App Service in a secondary region and using Azure SQL Database active geo-replication ensures that both the compute and data tiers can fail over to a different Azure region during a regional outage. Active geo-replication creates readable secondary replicas of the SQL Database in the paired region, and with App Service, you can use Azure Front Door or Traffic Manager to route traffic to the secondary instance. This solution meets the availability requirement with minimal administrative overhead, as geo-replication is managed by Azure and does not require complex manual synchronization.

Exam trap

The trap here is that candidates often confuse availability zones (which protect against datacenter failures within a region) with region pairs (which protect against full regional outages), leading them to choose Option A or B incorrectly.

How to eliminate wrong answers

Option A is wrong because an App Service Environment (ASE) in a single region with App Service plans in multiple availability zones protects only against zonal failures within that region, not against a full regional outage. Option B is wrong because using Azure Front Door to route traffic to a secondary App Service in the same region does not provide resilience against a regional outage; both instances would be affected simultaneously. Option C is wrong because Azure Backup is designed for data protection and recovery from accidental deletion or corruption, not for maintaining continuous availability during a regional outage; it involves downtime during restore operations.

55
Multi-Selecteasy

Which TWO features of Microsoft Entra ID can be used to secure hybrid identities?

Select 2 answers
A.Microsoft Sentinel
B.Microsoft Intune
C.Seamless Single Sign-On
D.Azure Active Directory Domain Services
E.Password Hash Synchronization
AnswersC, E

Seamless Single Sign-On is a correct answer: it silently signs users into Microsoft Entra ID when they are on a domain-joined device connected to the corporate network, using their existing on-premises AD Kerberos tickets. It lets users access cloud and SaaS applications without re-entering passwords, reducing password fatigue and phishing exposure while relying on the on-premises credential validation. However, it is not a standalone authentication method and must be paired with Password Hash Synchronization or Pass-through Authentication.

Why this answer

Seamless Single Sign-On (Seamless SSO) automatically signs users in when they are on corporate devices connected to the corporate network, eliminating password prompts. Password Hash Synchronization (PHS) synchronizes a hash of the user's on-premises AD password to Azure AD, enabling cloud authentication without additional infrastructure. Both features directly secure hybrid identities by extending on-premises credentials to the cloud.

Exam trap

The trap here is that candidates often confuse Azure AD DS (a managed domain service) with a feature of Microsoft Entra ID, when in fact it is a separate service that provides legacy LDAP and NTLM capabilities, not a native hybrid identity authentication feature.

56
Multi-Selectmedium

Which TWO of the following are valid considerations when designing a SQL Server Always On availability group in Azure VMs? (Choose two.)

Select 2 answers
A.The availability group listener should use a static IP address in the same subnet as the primary replica.
B.The availability group listener can use DHCP to automatically assign an IP address.
C.The number of replicas should be an odd number to avoid split-brain scenarios.
D.A file share witness is required for the quorum configuration.
E.All replicas must be in the same subnet to use a single internal load balancer.
AnswersA, C

The availability group listener is created as a clustered resource in Windows Server Failover Clustering (WSFC) and must be assigned a static IP address because WSFC does not support dynamic IP assignment for network name resources. In an Azure IaaS deployment, that static IP must be a free address from the same subnet that hosts the primary replica, because the listener's IP is used as the frontend IP of the internal load balancer and must be directly routable to the replica nodes. This ensures that client connections are forwarded to the current primary replica when a failover occurs.

Why this answer

The availability group listener in Azure VMs requires a static IP address in the same subnet as the primary replica. This is necessary because the internal load balancer (ILB) used for the listener must have a static frontend IP that matches the listener's IP, and the IP must reside in the same subnet as the primary replica to ensure proper routing and failover behavior.

Exam trap

The trap here is that candidates often assume a file share witness is mandatory for quorum in Azure VMs, but Azure provides a cloud witness as a simpler alternative, and the requirement for an odd number of replicas is a general best practice to avoid split-brain, not an Azure-specific constraint.

57
Multi-Selectmedium

Your company uses Microsoft Entra ID. You need to implement a privileged identity management (PIM) strategy to secure administrative roles. Which TWO capabilities does PIM provide? (Choose two.)

Select 2 answers
A.Approval workflows for role activation
B.Conditional Access policies for role activation
C.Management of external identities
D.Just-in-time (JIT) access to privileged roles
E.Automated user provisioning to applications
AnswersA, D

PIM's approval workflows require designated approvers to approve an activation request before the role becomes active, adding human oversight to privileged access. Approvals are configured per role and support multi-stage approval via approver groups, with users able to provide justification. This gate prevents unauthorized or casual elevation, complementing time-bound eligibility.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides time-based and approval-based role activation to secure privileged roles. Approval workflows for role activation (Option A) are a core PIM feature, allowing designated approvers to review and approve activation requests before a user gains elevated permissions. This ensures that privileged access is granted only after explicit authorization, reducing the risk of unauthorized use.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control access to apps) with PIM's role activation policies (which control access to privileged roles), leading them to incorrectly select Option B.

58
Drag & Dropmedium

Drag and drop the steps to implement Azure Site Recovery for a Hyper-V VM into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, create the vault. Then ensure network connectivity. Install the provider and agent.

Create and apply a replication policy. Finally, enable replication.

59
MCQmedium

You are designing an authentication solution for a mobile application that uses Azure AD B2C (now Microsoft Entra External ID). The application needs to support social logins (Google, Facebook) and also allow users to sign in with their corporate Microsoft Entra ID accounts. Which of the following identity providers should you configure?

A.Use Microsoft Entra ID as the only identity provider and configure federation with Google and Facebook.
B.Use Microsoft Entra External ID with Google and Facebook only, and advise corporate users to create local accounts.
C.Configure Google and Facebook as social identity providers, and add Microsoft Entra ID as a custom identity provider.
D.Configure only Google and Facebook as identity providers, and use Microsoft account for corporate users.
AnswerC

Microsoft Entra External ID is specifically built for customer-facing apps and supports multiple identity providers within a single tenant. Google and Facebook can be configured as built-in social identity providers for consumer users, while Microsoft Entra ID can be added as a custom identity provider using OpenID Connect (OIDC) or SAML federation, enabling corporate users to sign in with their existing work accounts. This hybrid configuration cleanly handles both consumer social logins and enterprise corporate identities without requiring local account creation or separate authentication flows.

Why this answer

Microsoft Entra External ID (Azure AD B2C) supports social identity providers like Google and Facebook natively, and also allows you to add Microsoft Entra ID as a custom (OpenID Connect) identity provider. This enables corporate users to sign in with their existing Entra ID accounts while external users can use social logins, all within a single B2C tenant.

Exam trap

The trap here is that candidates often assume Microsoft Entra ID can directly federate with social identity providers, but in reality, social identity provider support requires Microsoft Entra External ID (Azure AD B2C) as the authentication platform.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID alone cannot directly federate with Google or Facebook as social identity providers; it requires Azure AD B2C (External ID) for social identity support. Option B is wrong because advising corporate users to create local accounts defeats the purpose of using their existing corporate identities and introduces unnecessary friction and security risks. Option D is wrong because using Microsoft account (personal) for corporate users does not support corporate Entra ID accounts, which require a dedicated identity provider configuration.

60
MCQhard

A multinational corporation is designing a disaster recovery strategy for a critical application running on Azure VMs. The application must have a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The primary region is East US, and the secondary region is West US. The solution must minimize costs while meeting the requirements. What should you recommend?

A.Deploy an active-passive configuration with Azure Front Door and Traffic Manager
B.Implement Azure Site Recovery for the VMs
C.Configure the VMs in an availability zone across East US and West US
D.Use Azure Backup with cross-region restore for the VMs
AnswerB

Azure Site Recovery is the native DR service for IaaS VMs, continuously replicating VM storage to a paired secondary region with an RPO as low as 15 seconds and RTO in minutes. It handles orchestrated failover, failback, and recovery drills, offering a cost-effective, fully managed solution that meets the stringent DR objectives without extra infrastructure. This directly satisfies the requirement for cross-region VM protection.

Why this answer

Azure Site Recovery (ASR) provides orchestrated replication of Azure VMs from a primary to a secondary region with an RPO as low as 15 minutes (Premium SSD) and RTOs that can be met within 1 hour through planned failover. It is the native Azure service designed for disaster recovery of IaaS workloads, offering cost-effective replication without requiring always-on secondary VMs, as it only incurs storage costs for replicated disks until failover.

Exam trap

The trap here is that candidates confuse high-availability solutions (availability zones, load balancers) with disaster recovery solutions, or assume Azure Backup's cross-region restore can meet low RPOs, when in fact only Azure Site Recovery provides the sub-hour replication frequency required for a 15-minute RPO.

How to eliminate wrong answers

Option A is wrong because Azure Front Door and Traffic Manager are global load-balancing and traffic-routing services; they do not provide VM replication or failover orchestration, and an active-passive configuration alone cannot meet the RPO/RTO without a replication mechanism. Option C is wrong because availability zones are within a single Azure region (e.g., East US) and cannot span across East US and West US; they protect against datacenter failures within a region, not regional disasters. Option D is wrong because Azure Backup with cross-region restore has a default RPO of 24 hours (for daily backups) and cannot achieve a 15-minute RPO; it is designed for backup and long-term retention, not low-latency disaster recovery.

61
MCQmedium

A company is migrating on-premises SQL Server databases to Azure. They need to minimize administrative overhead for patching and backups while ensuring high availability. The solution must support automatic failover within the same Azure region. Which Azure service should they choose?

A.SQL Server on Azure Virtual Machines
B.Azure SQL Database Hyperscale
C.Azure SQL Database (single database)
D.Azure SQL Database Managed Instance
AnswerD

Azure SQL Database Managed Instance delivers the broadest SQL Server engine compatibility, including support for SQL Agent, linked servers, CLR, and cross-database transactions, while fully automating maintenance tasks such as patching, backups, and high availability with auto-failover. This makes it the ideal PaaS target for migrating existing on-premises SQL Server databases with minimal administrative overhead, as it removes the need to manage VMs or handle manual DR configuration. The service provides a native virtual network (VNet) deployment and near-100% feature parity, so applications and DBAs can operate almost exactly as they did on-premises.

Why this answer

Azure SQL Database Managed Instance is correct because it provides near-100% compatibility with on-premises SQL Server, automated patching and backups, and built-in high availability with automatic failover within the same region via Always On availability groups. This minimizes administrative overhead while meeting the high availability requirement without manual configuration.

Exam trap

The trap here is that candidates often confuse Azure SQL Database Managed Instance with Azure SQL Database single database, assuming both offer the same high availability and compatibility, but Managed Instance provides full SQL Server instance-level features and automatic failover within the region without additional configuration.

How to eliminate wrong answers

Option A is wrong because SQL Server on Azure Virtual Machines requires manual patching and backup management, increasing administrative overhead, and high availability requires manual configuration of Windows Server Failover Clustering or SQL Server Always On. Option B is wrong because Azure SQL Database Hyperscale is designed for large databases with fast scaling and read scale-out, but its high availability model uses page servers and a log-based service, not automatic failover within the same region in the same way as Managed Instance; it also lacks full SQL Server agent and CLR support. Option C is wrong because Azure SQL Database (single database) offers automated patching and backups but does not support automatic failover within the same region without configuring active geo-replication or failover groups, which adds complexity and cost; it also has limited compatibility for existing SQL Server features like SQL Agent jobs and cross-database queries.

62
MCQhard

You are a solutions architect for a financial services company. The company is deploying a new critical application on Azure that processes sensitive customer transactions. The application consists of an ASP.NET Core web app (Azure App Service), a REST API (Azure Kubernetes Service), and an Azure SQL Database. The requirements are: - All data at rest must be encrypted using customer-managed keys (CMK) stored in a managed HSM. - All network traffic between components must be encrypted and traverse the Microsoft backbone network. - The web app must be protected against common web attacks (SQL injection, XSS). - The solution must automatically scale the API based on CPU utilization. - All API calls must be authenticated using OAuth 2.0 with Microsoft Entra ID. - Logs from all components must be sent to a central Log Analytics workspace for analysis. - The solution must have a recovery time objective (RTO) of 1 hour and recovery point objective (RPO) of 5 minutes for the database. Which combination of Azure services should you recommend to meet ALL requirements?

A.Azure Front Door with WAF, Azure SQL Database point-in-time restore, Azure Key Vault Managed HSM, Azure App Service with private endpoint, AKS with HPA, Azure Log Analytics agent, Microsoft Entra ID
B.Azure Front Door with WAF, Azure SQL Database geo-replication, Azure Key Vault (Standard), Azure App Service with private endpoint, AKS with HPA, Azure Diagnostics extension, Microsoft Entra ID
C.Azure Application Gateway with WAF, Azure SQL Database active geo-replication, Azure Key Vault Managed HSM, Azure App Service with VNet integration, AKS with cluster autoscaler, Azure Monitor Agent, Microsoft Entra ID
D.Azure Application Gateway with WAF, Azure SQL Database failover groups, Azure Key Vault Managed HSM, Azure App Service with service endpoint, AKS with HPA, Azure Monitor Agent, Microsoft Entra ID
AnswerD

Correct. Failover groups meet RPO and RTO, Managed HSM meets key storage, service endpoint keeps traffic on Microsoft backbone, AKS with HPA scales based on CPU, Application Gateway WAF protects against attacks, Azure Monitor Agent collects logs, and Microsoft Entra ID authenticates API calls.

Why this answer

Meets all requirements: Azure Application Gateway with WAF protects against SQL injection and XSS; Azure SQL Database failover groups provide an RPO of 5 seconds and an RTO of 1 hour (auto-failover); Azure Key Vault Managed HSM stores customer-managed keys for encryption at rest; App Service with service endpoint ensures traffic to other Azure services stays on the Microsoft backbone network (combined with AKS in a VNet, internal traffic stays on backbone); AKS with Horizontal Pod Autoscaler (HPA) scales pods based on CPU utilization; Azure Monitor Agent sends logs to Log Analytics; Microsoft Entra ID authenticates API calls via OAuth 2.0. Option A uses point-in-time restore, which cannot guarantee RPO of 5 minutes and RTO of 1 hour. Option B uses Key Vault Standard instead of Managed HSM.

Option C uses cluster autoscaler, which scales nodes, not pods, failing the CPU-based scaling requirement.

Exam trap

The trap is confusing cluster autoscaler with Horizontal Pod Autoscaler (HPA). Cluster autoscaler scales the number of node VMs, not pod replicas, and does not respond to CPU utilization; it only responds to pending pods. HPA scales pod replicas based on CPU or memory metrics.

Also, service endpoints vs. private endpoints: both keep traffic on the Microsoft backbone, but private endpoints provide a private IP in the VNet for enhanced security.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database point-in-time restore has an RPO of up to 1 hour (not 5 minutes) and does not meet the RPO requirement; also, Azure Log Analytics agent is deprecated in favor of Azure Monitor Agent. Option B is wrong because Azure Key Vault (Standard) does not support customer-managed keys stored in a managed HSM (requires Premium tier or Managed HSM), and Azure Diagnostics extension is legacy and not the recommended agent for Log Analytics. Option D is wrong because Azure App Service with service endpoint does not ensure traffic traverses the Microsoft backbone network (it uses public IPs with ACLs, not private IPs); also, AKS with HPA (Horizontal Pod Autoscaler) scales pods, not nodes, and the requirement is to scale the API based on CPU utilization, which is better handled by cluster autoscaler for node-level scaling or HPA for pod-level scaling, but the key issue is service endpoint not meeting the private network requirement.

63
MCQhard

A company runs a high-performance computing (HPC) workload on Azure that requires extremely low latency (under 10 microseconds) between multiple VMs for MPI communication. The VMs are part of a single job and must be placed together to minimize network latency. Which VM deployment option should they use?

A.Azure Virtual Machine Scale Sets with a Proximity Placement Group
B.Azure Availability Sets
C.Azure Virtual Machine Scale Sets across Availability Zones
D.Azure Kubernetes Service (AKS)
AnswerA

Azure Virtual Machine Scale Sets with a Proximity Placement Group (PPG) is the correct choice for tightly coupled HPC workloads because a PPG co-locates all VM instances within the same Azure datacenter, minimizing network latency to the sub-10 microseconds required by MPI applications. VMSS integrates with PPG by allowing you to scale the compute cluster out while ensuring every new instance remains within the placement group, preserving low-latency inter-node communication. This combination also enables the use of high-throughput, low-latency networking such as InfiniBand on supported HPC VM SKUs, which is essential for parallel jobs that need frequent, low-latency message passing.

Why this answer

A Proximity Placement Group (PPG) within a Virtual Machine Scale Set ensures that all VMs are physically located as close as possible within an Azure datacenter, reducing network latency to under 10 microseconds for MPI communication. This is the only option that guarantees co-location of VMs for a single HPC job, as PPGs minimize inter-VM latency by placing VMs in the same rack or cluster.

Exam trap

The trap here is that candidates often confuse Availability Sets (which provide high availability) with Proximity Placement Groups (which provide low latency), or assume that Availability Zones offer sufficient performance for HPC, ignoring the significant latency penalty of inter-zone communication.

How to eliminate wrong answers

Option B is wrong because Availability Sets only protect against failures by distributing VMs across fault and update domains, but they do not guarantee low latency or co-location; in fact, they may spread VMs across different racks, increasing latency. Option C is wrong because Virtual Machine Scale Sets across Availability Zones place VMs in physically separate datacenters within a region, which introduces network latency far exceeding the 10-microsecond requirement due to inter-zone communication. Option D is wrong because Azure Kubernetes Service (AKS) abstracts VM placement and does not provide native mechanisms to enforce co-location of pods for low-latency MPI communication; it relies on underlying node placement, which is not guaranteed to be within a single rack.

64
MCQhard

Contoso Ltd. is a global e-commerce company running its online store on Azure. The application consists of: - Frontend: Azure App Service (Windows) in West US. - Backend: Azure Kubernetes Service (AKS) cluster in West US. - Database: Azure SQL Database (General Purpose, S2) in West US. - Cache: Azure Cache for Redis (Standard C1) in West US. - Storage: Azure Blob Storage (LRS) for product images. Business continuity requirements: - RPO: 5 minutes for the database. - RTO: 1 hour for the entire application. - The solution must survive a complete West US region outage. - Budget is limited; minimize additional costs. What should you recommend as the primary DR strategy?

A.Deploy a secondary region (East US) with a passive AKS cluster (minimal node count), a standby App Service plan (same tier), and a secondary Azure SQL Database in an auto-failover group. Use Azure Traffic Manager for frontend and configure Azure Cache for Redis with geo-replication. For Blob Storage, enable geo-redundant storage (GRS).
B.Use Azure Backup for the database with 5-minute log backup frequency. For the app, use Azure App Service backup with frequency to a secondary region. For AKS, back up persistent volumes using Azure Backup. Restore everything in a secondary region during disaster.
C.Deploy the entire application across two Azure Availability Zones within West US. Use zone-redundant storage for blobs, zone-redundant App Service plan, and zone-redundant AKS. For SQL Database, use a zone-redundant configuration. For Redis, use Enterprise tier with zone redundancy.
D.Use Azure Site Recovery to replicate all VMs (including AKS nodes) to a secondary region. For the database, use Azure SQL Database active geo-replication. For Azure Cache for Redis, replicate data via geo-replication. Use Azure Traffic Manager for frontend traffic routing.
AnswerA

A passive secondary region with auto-failover groups meets the 5-minute database RPO and 1-hour RTO, while Traffic Manager, Redis geo-replication and GRS cover the remaining tiers. Minimal AKS nodes and a standby plan keep costs low, satisfying the limited-budget constraint.

Why this answer

It meets the RPO of 5 minutes for the database using an auto-failover group with a secondary Azure SQL Database in East US, which provides continuous data synchronization with minimal data loss. The passive AKS cluster (minimal node count) and standby App Service plan minimize costs while ensuring RTO of 1 hour by allowing rapid scaling during failover. Azure Traffic Manager routes frontend traffic to the secondary region, and geo-replication for Redis Cache and GRS for Blob Storage provide data durability across regions, satisfying the requirement to survive a complete West US region outage.

Exam trap

The trap here is that candidates often choose zone-redundant options (Option C) thinking they provide regional resilience, but they only protect against zone failures within a region, not a complete region outage, which is explicitly required in the question.

How to eliminate wrong answers

Option B is wrong because Azure Backup with 5-minute log backup frequency can achieve an RPO of 5 minutes, but restoring the entire application in a secondary region during a disaster would likely exceed the 1-hour RTO due to the time required to restore App Service backups, AKS persistent volumes, and database backups, and it does not provide automated failover or pre-provisioned infrastructure. Option C is wrong because deploying across Availability Zones within West US cannot survive a complete region outage, as all zones are in the same region; this violates the requirement to survive a full West US region outage. Option D is wrong because Azure Site Recovery replicates VMs, but AKS nodes are typically managed and ephemeral; replicating them adds complexity and cost, and the solution does not address the App Service frontend or Blob Storage replication efficiently, while active geo-replication for SQL Database is more expensive than an auto-failover group with a secondary database in the same tier.

65
MCQeasy

You are designing a disaster recovery strategy for an Azure virtual machine running a critical application. The VM is in the East US region. Your recovery point objective (RPO) is 15 minutes, and your recovery time objective (RTO) is 1 hour. Which Azure service should you use to replicate the VM to the West US region?

A.Azure Site Recovery
B.Azure Traffic Manager
C.Azure Backup
D.Azure Migrate
AnswerA

Azure Site Recovery orchestrates replication of Azure VMs to a paired secondary region by continuously copying disk writes to a Recovery Services vault, achieving RPOs as low as a few seconds and RTOs in minutes. It supports application-consistent snapshots and includes test failover, scheduled failover, and full orchestration with recovery plans. This continuous, coordinated replication is precisely what makes ASR the correct DR solution.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs between regions. It supports continuous replication with an RPO as low as 30 seconds and can meet your 15-minute RPO, while automated failover and recovery plans can achieve a 1-hour RTO by spinning up replicated VMs in the West US region.

Exam trap

The trap here is that candidates confuse Azure Backup (which provides point-in-time restores with longer RPO/RTO) with Azure Site Recovery (which provides continuous replication and rapid failover), overlooking the specific RPO and RTO requirements stated in the question.

How to eliminate wrong answers

Option B is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes incoming traffic based on routing methods (e.g., performance, priority), but it does not replicate VM data or provide disaster recovery failover capabilities. Option C is wrong because Azure Backup provides crash-consistent or application-consistent backups with a minimum RPO of 1 hour (for hourly backups) and a restore time that typically exceeds 1 hour, failing to meet the 15-minute RPO and 1-hour RTO. Option D is wrong because Azure Migrate is a tool for assessing and migrating on-premises workloads to Azure, not for ongoing replication or disaster recovery between Azure regions.

66
MCQmedium

A company uses Azure SQL Database for a line-of-business application. They need to implement a disaster recovery solution across Azure regions with RPO of 5 seconds and RTO of 30 seconds. Which feature should they use?

A.Active geo-replication
B.Geo-restore
C.Azure SQL Database zone-redundant configuration
D.Auto-failover groups
AnswerA

Active geo-replication is the correct answer because it continuously replicates the database asynchronously to a readable secondary in a different Azure region, offering an RPO of under 5 seconds and an RTO of less than 30 seconds when the application's connection string is manually redirected. Because failover is a manual command, there is no DNS propagation delay, making it ideal for strict RTO requirements. The secondary can also be used for read-only queries, but its main purpose is low-latency disaster recovery.

Why this answer

Active geo-replication for Azure SQL Database provides a continuous replication mechanism with an RPO of 5 seconds and an RTO of 30 seconds when using a readable secondary replica in a paired region. It replicates transactions asynchronously but with very low latency, meeting the strict RPO/RTO requirements for cross-region disaster recovery.

Exam trap

The trap here is that candidates often confuse auto-failover groups with active geo-replication, assuming the managed failover group provides faster RTO, but in reality, auto-failover groups have a longer RTO (typically 1 hour) due to DNS propagation and health probe intervals, while active geo-replication allows manual failover with sub-minute RTO.

How to eliminate wrong answers

Option B (Geo-restore) is wrong because it restores a database from geo-replicated backups with an RPO of 1 hour and an RTO of 12+ hours, far exceeding the required 5-second RPO and 30-second RTO. Option C (Azure SQL Database zone-redundant configuration) is wrong because it protects against datacenter failures within a single region, not across Azure regions, and does not provide cross-region disaster recovery. Option D (Auto-failover groups) is wrong because, while it uses active geo-replication under the hood, it adds a DNS-level routing layer that introduces additional failover latency, typically achieving an RTO of 1 hour, not the required 30 seconds.

67
MCQhard

A company ingests millions of IoT events per second from sensors around the world. Each event is a JSON message with timestamp, device ID, and readings. They need to support real-time analytics dashboards and also store all raw data for long-term historical analysis. They want to minimize operational overhead. Which Azure data storage solution should they recommend?

A.Azure Data Lake Storage Gen2 for all data.
B.Azure Event Hubs with Capture to Azure Data Lake Storage.
C.Azure Cosmos DB for both real-time and historical data.
D.Azure Time Series Insights (TSI) Standard.
AnswerB

Event Hubs can handle millions of events per second. The Capture feature automatically writes ingested events to Data Lake Storage in Avro format (or JSON). For real-time dashboards, you can use Stream Analytics to query the Event Hubs stream. This provides a seamless, low-operational-overhead solution.

Why this answer

Azure Event Hubs is designed for high-throughput data ingestion, capable of handling millions of events per second. By enabling the Capture feature, data is automatically and durably persisted to Azure Data Lake Storage in Avro format, providing a serverless, low-latency pipeline for real-time dashboards while storing raw data for long-term analytics. This minimizes operational overhead by eliminating the need to manage separate ingestion and storage infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Data Lake Storage as a complete solution for both ingestion and storage, overlooking the need for a dedicated event ingestion service like Event Hubs to handle high-throughput streaming data before persisting it to the lake.

How to eliminate wrong answers

Option A is wrong because Azure Data Lake Storage Gen2 is a scalable storage service but lacks native real-time ingestion capabilities; it would require an additional service like Event Hubs to handle the high-velocity IoT stream, adding complexity. Option C is wrong because Azure Cosmos DB is a NoSQL database optimized for low-latency reads/writes and transactional workloads, not for ingesting millions of events per second as a streaming buffer; using it for both real-time and historical data would incur high costs and operational overhead for raw event storage. Option D is wrong because Azure Time Series Insights (TSI) Standard is purpose-built for time-series data visualization and analysis, but it has limited throughput and retention compared to Event Hubs with Capture, and it is not designed to store raw JSON events for long-term historical analysis at this scale.

68
MCQeasy

You need to design a networking solution for a multi-tier application that includes a web front-end, an API layer, and a database. The web and API tiers must be accessible from the internet, while the database tier must be isolated. What is the most secure and efficient design?

A.Place all VMs in the same subnet and use a single Azure Load Balancer to distribute traffic.
B.Use separate VNets for each tier and connect them with VNet peering.
C.Deploy all VMs in a single subnet and use Azure Firewall to inspect all inbound and outbound traffic.
D.Deploy all tiers in the same VNet with separate subnets, and use NSGs to restrict traffic. Place an Azure Application Gateway with WAF in front of the web tier.
AnswerD

This architecture separates each application tier into its own subnet and applies per-subnet NSG rules to allow only required communication (e.g., web-to-app on port 443, app-to-data on port 3306), ensuring that a compromise in one tier does not implicitly expose another. An Azure Application Gateway with its WAF sits in a dedicated gateway subnet, providing the single internet-facing HTTPS endpoint, SSL offload, cookie-based session affinity, path-based routing, and OWASP Top-10 protection—all before traffic reaches the web tier. This is the recommended pattern because it balances security and operational simplicity.

Why this answer

It uses a single VNet with separate subnets for each tier, allowing Network Security Groups (NSGs) to enforce micro-segmentation and restrict traffic between tiers. The Azure Application Gateway with Web Application Firewall (WAF) provides Layer 7 protection and SSL termination for internet-facing web traffic, while the database tier remains isolated with no public endpoint. This design minimizes latency by keeping all tiers within the same VNet and avoids the complexity of VNet peering or unnecessary firewall inspection.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing separate VNets (Option B) thinking it provides better isolation, but they overlook that a single VNet with separate subnets and NSGs is simpler, lower latency, and equally secure for multi-tier applications within the same trust boundary.

How to eliminate wrong answers

Option A is wrong because placing all VMs in the same subnet with a single Azure Load Balancer provides no network isolation between tiers, exposing the database to direct access from the web and API tiers and violating the principle of least privilege. Option B is wrong because using separate VNets for each tier with VNet peering introduces unnecessary latency and administrative overhead, and peering does not inherently provide the granular traffic filtering needed between tiers; NSGs or firewalls would still be required. Option C is wrong because deploying all VMs in a single subnet with Azure Firewall to inspect all traffic creates a bottleneck and adds cost and complexity, while Azure Firewall operates at Layers 3-7 and is overkill for simple east-west traffic filtering that NSGs can handle more efficiently.

69
MCQmedium

A global e-commerce platform uses Azure Cosmos DB for its product catalog. The application requires multi-region writes to provide low-latency updates from any geographic location. Two users may update the same product item concurrently, so the solution must automatically resolve conflicts. For real-time inventory checks, reads must be strongly consistent, while product description reads can be eventually consistent. Which Cosmos DB configuration should they choose?

A.SQL API with multi-region writes, last-writer-wins conflict resolution, and per-request strong consistency
B.MongoDB API with multi-region writes and automatic conflict resolution
C.Table API with multi-region writes and strong consistency
D.Cassandra API with multi-region writes and strong consistency
AnswerA

SQL API supports multi-master writes, customizable conflict resolution, and the ability to set strong consistency on a per-request basis.

Why this answer

The SQL API in Cosmos DB supports multi-region writes with last-writer-wins (LWW) conflict resolution using a timestamp or custom property, which automatically resolves concurrent updates to the same product item. Per-request strong consistency allows inventory reads to achieve linearizability by setting the consistency level at the request level, while product description reads can use the default session or eventual consistency for performance. This combination meets all requirements: multi-region writes, automatic conflict resolution, and the ability to mix strong and eventual consistency on a per-request basis.

Exam trap

The trap here is that candidates assume all Cosmos DB APIs support multi-region writes and per-request strong consistency equally, but only the SQL API (and the Table API with specific limitations) offers the full flexibility to mix consistency levels per request, while the MongoDB, Cassandra, and Table APIs have fixed account-level consistency or lack multi-region write support entirely.

How to eliminate wrong answers

Option B is wrong because the MongoDB API in Cosmos DB does not support per-request strong consistency; it only offers a fixed set of consistency levels at the account level, and its automatic conflict resolution is limited to LWW without the flexibility to mix consistency levels per request. Option C is wrong because the Table API does not support multi-region writes; it is designed for single-region writes with read-only replicas, and it lacks per-request strong consistency. Option D is wrong because the Cassandra API does not support multi-region writes in Cosmos DB; it is limited to single-region writes, and its consistency model is based on Cassandra's tunable consistency (e.g., QUORUM) rather than Cosmos DB's per-request strong consistency.

70
MCQhard

A company is designing a hybrid storage solution to connect on-premises file shares to Azure. They need to cache frequently accessed files locally for low-latency access while storing all files in Azure. The solution must support SMB protocol and integrate with existing Windows file servers. Which Azure service should they use?

A.Azure Blob Storage with NFS 3.0 support
B.Azure Files
C.Azure File Sync
D.Azure NetApp Files
AnswerC

Azure File Sync is the correct hybrid solution because it combines an Azure file share with a local Windows Server caching tier. The sync agent replicates changes both ways, and cloud tiering ensures only hot files occupy on-premises capacity while all data remains accessible on demand. This gives the performance and compatibility of local SMB storage with the durability and scalability of Azure Files, directly addressing the requirement for cloud connectivity and local caching.

Why this answer

Azure File Sync is the correct choice because it enables caching of frequently accessed files on-premises via a sync agent installed on Windows Server, while all files are stored in Azure Files. This provides low-latency access for local users and supports SMB protocol, seamlessly integrating with existing Windows file servers through a cloud tiering feature that keeps only hot files locally.

Exam trap

The trap here is that candidates often confuse Azure Files (a cloud-only SMB share) with Azure File Sync (which adds local caching and sync capabilities), leading them to select Azure Files without recognizing the requirement for on-premises low-latency access.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with NFS 3.0 support does not natively support SMB protocol and cannot integrate with existing Windows file servers as a cached file share; it is designed for POSIX-compliant workloads. Option B is wrong because Azure Files alone provides a cloud-based SMB share but does not cache files locally on-premises; it requires direct network connectivity and does not offer local caching for low-latency access. Option D is wrong because Azure NetApp Files supports SMB but is a fully managed, high-performance file service that does not provide local caching on existing Windows file servers; it is intended for enterprise workloads requiring dedicated throughput, not hybrid caching.

71
MCQhard

Your company plans to deploy a new SaaS application that will be used by employees and external users. The application requires single sign-on (SSO) and must support conditional access policies that enforce MFA for external users. Additionally, the application must be able to read user profile attributes from Microsoft Entra ID. You need to design an identity solution that meets these requirements. What should you include in the design?

A.Register the application in Microsoft Entra ID (App Registration) and configure it to use OpenID Connect for authentication; apply conditional access policies to the app.
B.Use Azure AD Application Proxy to publish the SaaS app and configure pre-authentication with Entra ID.
C.Use Microsoft Entra Domain Services to authenticate the application via LDAP.
D.Register the application in Microsoft Entra B2C and configure federation with your Entra ID tenant.
AnswerA

Registering the SaaS app as an App Registration in Microsoft Entra ID and using OpenID Connect (OIDC) is the correct approach because OIDC is the modern, standards-based authentication protocol that Microsoft Entra ID fully supports for SSO. The app registration generates service principles, enabling Entra ID to issue ID and access tokens, which the SaaS app can validate. OIDC also exposes the application to conditional access policies in the same tenant, allowing you to enforce MFA, device compliance, and sign-in risk controls. Additionally, the Microsoft Graph API can be consented to read user profile data seamlessly, a capability not available through the alternatives.

Why this answer

Registering the application in Microsoft Entra ID (App Registration) and configuring OpenID Connect (OIDC) enables SSO and allows the application to read user profile attributes via the Microsoft Graph API. Conditional access policies can be applied directly to the enterprise app in Entra ID to enforce MFA for external users, meeting all stated requirements.

Exam trap

The trap here is that candidates may confuse Azure AD Application Proxy (for on-premises apps) or Entra B2C (for customer identities) with the correct solution for a SaaS app requiring employee and external user access with conditional access and Graph API reads.

How to eliminate wrong answers

Option B is wrong because Azure AD Application Proxy is designed for publishing on-premises apps, not SaaS applications, and does not inherently support reading user profile attributes via Graph API. Option C is wrong because Microsoft Entra Domain Services provides LDAP/Kerberos/NTLM authentication for legacy apps and does not support modern SSO protocols like OIDC or conditional access policies for SaaS apps. Option D is wrong because Microsoft Entra B2C is intended for customer-facing identity management with external identity providers, not for employee access to a SaaS app, and it does not natively support reading user profile attributes from the primary Entra ID tenant via Graph API.

72
MCQeasy

A company is designing a data storage solution for a globally distributed application that requires low-latency read access to frequently accessed data and high throughput for write operations. The data is non-relational and can be stored as key-value pairs. Which Azure service should they use?

A.Azure Table Storage
B.Azure Cosmos DB
C.Azure SQL Database
D.Azure Blob Storage
AnswerB

Azure Cosmos DB is a multi-model database that provides turnkey global distribution: any number of Azure regions can be associated with the account, and data is automatically replicated so requests are served from the nearest region. It supports key-value APIs, multiple consistency models, and offers 99.999% availability with single-digit-millisecond reads/writes at any scale—exactly what a globally distributed key-value workload needs.

Why this answer

Azure Cosmos DB is the correct choice because it is a globally distributed, multi-model database service that provides guaranteed low-latency reads (under 10 ms at the 99th percentile) and high throughput for write operations, with automatic indexing and turnkey global distribution. It natively supports key-value data models, making it ideal for non-relational, frequently accessed data requiring consistent performance across regions.

Exam trap

The trap here is that candidates often confuse Azure Table Storage as a sufficient key-value store for global scenarios, overlooking its lack of global distribution and guaranteed low-latency SLAs, which Cosmos DB uniquely provides.

How to eliminate wrong answers

Option A is wrong because Azure Table Storage is a NoSQL key-value store but lacks global distribution, automatic indexing, and guaranteed low-latency SLAs; it is designed for simpler, less demanding workloads and cannot match Cosmos DB's throughput and latency guarantees. Option C is wrong because Azure SQL Database is a relational database that requires a fixed schema and does not natively support key-value pair storage; it is optimized for structured, relational data and ACID transactions, not for high-throughput, low-latency key-value access. Option D is wrong because Azure Blob Storage is an object storage service for unstructured data (e.g., images, videos) and does not provide key-value pair semantics or the sub-10 ms read latency and high write throughput required for a globally distributed application; it is designed for bulk storage and streaming, not transactional key-value operations.

73
Multi-Selectmedium

Which TWO of the following Azure services support storing JSON documents without requiring a predefined schema? (Select two.)

Select 2 answers
A.Azure Purview
B.Azure Blob Storage
C.Azure Cosmos DB
D.Azure Analysis Services
E.Azure SQL Database
AnswersB, C

Azure Blob Storage holds unstructured data as blobs with no enforced schema, so JSON documents can be stored as-is without defining fields or types. This schema-agnostic object storage satisfies the requirement to store JSON without a predefined schema.

Why this answer

Azure Blob Storage can store JSON documents as block blobs without requiring a predefined schema, treating the JSON as opaque binary data. Azure Cosmos DB is a NoSQL database that natively supports schema-less JSON document storage. Both services allow storing JSON documents without needing to define a schema upfront.

Exam trap

The trap here is that candidates may mistakenly think Azure SQL Database's JSON support (e.g., OPENJSON, JSON_VALUE) means it can store JSON without a schema, but in reality, the JSON must be inserted into a predefined table column, so the table schema is still required.

74
MCQeasy

You need to design a storage solution for unstructured data that requires low latency (single-digit milliseconds) for frequently accessed files and must support NFS and SMB protocols. Which Azure storage solution should you recommend?

A.Azure Files
B.Azure Blob Storage
C.Azure Disk Storage
D.Azure NetApp Files
AnswerD

Azure NetApp Files delivers single-digit-millisecond latency and natively supports both NFS and SMB, satisfying the performance and protocol constraints. Azure Files and Blob storage cannot meet the sub-millisecond-class latency requirement for frequently accessed unstructured data at this tier.

Why this answer

Azure NetApp Files is a fully managed, high-performance file share service that supports both NFS (v3/v4.1) and SMB protocols natively, and is designed for low-latency (single-digit milliseconds) access to unstructured data. It provides the required protocol flexibility and performance for frequently accessed files, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse Azure Files (which supports SMB and NFS) with Azure NetApp Files, overlooking the critical performance requirement for single-digit millisecond latency that only Azure NetApp Files can consistently deliver for high-frequency access patterns.

How to eliminate wrong answers

Option A is wrong because Azure Files supports SMB and NFS (preview) but is optimized for general-purpose file sharing, not for the ultra-low latency (single-digit milliseconds) required for frequently accessed high-performance workloads. Option B is wrong because Azure Blob Storage is an object storage solution that does not natively support NFS or SMB protocols (NFS 3.0 is available via Blob NFS but with higher latency and limited SMB support). Option C is wrong because Azure Disk Storage provides block-level storage for VMs and does not support NFS or SMB protocols directly; it requires a guest OS or clustering software to share files, adding complexity and latency.

75
MCQhard

Refer to the exhibit. You run this Kusto query in Azure Monitor Logs. What does it return?

A.The number of heartbeats per computer in the last hour.
B.Computers that sent a heartbeat in the last 5 minutes.
C.Computers that have not sent a heartbeat in the last 5 minutes.
D.The average heartbeat frequency per computer.
AnswerC

This is the correct interpretation. The query first obtains each computer's latest heartbeat timestamp (typically via `summarize max(TimeGenerated) by Computer` or `arg_max`), then applies a `where` clause that retains only rows where that latest timestamp is less than `ago(5m)`. Computers that satisfy this predicate have not emitted a heartbeat in the past five minutes, so they are correctly identified as stale or offline.

Why this answer

The query uses the `Heartbeat` table and filters for heartbeats older than 5 minutes (`ago(5m)`). The `where` clause selects records where `TimeGenerated` is less than 5 minutes ago, meaning it finds heartbeats that were sent before that threshold. The `distinct Computer` then returns only computers whose most recent heartbeat is older than 5 minutes, i.e., computers that have not sent a heartbeat in the last 5 minutes.

This is a common pattern for detecting unresponsive or offline machines.

Exam trap

The trap here is that candidates misread the comparison operator: `TimeGenerated < ago(5m)` selects records older than 5 minutes (not newer), leading them to incorrectly think the query returns computers that recently sent a heartbeat.

How to eliminate wrong answers

Option A is wrong because the query does not count heartbeats per computer; it uses `distinct Computer` to return unique computer names, not an aggregation like `summarize count()`. Option B is wrong because the filter `TimeGenerated < ago(5m)` selects records older than 5 minutes, not records within the last 5 minutes; to find computers that sent a heartbeat in the last 5 minutes, the filter would be `TimeGenerated > ago(5m)`. Option D is wrong because the query does not calculate any average or frequency; it simply returns distinct computer names based on a time filter, with no aggregation or statistical function.

Page 1 of 11

Page 2

All pages