Courseiva

Microsoft Azure Solutions Architect Expert AZ-305 (AZ-305) — Questions 676–750

795 questions total · 11pages · All types, answers revealed

Page 9

Page 10 of 11

Page 11
676
MCQmedium

Your company is migrating a critical on-premises database to Azure SQL Managed Instance. The database is 500 GB and requires minimal downtime during migration. You need to choose the best migration approach. What should you recommend?

A.Use the export/import bacpac method.
B.Use Azure Data Factory to copy data.
C.Use transactional replication.
D.Use Azure Database Migration Service with online migration.
AnswerD

Azure Database Migration Service with online migration is the correct choice because it performs an initial full copy of the schema and data, then uses a continuous replication stream to keep the target synchronized with the source as transactions occur. It supports a controlled cutover where you can validate the target, stop writes on the source, and switch applications with near-zero downtime. DMS automates the heavy lifting, handles large databases like 500 GB, and is designed specifically for minimal-downtime migrations to Azure SQL, eliminating the need for manual log shipping or custom replication code.

Why this answer

Azure Database Migration Service (DMS) with online migration is the correct choice because it supports minimal downtime by continuously replicating changes from the source SQL Server to Azure SQL Managed Instance using a log-based change capture mechanism. This allows you to cut over to the target with only a brief pause, meeting the critical requirement for a 500 GB database.

Exam trap

The trap here is that candidates often confuse transactional replication (Option C) with a managed migration service, but DMS is the purpose-built Azure tool for online migrations with minimal downtime, whereas replication requires more manual configuration and is not optimized for one-time migrations.

How to eliminate wrong answers

Option A is wrong because the export/import bacpac method is an offline process that exports the database schema and data to a .bacpac file, which requires the database to be quiesced or taken offline, causing significant downtime for a 500 GB database. Option B is wrong because Azure Data Factory is designed for bulk data movement and orchestration, not for live transactional replication with minimal downtime; it would require a full copy and cannot handle ongoing changes without complex custom logic. Option C is wrong because transactional replication requires manual setup of publishers, distributors, and subscribers, and while it can provide near-real-time synchronization, it is not a managed migration service and does not handle the full schema and data migration as seamlessly as DMS, often requiring additional steps to ensure consistency.

677
MCQmedium

Fabrikam Inc. runs a file-sharing service used by 500 employees globally. The service is deployed on Azure VMs in the North Europe region. The VMs store data on Azure Files shares (Standard performance tier) mounted via SMB. The company's business continuity policy requires: - RPO: 1 hour for any data loss. - RTO: 4 hours to restore service after a regional disaster. - All data must be backed up and recoverable in a different region. - Budget is a concern; prefer cost-effective solutions. Currently, there is no backup in place. You need to design a solution. What should you do?

A.Set up Azure Site Recovery (ASR) for the VMs and Azure Files. Replicate to a secondary region (West Europe). Use ASR recovery plans to orchestrate failover.
B.Configure Azure Backup for the Azure Files shares with a backup policy of 1-hour frequency. Also back up the VMs using Azure Backup with a 1-hour policy. Store backups in a Recovery Services vault with geo-redundant storage (GRS). Enable cross-region restore.
C.Use Azure Files share snapshots taken every hour and store them in a separate storage account in the same region. For VM backup, use Azure Backup with daily frequency. In a disaster, deploy new VMs and restore from snapshots.
D.Implement Azure File Sync between the Azure Files share and an on-premises file server. For disaster recovery, failover to the on-premises server.
AnswerA

Correct. ASR replicates VMs to a secondary region with low RPO, and GRS on the Azure Files storage account provides cross-region data replication. This meets all requirements cost-effectively.

Why this answer

Azure Site Recovery (ASR) can replicate the VMs to a secondary region (West Europe), meeting the RPO (near-synchronous) and RTO (4 hours achievable). For the Azure Files data, the storage account hosting the file shares should be configured with geo-redundant storage (GRS), which automatically replicates data to a paired region, satisfying the cross-region recoverability requirement. This combination is cost-effective as it uses built-in replication without additional backup infrastructure.

Option B is incorrect because Azure Backup for Azure Files does not support a 1-hour backup frequency (minimum is 4 hours), and Azure Backup for Azure VMs also has a minimum 4-hour frequency, so it cannot meet the 1-hour RPO. Option C fails cross-region requirement as snapshots are stored in the same region, and VM backup frequency is daily. Option D requires an on-premises server and does not provide failover to a different Azure region.

Exam trap

The trap here is that candidates assume Azure Backup supports a 1-hour backup frequency for Azure Files (it does not; the minimum is 4 hours), leading them to incorrectly select Option B without considering ASR and GRS for meeting the RPO and cross-region requirement.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery (ASR) replicates VMs and Azure Files at the infrastructure level but does not provide point-in-time backup with 1-hour granularity; ASR's replication frequency is typically 5 minutes or more, and it does not natively support Azure Files replication for file shares, making it unsuitable for the RPO requirement. Option C is wrong because Azure Files share snapshots are stored in the same region and do not provide cross-region disaster recovery; additionally, VM backup with daily frequency violates the 1-hour RPO, and deploying new VMs from snapshots in the same region does not meet the 'different region' requirement. Option D is wrong because Azure File Sync syncs to an on-premises server, which does not satisfy the requirement to back up and recover data in a different Azure region; it also introduces an on-premises dependency, increasing cost and complexity, and does not meet the RPO/RTO for a regional disaster.

678
MCQeasy

You need to store billions of small JSON files (average 50 KB) that are accessed infrequently but must be available within seconds when requested. Which Azure storage solution is most cost-effective?

A.Azure SQL Database with a table storing JSON
B.Azure Files with SMB shares
C.Azure Blob Storage Cool tier
D.Azure Cosmos DB with a container for each file
AnswerC

Azure Blob Storage Cool tier is purpose-built for massive, flat namespace object storage where a single account can hold trillions of blobs. Its storage cost per GB is significantly lower than hot tier, SQL Database, or Cosmos DB, and the access latency remains low enough to serve 50 KB JSON objects on demand. While Cool tier carries a minimum retention period and early-delete fee, for infrequently accessed small files it is the most cost-effective and scalable choice among the options.

Why this answer

Azure Blob Storage Cool tier is the most cost-effective solution for storing billions of small JSON files (average 50 KB) that are infrequently accessed but require low-latency retrieval within seconds. The Cool tier offers low storage costs for data accessed less than once per month, while still providing sub-second access latency for individual blobs via HTTPS REST API, matching the 'available within seconds' requirement without the higher costs of Hot or premium tiers.

Exam trap

The trap here is that candidates often choose Azure Cosmos DB (Option D) because of its low-latency guarantees, but they overlook the massive cost difference for storing billions of small files, where Blob Storage's object storage model is far more economical for infrequently accessed data.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database is a relational database optimized for transactional queries and structured data, not for storing billions of individual small files; storing each JSON file as a row would incur high storage costs (minimum 1 MB per row for LOB data) and poor performance for file-level retrieval. Option B is wrong because Azure Files with SMB shares is designed for shared file systems with SMB protocol overhead and is not optimized for billions of small files; it incurs higher costs per GB than Blob Storage and lacks native support for efficient bulk operations on individual small objects. Option D is wrong because Azure Cosmos DB is a NoSQL database optimized for low-latency queries and real-time access with high throughput, but its cost per GB of storage is significantly higher than Blob Storage (often 10x or more), making it prohibitively expensive for storing billions of small files that are accessed infrequently.

679
MCQmedium

A company has an Azure virtual network (VNet) in the East US region hosting a web application. They need to securely connect to an on-premises data center in the same region using a dedicated, private network connection with high throughput and low latency. They also need a backup connection for redundancy in case the primary connection fails. Which connectivity solution should they implement?

A.Site-to-Site VPN only
B.ExpressRoute only
C.ExpressRoute as primary with Site-to-Site VPN as backup
D.Azure Virtual WAN with VPN
AnswerC

The optimal design is an ExpressRoute circuit as the primary path for production traffic, leveraging its dedicated private bandwidth, low latency, and Microsoft SLA. In parallel, a Site-to-Site VPN over the internet serves as a cost-effective backup that automatically takes over if the ExpressRoute circuit fails, especially when implemented with Azure VPN Gateway in active-passive mode or with BGP routing. This hybrid approach satisfies both performance requirements and continuity of connectivity without doubling cost.

Why this answer

ExpressRoute provides a dedicated, private, high-throughput, low-latency connection to Azure, ideal for the primary link. A Site-to-Site VPN over the internet serves as a cost-effective, encrypted backup path that activates if the ExpressRoute circuit fails, meeting the redundancy requirement without relying on the same physical infrastructure.

Exam trap

The trap here is that candidates often choose ExpressRoute only, forgetting that it lacks built-in redundancy and that a Site-to-Site VPN is the standard, cost-effective backup for ExpressRoute circuits in the same region.

How to eliminate wrong answers

Option A is wrong because a Site-to-Site VPN alone uses the public internet, which cannot guarantee the dedicated, high-throughput, low-latency private connection required for the primary link. Option B is wrong because ExpressRoute alone provides no automatic backup; if the circuit fails, connectivity is lost, violating the redundancy requirement. Option D is wrong because Azure Virtual WAN with VPN is a managed networking service that can aggregate multiple connections, but it does not inherently provide a dedicated private primary link with a VPN backup unless ExpressRoute is also configured; the option as stated lacks the ExpressRoute component needed for the primary connection.

680
Multi-Selectmedium

You are designing an identity lifecycle management solution for a multinational company. Employees frequently change departments, and you need to automate the assignment and removal of application access based on their current department. Which THREE Microsoft Entra features should you use?

Select 3 answers
A.Dynamic membership groups
B.Microsoft Entra Privileged Identity Management
C.Microsoft Entra access reviews
D.Microsoft Entra entitlement management
E.Microsoft Entra self-service password reset
AnswersA, C, D

Dynamic membership groups in Microsoft Entra ID automatically add and remove user accounts based on rule expressions evaluated against attributes like department, jobTitle, or country. Because membership is recalculated whenever an attribute changes or a user signs in, access to the group's linked applications is granted or revoked immediately without manual intervention. For an identity lifecycle solution centered on automating access based on organizational attributes, dynamic groups are the most direct choice.

Why this answer

Dynamic membership groups (A) are correct because they automatically add or remove users based on attribute values like 'department'. When an employee changes departments, their department attribute is updated, and the group membership is recalculated, granting or revoking access to applications assigned to that group. This is the core mechanism for automating access changes based on user attributes.

Exam trap

The trap here is confusing Privileged Identity Management (PIM) with lifecycle management—PIM handles temporary elevation for admin roles, not the ongoing assignment of application access based on user attribute changes.

681
MCQmedium

Your company runs a Windows-based application on Azure Virtual Machines in the Brazil South region. The application uses Azure Files for shared storage and Azure SQL Database (Hyperscale tier) for the database. The business requires a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 30 minutes for the entire application. The solution must be cost-effective and leverage Azure-native services. You have been asked to design the disaster recovery strategy. Which option should you recommend?

A.Use Azure Site Recovery to replicate the VMs to a secondary region. Configure geo-redundant storage (GRS) for Azure Files. For Azure SQL Database Hyperscale, enable geo-restore and test restore procedures.
B.Deploy a second set of VMs in a secondary region. Use Azure File Sync to keep Azure Files in sync. Use Azure SQL Database failover groups with a readable secondary.
C.Back up the VMs using Azure Backup with a 15-minute frequency. Use Azure File Sync to replicate Azure Files to a secondary region. Use Azure SQL Database backup with point-in-time restore.
D.Use Azure Site Recovery for VMs. Use Azure File Sync for Azure Files. Use active geo-replication for Azure SQL Database.
AnswerA

Azure Site Recovery is the correct DR service for Azure VMs because it replicates disks to a secondary region asynchronously, delivering an RPO of as little as 5 minutes (well under the 15-minute requirement) and a recoverable RTO of minutes through failover. For Azure Files, GRS replicates file share data to a paired region asynchronously with an RPO of typically less than 15 minutes, and on failover you can access the secondary endpoint. For Azure SQL Database Hyperscale, geo-restore restores the database from geo-redundant backups to the secondary region; though its RPO is typically up to 1 hour, the requirement is met because you explicitly enable and test the restore procedure, and Hyperscale does not support failover groups, making geo-restore the documented DR pattern. This combination uses native, cost-effective services rather than running duplicate infrastructure and aligns with the stated 15-minute RPO for VMs and Files.

Why this answer

Azure Site Recovery provides VM replication with RPOs as low as 15 minutes and RTOs of minutes, meeting the 15-minute RPO and 30-minute RTO. Geo-redundant storage (GRS) for Azure Files ensures data is replicated to a paired secondary region with an RPO of 15 minutes (typically), and Azure SQL Database Hyperscale’s geo-restore allows restoring from geo-replicated backups, which can achieve the required RPO/RTO when tested and automated. This combination is cost-effective as it uses native Azure services without requiring a pre-provisioned secondary environment.

Exam trap

The trap here is that candidates may assume active geo-replication or failover groups are always available for Azure SQL Database, but the Hyperscale tier does not support these features, requiring geo-restore instead.

How to eliminate wrong answers

Option B is wrong because deploying a second set of VMs in a secondary region incurs ongoing compute costs, which is not cost-effective, and Azure File Sync does not provide the 15-minute RPO for Azure Files (sync intervals are configurable but typically longer). Option C is wrong because Azure Backup with a 15-minute frequency is not supported for Azure VMs (minimum frequency is 4 hours for application-consistent backups), and point-in-time restore for Azure SQL Database does not meet the 15-minute RPO for cross-region DR. Option D is wrong because active geo-replication for Azure SQL Database is not available for the Hyperscale tier; Hyperscale uses named replicas and geo-restore instead of failover groups or active geo-replication.

682
MCQmedium

A company runs a SQL Server database on an Azure virtual machine in a single region. They need to increase storage capacity and improve I/O performance for their transaction-intensive workload. They also want to ensure high availability within the same datacenter (99.99% SLA). What should they do?

A.Use Azure Premium SSD v2 managed disks in a storage pool with mirroring across multiple disks.
B.Use Azure Ultra Disk storage attached to the VM.
C.Deploy the SQL Server on an availability set and use Storage Spaces Direct with multiple disks.
D.Enable Azure SQL Managed Instance with auto-failover groups.
AnswerC

Correct. Deploying SQL Server on an availability set ensures multiple VMs are in separate fault domains and update domains, achieving 99.99% SLA. Storage Spaces Direct pools multiple disks across VMs, providing both increased capacity and I/O performance through mirroring, while also offering data redundancy.

Why this answer

To achieve 99.99% availability within a single datacenter, you need multiple VMs in an availability set. Option C combines an availability set with Storage Spaces Direct (S2D), which uses multiple disks across VMs to provide both performance (through disk pooling) and high availability (via mirroring). This meets all requirements: increased storage capacity, improved I/O performance, and 99.99% SLA.

Option A only addresses disk performance and redundancy but fails to provide VM-level redundancy, which is necessary for the SLA.

Exam trap

Candidates often think that simply using high-performance disks (like Premium SSD v2 or Ultra Disk) is sufficient for the SLA. However, the 99.99% SLA requires multiple VMs in an availability set. Storage Spaces Direct with availability set provides both performance and HA within a datacenter.

How to eliminate wrong answers

Option B is wrong because Azure Ultra Disk storage, while offering extremely low latency and high IOPS, does not natively support mirroring or striping across multiple disks in a storage pool to increase capacity and I/O simultaneously; it is typically used as a single disk and does not provide the same aggregated performance and redundancy as a mirrored pool. Option C is wrong because Storage Spaces Direct is designed for on-premises or Azure Stack HCI scenarios, not for Azure VMs; it cannot be used with Azure managed disks and would not be supported in a standard Azure VM deployment. Option D is wrong because Azure SQL Managed Instance with auto-failover groups is a PaaS solution that moves the workload off the VM, which does not address the requirement to increase storage capacity and I/O performance for the existing SQL Server on an Azure VM, and it introduces a different architecture and SLA model.

683
MCQmedium

A company runs a critical web application on Azure VMs in the West US region. They need a disaster recovery solution that replicates the VMs to the East US region. The recovery point objective (RPO) must be 30 minutes, and the recovery time objective (RTO) must be 1 hour. The company also needs to perform quarterly disaster recovery drills without impacting the production environment. Additionally, after a failover, the solution must automatically update traffic management to route users to the East US region. Which combination of Azure services should they use?

A.Azure Site Recovery and Azure Traffic Manager
B.Azure Backup and Azure Traffic Manager
C.Azure Site Recovery and Azure Front Door
D.Azure Backup and Azure Front Door
AnswerA

Azure Site Recovery handles VM replication with the required RPO/RTO and supports non-disruptive test failovers. Azure Traffic Manager can automatically route user traffic to the secondary region after failover by using endpoint monitoring and failover priority.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs from West US to East US, meeting the 30-minute RPO and 1-hour RTO. Azure Traffic Manager automatically updates DNS-based traffic routing to the East US region after failover, ensuring users are redirected without manual intervention. This combination satisfies all requirements: DR replication, RPO/RTO, quarterly drills (via test failover), and automated traffic management.

Exam trap

A common trap is to choose Azure Front Door because of its global routing capabilities, but Azure Traffic Manager is the correct fit here. Traffic Manager integrates natively with Azure Site Recovery recovery plans, enabling automatic DNS updates after failover. While Front Door can route based on health probes, it does not integrate directly with ASR recovery plans, requiring custom automation to update backend pools post-failover.

How to eliminate wrong answers

Option B is wrong because Azure Backup is designed for long-term data retention and point-in-time restore, not for full VM replication with orchestrated failover and RPO of 30 minutes; it cannot meet the RTO of 1 hour or support automated traffic rerouting after failover. Option C is wrong because Azure Front Door is a global load balancer and application delivery controller that uses anycast and HTTP-level routing, but it does not provide automatic traffic rerouting after a Site Recovery failover without manual DNS updates; Traffic Manager is the correct service for DNS-based failover routing. Option D is wrong because it combines Azure Backup (which lacks DR orchestration) with Azure Front Door (which does not automatically update routing after failover), failing both the replication and traffic management requirements.

684
MCQmedium

A company wants to configure policies that detect risky sign-ins (e.g., from anonymous IPs or unfamiliar locations) and automatically require multi-factor authentication (MFA) when such risk is detected. Which Microsoft Entra ID feature should they use to create these policies?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management
D.Microsoft Entra ID Audit Logs
AnswerA

Conditional Access is the actual enforcement layer in Microsoft Entra ID that consumes risk signals, including sign-in risk scores generated by Identity Protection, and applies real-time policies. With conditions such as user risk or sign-in risk, it can require MFA, block access from anonymous IP addresses, or force password change. This policy-based action is exactly what is needed to 'configure policies that detect risky sign-ins' from anonymous sources.

Why this answer

Microsoft Entra ID Conditional Access is the correct feature because it allows administrators to create policies that evaluate sign-in risk signals (such as anonymous IP addresses or unfamiliar locations) and enforce access controls like requiring multi-factor authentication (MFA). Conditional Access policies can integrate with Identity Protection risk detections, but the policy itself is defined and managed within the Conditional Access blade, making it the direct tool for this requirement.

Exam trap

The trap here is that candidates often confuse Identity Protection (which detects risk) with Conditional Access (which enforces the policy), leading them to select Identity Protection as the answer when the question explicitly asks for the feature that 'creates policies' to require MFA.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection detects and reports risky sign-ins and users (e.g., via risk events like anonymous IP address or unfamiliar sign-in properties), but it does not itself enforce access controls like requiring MFA; it relies on Conditional Access policies to act on those risk detections. Option C is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not risk-based sign-in policies or MFA enforcement. Option D is wrong because Microsoft Entra ID Audit Logs provide a record of sign-in and administrative activities for monitoring and compliance, but they cannot be used to create proactive policies that detect risk and enforce MFA.

685
MCQeasy

A small business is moving its on-premises file server to Azure. The company has 50 users and stores approximately 500 GB of data, which includes documents and spreadsheets. The users need to access the files from their Windows laptops both at the office and remotely. The company wants to minimize costs while ensuring that files are always available and secure. You need to recommend a storage solution. What should you recommend?

A.Migrate the files to Azure Blob Storage and use Azure Storage Explorer for access.
B.Use Azure Stack Edge to sync the data to Azure Blob Storage.
C.Deploy Azure NetApp Files with a Standard capacity pool.
D.Deploy Azure Files with Azure File Sync and use a Windows File Server on-premises.
AnswerD

Azure Files provides fully managed SMB file shares in the cloud, and Azure File Sync replicates those shares to an on-premises Windows File Server, giving users low-latency local access while the cloud retains an authoritative copy. This hybrid setup preserves the existing server's drive-letter mappings, NTFS permissions, and AD integration, effectively 'lifting and shifting' the file server to Azure with minimal client disruption. Cloud tiering can even free local storage by keeping cool files only in Azure, while warm files stay cached on the server—ideal for a small business with modest capacity.

Why this answer

Azure Files with Azure File Sync provides a cloud-based file share that users can access via the SMB protocol from Windows laptops both on-premises and remotely, while Azure File Sync enables caching on an on-premises Windows File Server for low-latency access. This solution minimizes costs by using a standard file share tier and leverages Azure Backup for security and availability, meeting the 50-user, 500 GB requirement without over-provisioning.

Exam trap

The trap here is that candidates often choose Azure Blob Storage (Option A) because it is cheap and familiar, but they overlook the lack of native SMB file sharing support required for Windows laptop users to map drives and collaborate on documents.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage is an object storage solution that does not natively support SMB access for file sharing; users would need to use Azure Storage Explorer, which is not designed for concurrent file sharing from Windows laptops and lacks the seamless drive-mapping experience required. Option B is wrong because Azure Stack Edge is a hardware appliance designed for edge computing and data transfer to Azure, which is overkill and costly for a simple 500 GB file server migration with 50 users. Option C is wrong because Azure NetApp Files is a high-performance, enterprise-grade file service with a Standard capacity pool that is significantly more expensive than Azure Files and is typically used for latency-sensitive workloads like SAP or HPC, not for basic document and spreadsheet sharing.

686
MCQhard

A company uses Azure Firewall to secure outbound traffic from a hub virtual network. The security team reports that some traffic is bypassing the firewall because of asymmetric routing. You need to design a solution to force all outbound traffic through the firewall. What should you implement?

A.VNet peering with gateway transit
B.User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall
C.Azure Route Server
D.Azure Firewall Manager to enforce routing policies
AnswerB

A UDR with an address prefix of 0.0.0.0/0 and a next hop type of VirtualAppliance, pointing to the Azure Firewall's private IP, overrides the system default route for all outbound traffic from associated subnets. This forces all internet-bound traffic through the firewall, ensuring stateful inspection and symmetric routing for return packets. UDRs are the core mechanism for forced tunneling and centralized egress control in a hub-and-spoke architecture, making this the correct solution.

Why this answer

User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall as the next hop are the correct solution because they override the system default route and force all outbound traffic from subnets to be forwarded to the firewall, preventing asymmetric routing. Asymmetric routing occurs when traffic takes different paths to and from a destination; by ensuring the firewall is the next hop for all outbound traffic, UDRs guarantee symmetric flow through the firewall.

Exam trap

The trap here is that candidates often confuse Azure Firewall Manager's policy enforcement with actual traffic routing, but Firewall Manager does not create UDRs; it only manages firewall policies, and UDRs are still required to direct traffic to the firewall.

How to eliminate wrong answers

Option A is wrong because VNet peering with gateway transit allows traffic to flow through a VPN or ExpressRoute gateway in a peered VNet, but it does not enforce a specific next hop for outbound traffic and does not prevent asymmetric routing through Azure Firewall. Option C is wrong because Azure Route Server is used to dynamically exchange routes between network virtual appliances (NVAs) and Azure virtual networks, but it does not directly force all outbound traffic through a firewall; it facilitates BGP route propagation, which can be overridden by UDRs. Option D is wrong because Azure Firewall Manager can centralize routing policies and manage firewall policies across multiple firewalls, but it does not enforce the next hop for outbound traffic at the subnet level; UDRs are still required to direct traffic to the firewall.

687
MCQmedium

A global e-commerce company stores product catalog data in a JSON document format. The application requires low-latency reads and writes from multiple geographic regions. The solution must support multi-region writes with automatic conflict resolution and provide a guaranteed 99th percentile latency. Which Azure Cosmos DB API and consistency level should they choose?

A.SQL API with Session consistency
B.Table API with Eventual consistency
C.SQL API with Strong consistency
D.MongoDB API with Bounded staleness consistency
AnswerA

The SQL API is Cosmos DB's native JSON document data plane, making it the natural fit for product catalog records which are typically nested JSON objects with varying attributes. Session consistency is the default and most widely used consistency level because it gives each client a read-your-writes guarantee with low, predictable latency; this is exactly what an e-commerce session needs when a user updates their cart or profile. It avoids the overhead of strong consistency while preventing users from seeing inconsistent views of their own actions.

Why this answer

The SQL API with Session consistency is correct because it supports multi-region writes with automatic conflict resolution using last-writer-wins (LWW) and provides a guaranteed 99th percentile latency. Session consistency is the most widely used level for globally distributed applications, offering read-your-writes guarantees while maintaining low latency across regions.

Exam trap

The trap here is that candidates often assume Strong consistency is required for low-latency multi-region writes, but Strong consistency is incompatible with multi-region writes and would actually increase latency, while Session consistency provides the right balance of performance and guarantees.

How to eliminate wrong answers

Option B (Table API with Eventual consistency) is wrong because the Table API does not support multi-region writes; it only supports single-region writes with multi-region reads. Option C (SQL API with Strong consistency) is wrong because Strong consistency cannot be used with multi-region writes; it is only supported in single-region write configurations and would introduce high latency across regions. Option D (MongoDB API with Bounded staleness consistency) is wrong because Bounded staleness consistency, while supporting multi-region writes, does not guarantee a specific 99th percentile latency due to the configurable staleness window (k or t), which can introduce unpredictable delays.

688
Multi-Selecthard

Which THREE of the following are best practices for designing an Azure SQL Database solution for performance and scalability?

Select 3 answers
A.Use appropriate indexes to optimize query performance
B.Use elastic pools to manage multiple databases with variable workloads
C.Implement read replicas for read-heavy workloads
D.Avoid using stored procedures to reduce complexity
E.Disable automatic tuning to maintain consistent performance
AnswersA, B, C

Indexes are data structures that enable the query engine to locate rows using seek operations instead of full table scans. Appropriate indexes tailored to the workload's predicates, joins, and ordering can reduce I/O and CPU while improving response times. However, they must be balanced against write overhead and storage costs, so they should be designed rather than added indiscriminately.

Why this answer

Appropriate indexes, such as clustered and nonclustered indexes, reduce the number of data pages scanned during query execution, directly improving query performance. In Azure SQL Database, index tuning is critical for minimizing I/O and CPU overhead, especially for large tables or complex joins.

Exam trap

The trap here is that candidates may mistakenly think stored procedures add complexity or that disabling automatic tuning ensures consistency, when in fact both practices hinder scalability and performance in Azure SQL Database's managed environment.

689
MCQmedium

A company wants to cache frequently accessed session state and product data for their e-commerce website. They need the cache to be highly available with a 99.9% SLA and provide fast read and write access. The solution must be fully managed. Which Azure Cache tier should they choose?

A.Azure Redis Cache Basic tier
B.Azure Redis Cache Standard tier
C.Azure Redis Cache Premium tier
D.Azure Content Delivery Network
AnswerB

Azure Redis Cache Standard tier is a fully managed in-memory cache that runs on two replicas in the same datacenter, with automatic failover and a 99.9% SLA. For session state and frequently accessed product data, this replication provides the required high availability while keeping the architecture simple and cost-effective. It also supports standard Redis features such as expiration policies and cache-aside patterns, making it a natural fit for stateless web front ends that need a resilient shared state store.

Why this answer

The Standard tier of Azure Redis Cache provides a 99.9% SLA through built-in replication with two nodes (primary and replica) in the same region, ensuring high availability. It is fully managed, supports fast read/write access for session state and product data, and meets the requirement without the additional cost or complexity of the Premium tier.

Exam trap

The trap here is that candidates often choose the Premium tier for high availability, not realizing that the Standard tier already provides a 99.9% SLA with replication, and Premium adds features like data persistence and clustering that are not required by the question.

How to eliminate wrong answers

Option A is wrong because the Basic tier has no SLA (0% SLA) and no replication, making it unsuitable for high availability requirements. Option C is wrong because the Premium tier, while offering higher performance and features like persistence and clustering, is overkill for the stated requirements and incurs unnecessary cost; the Standard tier already meets the 99.9% SLA and fast access needs. Option D is wrong because Azure Content Delivery Network is a caching solution for static content delivery at edge locations, not a low-latency, fully managed cache for dynamic session state and product data; it does not provide the read/write semantics required for session state.

690
MCQmedium

You are designing a hybrid storage solution where on-premises applications need low-latency access to file shares hosted in Azure. The solution must cache frequently accessed files locally and sync changes bidirectionally. Which Azure feature should you use?

A.Azure File Sync
B.Azure Data Box
C.Azure NetApp Files with ExpressRoute
D.Azure Blob Storage with Azure Files migration
AnswerA

Azure File Sync is the correct choice for a hybrid storage solution that requires ongoing, bidirectional synchronization. It installs an agent on your on-premises Windows Server, creates a local cache, and continuously syncs changes both to and from an Azure file share. This gives you local performance for active files while maintaining a cloud copy for disaster recovery, multi-site replication, and backup. Its cloud tiering policy also optimizes local storage capacity by automatically moving cold files to Azure and leaving placeholders.

Why this answer

Azure File Sync is the correct choice because it enables bidirectional syncing of Azure file shares with on-premises Windows Servers, caching frequently accessed files locally for low-latency access while automatically syncing changes back to Azure. This meets the hybrid requirement of local caching and bidirectional sync without requiring full migration or dedicated network circuits.

Exam trap

The trap here is that candidates confuse Azure NetApp Files with ExpressRoute as a caching solution, but ExpressRoute only improves network latency and reliability—it does not provide local caching or bidirectional sync, which are core requirements of the scenario.

How to eliminate wrong answers

Option B is wrong because Azure Data Box is a physical data transfer device for bulk offline migration, not a continuous caching or bidirectional sync solution. Option C is wrong because Azure NetApp Files with ExpressRoute provides high-performance NFS/SMB volumes but does not include built-in bidirectional caching or sync with on-premises file servers; it requires separate replication tools. Option D is wrong because Azure Blob Storage with Azure Files migration is a one-time migration path, not a hybrid caching and sync service; Blob Storage itself does not support SMB file shares or bidirectional sync natively.

691
Multi-Selectmedium

Which TWO actions can be performed using Microsoft Entra ID Governance? (Choose two.)

Select 2 answers
A.Synchronize users from on-premises Active Directory
B.Manage access packages for internal and external users
C.Perform access reviews of group memberships
D.Configure network security group rules
E.Deploy virtual machines in Azure
AnswersB, C

Managing access packages is a flagship capability of Microsoft Entra ID Governance, delivered through Entitlement Management. It enables administrators to create catalogs of resources (groups, apps, sites), define request-and-approval workflows, set time-bound assignments, and handle automatic revocation. This feature is explicitly designed to govern access for both internal employees and external collaborators, ensuring access matches business need and is auditable.

Why this answer

Microsoft Entra ID Governance includes entitlement management, which allows administrators to create and manage access packages that bundle resources (like groups, apps, and SharePoint sites) and assign them to internal and external users. This enables automated lifecycle management of access, including expiration and renewal, making Option B correct.

Exam trap

The trap here is that candidates confuse Entra ID Governance's access review capability (Option C) with a separate feature, but both B and C are correct; the question asks for two actions, and the trap is that some might think only one of these is valid, or they might incorrectly select A because synchronization is a common identity task, but it's not a governance action.

692
MCQmedium

A media company is building a video streaming platform on Azure. The platform will store original high-definition videos and convert them to multiple resolutions for distribution. The company needs a cost-effective storage solution for the original videos, which are accessed infrequently but must be instantly available when needed. The converted videos will be served to end users globally and must be cached at edge locations for low latency. You need to design a storage and content delivery solution. What should you recommend?

A.Store original videos in Azure Blob Storage Cool tier and use Azure CDN for distribution.
B.Store original videos in Azure Blob Storage Premium tier and use Azure CDN for distribution.
C.Store original videos in Azure Blob Storage Archive tier and use Azure CDN for distribution.
D.Store original videos in Azure Files and use Azure Front Door for caching.
AnswerA

Cool tier is cost-effective for original videos that are stored but rarely accessed directly by consumers, because most playback traffic is served from Azure CDN edge caches. With CDN absorbing the majority of end-user requests, the origin store in Cool incurs negligible transaction costs while still offering immediate low-latency retrieval, unlike Archive or the premium cost of Hot. This architecture optimizes both storage spend and streaming performance.

Why this answer

Azure Blob Storage Cool tier provides low-cost storage for infrequently accessed data with instant retrieval, meeting the requirement for original videos that are rarely accessed but must be available immediately. Azure CDN caches the converted videos at edge locations globally, ensuring low-latency delivery to end users.

Exam trap

The trap here is confusing the Archive tier's low cost with instant availability, overlooking the mandatory rehydration delay, and mistaking Azure Front Door's global load balancing for a CDN caching solution.

How to eliminate wrong answers

Option B is wrong because Azure Blob Storage Premium tier is designed for high-performance, low-latency access with SSDs, which is unnecessary and cost-prohibitive for infrequently accessed original videos. Option C is wrong because Azure Blob Storage Archive tier has a retrieval latency of up to 15 hours (rehydration time), violating the requirement for instant availability. Option D is wrong because Azure Files is a managed file share for SMB/NFS protocols, not optimized for large-scale video storage or global content distribution, and Azure Front Door is a global load balancer and application accelerator, not a caching CDN for static content like video files.

693
MCQmedium

You are designing a containerized microservices application on Azure Kubernetes Service (AKS). The application must scale automatically based on HTTP traffic. You need to minimize cost by scaling down to zero pods when there is no traffic. Which scaling solution should you use?

A.Horizontal Pod Autoscaler (HPA)
B.Cluster Autoscaler
C.Kubernetes Event-driven Autoscaler (KEDA)
D.Vertical Pod Autoscaler (VPA)
AnswerC

Kubernetes Event-driven Autoscaler (KEDA) is the correct choice because it extends the Horizontal Pod Autoscaler (HPA) with event-driven triggers from HTTP requests, message queues, databases, or other external sources, allowing a microservice to scale from zero to N replicas and back down to zero when idle. KEDA installs a custom metrics API server that reports the current event stream length or request rate to the HPA, enabling fine-grained scaling that reacts to actual demand rather than only steady-state server metrics. This makes it ideal for containerized microservices that experience intermittent traffic and require cost-efficient running with no idle pods.

Why this answer

KEDA (Kubernetes Event-driven Autoscaler) is the correct choice because it can scale the number of pods in an AKS deployment down to zero when there is no HTTP traffic, and then scale up from zero when traffic resumes. Unlike the Horizontal Pod Autoscaler (HPA), which cannot scale below 1 replica by default, KEDA works with external event sources (like HTTP requests via an add-on) to achieve true zero-to-N scaling, minimizing cost during idle periods.

Exam trap

The trap here is that candidates often assume the Horizontal Pod Autoscaler (HPA) can scale to zero pods because it is the default autoscaler for Kubernetes, but HPA has a hard-coded minimum of 1 replica and cannot scale down to zero, making KEDA the only correct option for cost minimization through zero-pod scaling.

How to eliminate wrong answers

Option A is wrong because the Horizontal Pod Autoscaler (HPA) cannot scale a deployment to zero pods; it has a minimum replica count of 1 by design, as it relies on continuous metrics like CPU/memory or custom metrics that are not available when no pods exist. Option B is wrong because the Cluster Autoscaler adjusts the number of worker nodes in the AKS cluster, not the number of pods; it cannot scale pods to zero and does not respond to HTTP traffic directly. Option D is wrong because the Vertical Pod Autoscaler (VPA) adjusts CPU and memory requests/limits of existing pods, not the number of replicas, and cannot scale down to zero pods.

694
MCQeasy

A company deploys a web application on multiple Azure VMs within an availability set. They need to distribute incoming HTTP traffic evenly across the VMs and provide health probe monitoring. The solution must support SSL termination and source IP affinity (session persistence). Which Azure load balancing solution should they choose?

A.Azure Load Balancer (Basic)
B.Azure Load Balancer (Standard)
C.Azure Application Gateway v2
D.Azure Traffic Manager
AnswerC

Azure Application Gateway v2 is a regional layer-7 reverse proxy that terminates SSL/TLS at the gateway, offloading decryption from the backend VMs, and can optionally re-encrypt traffic to the origin pool. It provides cookie-based session affinity (ARRAffinity), configurable health probes, and URL/path-based routing, directly matching the need for SSL termination and persistent user sessions across multiple VMs. Its static VIPs and WebSocket support further solidify it as the correct L7 load-balancing choice in Azure.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that supports SSL termination, source IP affinity (session persistence), and health probe monitoring. It can distribute HTTP traffic evenly across VMs in an availability set while offloading SSL processing from the backend VMs.

Exam trap

The trap here is that candidates often confuse Layer 4 load balancers (Azure Load Balancer) with Layer 7 application delivery controllers (Application Gateway), assuming that SSL termination and session persistence are available in all load balancing tiers, but these features require application-layer processing only provided by Application Gateway.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer (Basic) operates at Layer 4 and does not support SSL termination or application-layer features like session persistence based on source IP. Option B is wrong because Azure Load Balancer (Standard) also operates at Layer 4 and cannot terminate SSL or provide Layer 7 routing capabilities. Option D is wrong because Azure Traffic Manager is a DNS-based global traffic routing solution that does not handle SSL termination or health probes at the application layer; it distributes traffic across endpoints based on DNS resolution, not direct HTTP traffic distribution.

695
Multi-Selectmedium

Which TWO are benefits of using Microsoft Entra ID Governance? (Choose two.)

Select 2 answers
A.Automate the deprovisioning of user accounts when an employee leaves the organization
B.Implement entitlement management for access request workflows
C.Enable just-in-time privileged access to Azure resources
D.Provide single sign-on to all SaaS applications
E.Provide VPN connectivity for remote users
AnswersA, B

Automating deprovisioning when an employee leaves is a core identity lifecycle workflow in Entra ID Governance. This workflow integrates with HR systems to trigger account and access removal in near real time, eliminating the risk of orphaned accounts and security breaches. It also generates audit logs for compliance, ensuring that departed staff cannot retain access to sensitive resources.

Why this answer

Option A is correct because Microsoft Entra ID Governance includes lifecycle workflows that automate the joiner-mover-leaver process, including automatically disabling or deleting user accounts and revoking access when an employee leaves the organization. Option B is correct because entitlement management is a core capability of Entra ID Governance, providing access packages, catalogs, and approval-based access request workflows so users can request and be granted time-bound access. Option C is not correct because just-in-time privileged access to Azure resources is delivered by Microsoft Entra Privileged Identity Management (PIM), which is a separate product from Entra ID Governance.

Option D is not correct because single sign-on to SaaS applications is a core Microsoft Entra ID feature (via SAML/OIDC enterprise applications), not a specific benefit of Entra ID Governance. Option E is not correct because VPN connectivity for remote users is provided by Azure VPN Gateway or similar networking services, not by Entra ID Governance.

Exam trap

The trap here is that candidates confuse the overlapping capabilities of Microsoft Entra ID, Entra ID Governance, and Privileged Identity Management (PIM), mistakenly attributing JIT access or SSO to governance when they belong to separate services within the Microsoft Entra portfolio.

696
MCQeasy

Your company has a large number of unstructured files (images, videos) that need to be stored cost-effectively in Azure. The data is accessed infrequently but must be available within minutes when needed. Which storage tier should you recommend?

A.Premium tier.
B.Archive tier.
C.Cool tier.
D.Hot tier.
AnswerC

The Cool tier is an online access tier intended for data that is infrequently accessed (a few times a month) but must be available immediately on demand. It offers lower storage costs and lower write/read transaction costs than Hot, allowing you to store many images economically while still supporting low-latency reads that can complete within milliseconds. Because there is no rehydration step, images are directly readable, and the 30-day minimum retention period aligns with typical lifecycle policies for images that are rarely accessed but need to be available.

Why this answer

The Cool tier is designed for data that is infrequently accessed but requires immediate availability when needed. It offers lower storage costs than the Hot tier while maintaining low-latency access (within minutes), making it ideal for unstructured files like images and videos that are accessed rarely but must be retrievable on demand.

Exam trap

The trap here is that candidates often confuse the Archive tier's low storage cost with immediate availability, overlooking the mandatory rehydration latency that violates the 'within minutes' requirement.

How to eliminate wrong answers

Option A is wrong because the Premium tier is optimized for high-performance, low-latency access (sub-millisecond) and is intended for active workloads, not cost-effective storage of infrequently accessed data. Option B is wrong because the Archive tier has the lowest storage cost but requires a rehydration process that can take up to 15 hours (Standard tier) or 1-5 hours (High Priority tier), failing the 'available within minutes' requirement. Option D is wrong because the Hot tier is designed for frequently accessed data with higher storage costs, making it unsuitable for infrequently accessed files where cost optimization is a priority.

697
MCQmedium

A media company stores large video files that are accessed once a month for audits. When needed, they must be available for download immediately (within seconds). The company wants to minimize storage costs. Which Azure Blob Storage access tier should they use?

A.Hot tier
B.Cool tier
C.Cold tier
D.Archive tier
AnswerB

Cool tier offers a low per-GB storage price with a modest per-GB retrieval fee and a 30-day minimum retention period, which aligns perfectly with monthly access. Retrieval is immediate because objects remain in the online tier, so the media company can read or stream the video without waiting for rehydration. For large files read once per month, Cool delivers the lowest total cost among tiers that still provide on-demand access, making it the correct choice.

Why this answer

The Cool tier is optimal for this scenario because it balances low storage cost with high availability and low latency access. Video files accessed once a month for audits require immediate download (within seconds), which Cool tier supports with the same millisecond latency as Hot tier, but at a lower storage price. Archive tier would introduce a multi-hour rehydration delay, making it unsuitable for on-demand access within seconds.

Exam trap

The trap here is that candidates often choose Archive tier for infrequent access without realizing that the multi-hour rehydration latency makes it impossible to meet the 'within seconds' availability requirement, or they choose Hot tier out of habit for any access speed requirement, ignoring the cost-minimization goal.

How to eliminate wrong answers

Option A (Hot tier) is wrong because it has the highest storage cost, which contradicts the goal of minimizing storage costs for infrequently accessed data. Option C (Cold tier) is wrong because although it offers lower storage cost than Cool, it has a higher minimum storage duration (90 days vs 30 days) and a higher early deletion fee, making it more expensive for data accessed only once a month. Option D (Archive tier) is wrong because it requires a rehydration process that takes up to 15 hours, making it impossible to provide download within seconds on demand.

698
MCQeasy

Your company uses Azure Backup to protect on-premises file servers and Azure VMs. The compliance team requires that backup data be stored in a secondary region to protect against regional disasters. Which Azure Backup feature should you enable?

A.Enable geo-redundant storage (GRS) for the Recovery Services vault
B.Use Azure Site Recovery to replicate the backup data
C.Configure backup policies to back up directly to the secondary region
D.Use a Recovery Services vault in the secondary region
AnswerA

Enabling geo-redundant storage (GRS) on the Recovery Services vault is the correct way to protect on-premises file backups against a regional disaster. GRS asynchronously replicates the vault's backup data to a paired Azure region, ensuring a second copy exists beyond the primary region's failure boundary. This replication is the built-in mechanism for making backup data resilient without requiring separate infrastructure or failover processes.

Why this answer

Azure Backup uses the Recovery Services vault as its management and storage container. By enabling geo-redundant storage (GRS) on the vault, backup data is automatically replicated to a paired secondary Azure region, meeting the compliance requirement for off-site disaster recovery without any additional configuration or separate vault.

Exam trap

The trap here is that candidates confuse Azure Site Recovery (which replicates workloads for failover) with Azure Backup's storage redundancy feature (which replicates backup data for durability), or they incorrectly assume that creating a vault in the secondary region alone provides cross-region backup storage.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery is a disaster recovery service for replicating and failing over workloads, not a feature for storing backup data in a secondary region. Option C is wrong because Azure Backup does not support direct backup to a secondary region; backup data is always written to the vault's primary region, and cross-region replication is handled by the vault's storage redundancy setting. Option D is wrong because simply creating a Recovery Services vault in the secondary region does not automatically replicate backup data from the primary region; you would need to manually configure backup policies to target that vault, which is not a built-in feature for cross-region backup storage.

699
MCQeasy

Your company uses Azure SQL Database and needs to retain backups for 7 years for compliance. Which backup retention policy should you configure?

A.Increase automated backup retention to 7 years.
B.Configure point-in-time restore backup retention for 7 years.
C.Enable geo-redundant backups.
D.Configure long-term retention (LTR) backup policy.
AnswerD

Configuring a long-term retention (LTR) backup policy is the correct approach for retaining backups beyond 35 days. LTR allows you to define separate retention periods for weekly, monthly, and yearly full backups, with a maximum retention of 10 years. These backups are stored in Azure Blob storage (geo-redundant by default) and are independent of automated backup and PITR retention limits. For a 7-year retention requirement, you can specify a yearly LTR policy with a 7-year retention period.

Why this answer

Azure SQL Database's automated backup retention is limited to a maximum of 35 days, which is insufficient for a 7-year compliance requirement. Long-term retention (LTR) allows you to retain full database backups for up to 10 years by storing them in separate Azure Blob Storage containers. Therefore, configuring an LTR backup policy is the correct solution for meeting a 7-year retention mandate.

Exam trap

The trap here is that candidates often confuse the maximum retention for automated backups (35 days) with the ability to extend it arbitrarily, or they mistakenly think point-in-time restore retention can be configured for years, when in reality only long-term retention (LTR) supports multi-year archival.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database automated backup retention has a maximum of 35 days, not 7 years; you cannot increase it beyond that limit. Option B is wrong because point-in-time restore (PITR) backup retention is also capped at 35 days and is designed for short-term recovery, not long-term archival compliance. Option C is wrong because enabling geo-redundant backups (e.g., geo-redundant storage) provides disaster recovery protection by replicating backups to a paired region, but it does not extend the retention period beyond the default 35 days.

700
MCQmedium

Your company has a global application deployed across multiple Azure regions. You need to design a disaster recovery solution that meets a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The solution should use Azure-native services and minimize costs. Which option should you choose?

A.Azure Traffic Manager with priority routing
B.Azure Site Recovery with 15-minute replication
C.Active geo-replication for Azure SQL Database
D.Azure Backup with cross-region restore
AnswerB

Azure Site Recovery continuously replicates your Azure VMs (or Hyper-V/VMware workloads) to a secondary region and can create application-consistent recovery points at a frequency as low as 15 minutes, giving a tightly bounded RPO. It also provides orchestrated failover, failback, and non-disruptive disaster-recovery drills, so the whole multi-tier application can be recovered in the paired region within minutes.

Why this answer

Azure Site Recovery (ASR) with 15-minute replication is the correct choice because it provides application-consistent replication for Azure VMs with a configurable RPO as low as 15 minutes and supports failover within the 1-hour RTO. ASR is an Azure-native disaster recovery service that orchestrates replication, failover, and failback across regions, making it the most cost-effective option for meeting the stated RPO and RTO requirements for a multi-region application.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery with Azure Backup, assuming both are suitable for DR, but Azure Backup is optimized for archival and long-term retention with higher RPO/RTO, while ASR is purpose-built for low-RPO/RTO disaster recovery scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager with priority routing is a DNS-level traffic load balancer that does not provide replication or failover of application data; it only redirects traffic based on endpoint health, so it cannot meet the RPO/RTO for data recovery. Option C is wrong because active geo-replication for Azure SQL Database offers an RPO of 5 seconds and RTO of 1 hour, but it is specific to Azure SQL Database and does not cover the entire application stack (e.g., VMs, app tiers), and it is more expensive than ASR for a full application DR solution. Option D is wrong because Azure Backup with cross-region restore is designed for long-term backup retention and has an RPO of typically 24 hours (or more) and an RTO that can exceed several hours, making it unsuitable for the 15-minute RPO and 1-hour RTO requirements.

701
MCQmedium

Your company is migrating a legacy on-premises application to Azure. The application requires low-latency access to a shared file system that supports SMB protocol. The solution must be highly available within a single Azure region and must not require the application to be modified. Which Azure service should you recommend?

A.Azure Managed Disks (SSD)
B.Azure NetApp Files
C.Azure Files (premium tier)
D.Azure Blob Storage
AnswerC

Azure Files is the correct choice because it provides fully managed SMB 3.0 file shares that expose a familiar UNC path (\\storageaccount.file.core.windows.net\share) without requiring application code changes. The premium tier uses SSD hardware to guarantee sub-millisecond latency for IOPS-intensive or latency-sensitive workloads, and it supports SMB Multichannel, AD integration, and Azure File Sync caching. Since it is a true file share service, multiple VMs can connect concurrently, allowing the legacy on-premises app to be re-pointed at the cloud share exactly as it would use any Windows file server.

Why this answer

Azure Files (premium tier) provides fully managed SMB file shares with low-latency access, high availability within a single Azure region, and supports the SMB protocol natively without requiring any application modifications. This makes it the ideal choice for migrating legacy on-premises applications that rely on SMB-based file sharing.

Exam trap

The trap here is that candidates often confuse Azure NetApp Files (a third-party service) with Azure Files, or assume that Azure Blob Storage can be used as a file share via SMB without modifications, overlooking the native SMB support and low-latency guarantees of Azure Files premium tier.

How to eliminate wrong answers

Option A is wrong because Azure Managed Disks (SSD) provide block-level storage for virtual machines, not a shared file system accessible via SMB protocol, and they require application modifications to use. Option B is wrong because Azure NetApp Files offers high-performance NFS and SMB volumes but is a third-party service (NetApp) that introduces additional complexity and cost, and while it supports SMB, it is not the simplest or most cost-effective fully managed Azure-native solution for this requirement. Option D is wrong because Azure Blob Storage is an object storage service that does not support the SMB protocol natively; it requires application modifications or additional components (like Azure File Sync) to present as a file share, and it is not designed for low-latency SMB access.

702
Multi-Selecthard

Which THREE conditions should be met to implement a successful Azure landing zone for a new enterprise subscription? (Choose three.)

Select 3 answers
A.A dedicated Azure Active Directory tenant.
B.A management group hierarchy that separates environments.
C.Microsoft Sentinel enabled for security monitoring.
D.A defined network topology with connectivity to on-premises.
E.A subscription vending process to automate creation.
AnswersB, D, E

Management groups form the backbone of governance in a landing zone by enabling role assignments and Azure Policy to be inherited down to the subscription level. Separating environments (such as production, non-production, and shared) into distinct hierarchy branches allows cloud admins to enforce different compliance and cost controls per environment. This hierarchy is a prerequisite in the Azure landing zone accelerator because it provides the structural placement point for policy and RBAC.

Why this answer

A management group hierarchy that separates environments (e.g., production, non-production, and management) is a core design principle of an Azure landing zone. It enables policy inheritance, role-based access control (RBAC) isolation, and cost tracking across different workloads, aligning with the Cloud Adoption Framework's governance best practices.

Exam trap

The trap here is that candidates often confuse optional security tools like Microsoft Sentinel or dedicated tenants as mandatory prerequisites, when the Azure landing zone's success hinges on governance structure (management groups), network connectivity (hub-spoke topology), and automation (subscription vending).

703
MCQeasy

Your company deploys a line-of-business application on Azure App Service. The application requires custom domain names and SSL/TLS certificates. You need to ensure that the application can be accessed via a custom domain with HTTPS. What should you configure in the App Service?

A.Add the custom domain and bind the SSL/TLS certificate.
B.Configure IP restrictions to allow only the custom domain.
C.Create a deployment slot for production traffic.
D.Scale out the App Service plan to increase instance count.
AnswerA

Azure App Service web apps require a custom domain to be mapped to the app's default hostname (e.g., appname.azurewebsites.net) before users can reach it via a domain they own. Binding an SSL/TLS certificate (whether App Service Managed Certificate, Key Vault, or a custom PFX) then enables HTTPS for that domain, fulfilling the need for secure access over the company's domain. Without both steps, the app stays on the azurewebsites.net hostname with only the default wildcard certificate, so the custom domain remains inaccessible over HTTPS.

Why this answer

To access an App Service via a custom domain with HTTPS, you must first add the custom domain to the App Service and then bind an SSL/TLS certificate (either App Service Managed Certificate, a Key Vault certificate, or a third-party certificate) to that domain. This binding enables the App Service to present the certificate during the TLS handshake, allowing secure HTTPS connections. Without both steps, the custom domain will not resolve securely.

Exam trap

The trap here is that candidates may confuse IP restrictions (which filter traffic) or deployment slots (which manage releases) with the necessary steps for custom domain and certificate binding, leading them to overlook the direct requirement of adding the domain and binding the certificate.

How to eliminate wrong answers

Option B is wrong because IP restrictions control which source IP addresses can access the app, not which domain names are allowed; they do not enable custom domain HTTPS access. Option C is wrong because deployment slots are used for staging and swapping traffic between environments, not for configuring custom domains or SSL/TLS bindings. Option D is wrong because scaling out increases the number of instances for performance and availability, but has no effect on custom domain or certificate configuration.

704
MCQhard

You need to design a network topology for a global e-commerce platform on Azure. The solution must provide low-latency access to static content and protect the backend APIs from DDoS attacks. The backend APIs are deployed in multiple regions behind an internal load balancer. Which services should you use?

A.Azure Traffic Manager and Azure Firewall.
B.Azure Content Delivery Network (CDN) and Azure Load Balancer.
C.Azure Application Gateway with WAF and Azure API Management.
D.Azure Front Door with WAF and Azure API Management.
AnswerD

Azure Front Door with WAF provides a single global entry point via anycast and split TCP, performing Layer 7 routing, SSL termination, path-based matching, and edge WAF policies that can inspect every request before it reaches the API origin. Azure API Management then acts as the API gateway, publishing APIs, applying subscription keys, validating JWT/OAuth tokens, rate-limiting and quotaing consumers, and enabling versioning/transformation policies. Together they satisfy the e-commerce platform's need for global availability, DDoS and WAF protection, and secure API control, while keeping backend origins scalable and stable.

Why this answer

Azure Front Door with WAF provides global load balancing and low-latency access to static content via its anycast-based routing, while the integrated Web Application Firewall (WAF) protects backend APIs from DDoS and application-layer attacks. Azure API Management secures and manages the backend APIs, offering policies for throttling, authentication, and transformation. This combination meets the requirements for global low-latency content delivery and DDoS protection for multi-region backend APIs.

Exam trap

The trap here is that candidates often confuse Azure Application Gateway (regional, Layer 7) with Azure Front Door (global, anycast), and overlook that only Front Door provides global low-latency access and edge DDoS protection for multi-region deployments.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager is a DNS-based load balancer that does not provide low-latency static content delivery or integrated DDoS protection, and Azure Firewall is a stateful network firewall that lacks application-layer WAF capabilities for API protection. Option B is wrong because Azure CDN delivers static content but does not protect backend APIs from DDoS attacks, and Azure Load Balancer operates at Layer 4 (TCP/UDP) without WAF or application-layer security. Option C is wrong because Azure Application Gateway with WAF is a regional service that cannot provide global low-latency access or multi-region load balancing, and Azure API Management alone does not offer global DDoS protection or anycast-based routing.

705
MCQmedium

A company has headquarters and multiple branch offices worldwide, each with its own on-premises network. They want to connect all these sites to Azure and to each other over a single, centrally managed solution. They need high bandwidth connectivity for site-to-site traffic, support for both VPN and ExpressRoute connections, and automatic routing management without the complexity of configuring multiple VPN tunnels or BGP manually. Which Azure service should they use?

A.Azure Virtual WAN
B.Azure VPN Gateway (site-to-site) with BGP
C.Azure ExpressRoute with Microsoft peering
D.Azure Virtual Network peering
AnswerA

Azure Virtual WAN is a Microsoft-managed global transit architecture that uses a hub-and-spoke topology to connect branch offices to Azure and to each other. It automatically establishes routing tables, supports multiple connection types (S2S VPN, ExpressRoute, point-to-site, VNet), and propagates routes across the hubs so traffic between any pair of on-premises sites flows over the Microsoft backbone. This built-in transitive connectivity and centralized management is exactly what a worldwide branch network requires, making it the ideal choice.

Why this answer

Azure Virtual WAN is the correct choice because it provides a single, centrally managed hub-and-spoke architecture that connects branch offices, headquarters, and Azure over a unified network. It supports both VPN and ExpressRoute connections, automatically manages routing (including BGP) without manual configuration of multiple tunnels, and offers high bandwidth for site-to-site traffic.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN with a simple VPN gateway or ExpressRoute, not realizing that Virtual WAN is a managed overlay that combines both connectivity types with automatic routing, while the other options require manual configuration for multi-site scenarios.

How to eliminate wrong answers

Option B is wrong because Azure VPN Gateway (site-to-site) with BGP requires manual configuration of multiple VPN tunnels and BGP peering for each branch, lacking the centralized management and automatic routing that Virtual WAN provides. Option C is wrong because Azure ExpressRoute with Microsoft peering only provides private connectivity to Azure, not site-to-site connectivity between branch offices, and does not include VPN support or automatic routing management across multiple sites. Option D is wrong because Azure Virtual Network peering connects only Azure virtual networks, not on-premises networks, and cannot provide site-to-site connectivity between branch offices or support VPN/ExpressRoute connections.

706
MCQhard

A company is planning to migrate a legacy application to Azure VMs. The application requires a static IP address for licensing purposes. The VM must be highly available within a single region. Which combination of Azure resources should they use?

A.Application Gateway with a static frontend IP and virtual machine scale set
B.Standard Load Balancer with a static frontend IP and availability set
C.Basic Load Balancer with a static frontend IP and availability zone
D.Azure Front Door with a static backend IP and VM in an availability zone
AnswerB

The Standard Load Balancer is a Layer-4 (TCP/UDP) service that supports a static frontend IP address and can route traffic to a backend pool of VMs deployed within an availability set. An availability set spreads virtual machines across multiple fault domains and update domains, ensuring that a hardware failure or planned maintenance does not take down all instances at once. This configuration directly matches common legacy migration requirements: a fixed IP for client whitelisting and resilient handling of raw TCP/UDP sessions.

Why this answer

A Standard Load Balancer with a static frontend IP provides a fixed IP address for licensing, and an availability set ensures high availability by distributing VMs across fault and update domains within a single region. This combination meets the requirement for a static IP and regional HA without needing scale-out or global routing.

Exam trap

The trap here is that candidates often confuse availability zones with availability sets, assuming zones provide better HA, but for a single-region legacy app with a static IP, an availability set is the correct choice because it offers fault domain redundancy without the complexity of multi-zone deployment.

How to eliminate wrong answers

Option A is wrong because an Application Gateway is a Layer 7 load balancer with SSL termination and URL routing, which is unnecessary for a simple static IP requirement; a VM scale set implies auto-scaling, which is not required for a single legacy application. Option C is wrong because a Basic Load Balancer does not support availability zones, and using an availability zone would place the VM in a single zone, not providing high availability across the region. Option D is wrong because Azure Front Door is a global load balancer with a static backend IP, but it requires a public backend IP and is designed for multi-region scenarios, not single-region HA; an availability zone alone does not provide fault domain redundancy like an availability set.

707
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID) and Microsoft Intune. They want to block all access to internal corporate applications from devices that are not enrolled in Intune and do not meet the company's compliance policies. The solution must apply to all cloud app access seamlessly. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management
D.Microsoft Entra ID Access Reviews
AnswerA

Microsoft Entra ID Conditional Access is the correct tool because it evaluates signal-rich policies at every authentication event, including the user's device state, to enforce access decisions. Administrators can create a policy that requires the device to be marked as compliant by Intune or to be hybrid Azure AD joined, blocking sign-ins from non-compliant devices and integrating directly with device compliance signals.

Why this answer

Microsoft Entra ID Conditional Access is the correct feature because it enables you to create policies that evaluate device compliance and enrollment status before granting access to cloud applications. By configuring a Conditional Access policy with a condition requiring devices to be marked as compliant and enrolled in Intune, you can block access from non-compliant or unenrolled devices seamlessly across all integrated cloud apps.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles risk-based conditional access) with Conditional Access (which handles broader policy conditions like device compliance), leading them to select Identity Protection when the question explicitly requires device enrollment and compliance enforcement.

How to eliminate wrong answers

Option B (Microsoft Entra ID Identity Protection) is wrong because it focuses on detecting and responding to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) rather than enforcing device compliance or enrollment requirements. Option C (Microsoft Entra ID Privileged Identity Management) is wrong because it manages just-in-time privileged role assignments and access reviews for administrative roles, not device-level access controls for all users. Option D (Microsoft Entra ID Access Reviews) is wrong because it automates periodic attestation of group memberships or application access, but does not enforce real-time device compliance checks at the point of authentication.

708
MCQeasy

A company needs to store millions of small JSON files (average 10 KB each) for a serverless application. The data must be accessed via HTTPS and support high read throughput. Which Azure storage solution is most cost-effective?

A.Azure Blob Storage (general-purpose v2, hot tier)
B.Azure Files (standard)
C.Azure Cosmos DB
D.Azure Table Storage
AnswerA

Azure Blob Storage (general-purpose v2) is purpose-built for storing massive numbers of small, unstructured objects like JSON files. It exposes a REST API over HTTPS, allows per-blob metadata and tags, and supports hot/cool/archive lifecycle management. The hot tier optimizes for frequent reads, making it both cost-effective and highly scalable for millions of entries.

Why this answer

Azure Blob Storage (general-purpose v2, hot tier) is the most cost-effective solution because it provides native HTTPS access, high throughput for read-heavy workloads, and low-cost storage for small objects like JSON files. The hot tier optimizes for frequent access, and GPv2 accounts support the high request rates needed for millions of small files without premium pricing.

Exam trap

The trap here is that candidates often choose Azure Cosmos DB for JSON files due to its native JSON support, but they overlook the cost inefficiency of using a transactional database for static file storage, where blob storage provides the same HTTPS access at a fraction of the cost.

How to eliminate wrong answers

Option B (Azure Files) is wrong because it is designed for SMB/NFS file shares with mounted drives, not for direct HTTPS access to individual small objects, and its cost per GB is higher than blob storage for this use case. Option C (Azure Cosmos DB) is wrong because it is a NoSQL database optimized for transactional workloads with low-latency queries, not for bulk storage of static JSON files, and its RU-based pricing would be prohibitively expensive for millions of small files with high read throughput. Option D (Azure Table Storage) is wrong because it is a NoSQL key-value store for structured data with partition key limitations, not designed for storing raw JSON files as blobs, and its throughput is constrained by partition scalability.

709
Drag & Dropmedium

Drag and drop the steps to set up Azure Key Vault for storing secrets and access them from an Azure function into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for setting up Azure Key Vault with an Azure function begins with creating the vault, then adding the secret. Next, grant the function app's managed identity access to the vault (using an access policy). After that, configure app settings or references in the function app to point to the secret.

Finally, test the function to ensure it can retrieve the secret successfully. Common mistakes include misordering the grant access and configure references steps, or attempting to add secrets or configure references before the vault exists.

710
MCQhard

A healthcare organization is deploying a new application on Azure that will handle Protected Health Information (PHI). The application must be compliant with HIPAA. The security team requires encryption at rest and in transit, and the ability to audit access to the data. The solution should minimize administrative overhead. Which storage solution should you recommend?

A.Azure SQL Database with Transparent Data Encryption and Always Encrypted
B.Azure Cosmos DB with encryption at rest
C.Azure SQL Managed Instance with customer-managed keys
D.SQL Server on Azure Virtual Machine with BitLocker
AnswerA

Azure SQL Database is a managed PaaS offering that automatically handles high availability, backups, and patching while providing built-in Transparent Data Encryption (TDE) for at-rest encryption and Always Encrypted to protect sensitive columns in transit and client-side. Always Encrypted ensures encryption keys are never exposed to the database engine, adding a strong separation-of-duties layer, and the service natively supports auditing for compliance.

Why this answer

Azure SQL Database provides encryption at rest via Transparent Data Encryption (TDE), which is enabled by default, and encryption in transit via TLS. It also supports Always Encrypted to protect sensitive data client-side, ensuring PHI is never exposed to database administrators. Built-in auditing tracks access, and as a PaaS service, it minimizes administrative overhead compared to SQL Managed Instance or IaaS.

Exam trap

Candidates may choose Azure SQL Managed Instance with customer-managed keys (Option C) thinking it is more HIPAA-compliant, but customer-managed keys increase administrative overhead. Azure SQL Database with service-managed keys is equally HIPAA-compliant and simpler to manage, while still supporting TDE and Always Encrypted.

How to eliminate wrong answers

Option B is wrong because Azure Cosmos DB with encryption at rest only provides encryption at rest, not encryption in transit with the granularity needed for PHI compliance, and lacks built-in auditing capabilities for access to specific data items. Option C is wrong because Azure SQL Managed Instance with customer-managed keys adds administrative overhead for key management (e.g., using Azure Key Vault) and does not inherently provide encryption in transit via Always Encrypted, which is required for HIPAA. Option D is wrong because SQL Server on Azure Virtual Machine with BitLocker requires manual configuration for encryption in transit (e.g., SSL/TLS), adds significant administrative overhead for patching and backups, and does not offer the same level of integrated auditing as Azure SQL Database.

711
Multi-Selectmedium

A company is designing a governance solution for a large Azure environment with multiple subscriptions. They need to ensure that all resources are deployed only in approved Azure regions and that all resources have a specific tag 'CostCenter'. They also need to be able to delegate management of policies to individual business units while maintaining central control. Which two features should be included in the design? (Choose two.)

Select 2 answers
A.Management groups to organize subscriptions and apply policies hierarchically.
B.Role-based access control (RBAC) assignments to restrict who can create resources in certain regions.
C.Azure Blueprints to define and assign policies across subscriptions.
D.Azure Resource Manager templates to enforce tagging and region constraints at deployment time.
E.Azure Policy with a deny effect for allowed locations and a deny effect for required tags.
AnswersA, E

Management groups allow hierarchical organization of subscriptions and inheritance of policies and role assignments. By assigning policies at a management group, all subscriptions inherit them. This provides central control while allowing delegation to business units through separate management groups with their own policies.

Why this answer

Azure Policy with deny effects enforces that resources can only be created in approved regions and must have the required tag. Management groups provide a hierarchical structure to apply these policies across subscriptions and allow delegation to business units while maintaining central oversight. Together, they deliver scalable governance with central control and delegated administration.

Exam trap

The trap here is assuming that RBAC or ARM templates can enforce resource properties like location and tags, when they only control permissions or deployment-time settings, not ongoing compliance.

712
MCQmedium

A company runs a SQL Server database on an Azure VM in West Europe. They need to back up the database daily and retain backups for 7 years for compliance. They also require the ability to restore the database to a secondary Azure region (North Europe) if the primary region fails. They want to minimize operational overhead and costs. Which Azure Backup configuration should they use?

A.A
B.B
C.C
D.D
AnswerA

Azure Backup for SQL Server in an Azure VM securely stores full, differential, and transaction log backups in a Recovery Services vault. You can configure the vault in West Europe as the primary region and enable the Cross-Region Restore (CRR) feature, which replicates the backup data to the paired North Europe region using geo-redundant storage (GRS). This design provides automated SQL-aware backup management, point-in-time restore capability, and the ability to restore databases in North Europe without deploying any additional backup infrastructure or vaults, making it the optimized, cost-effective approach.

Why this answer

Azure Backup's built-in cross-region restore (CRR) for Azure VMs allows you to restore SQL Server databases hosted on Azure VMs to a paired secondary region (North Europe) in the event of a disaster, while retaining backups for up to 10 years (covering the 7-year compliance requirement). This configuration minimizes operational overhead by using Azure Backup's native policy-based scheduling and storage management, and it is cost-effective as it uses geo-redundant storage (GRS) for the Recovery Services vault without needing a separate backup infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (ASR) with Azure Backup, thinking ASR can handle long-term backup retention, when in fact ASR is for replication and failover, not for point-in-time restores with multi-year retention, and they may overlook the need to explicitly enable cross-region restore (CRR) on the Recovery Services vault to meet the secondary region recovery requirement.

How to eliminate wrong answers

Option B is wrong because it suggests using Azure Site Recovery (ASR) for database backup, but ASR is designed for replication and failover of entire VMs, not for point-in-time database restore with long-term retention; it also incurs higher costs for continuous replication and does not natively support 7-year backup retention. Option C is wrong because it proposes backing up the SQL Server database to Azure Blob Storage using manual scripts or third-party tools, which increases operational overhead and does not integrate with Azure Backup's native cross-region restore or long-term retention policies. Option D is wrong because it recommends using Azure Backup for SQL Server on Azure VM but without enabling cross-region restore (CRR), which means backups are stored only in the primary region (West Europe) and cannot be restored to North Europe if the primary region fails, failing the disaster recovery requirement.

713
Matchingmedium

Match each Azure service to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

DNS-based traffic routing

Global HTTP(S) load balancing with WAF

Regional layer-7 load balancer with WAF

Regional layer-4 load balancer

Site-to-site VPN connectivity

Why these pairings

Correct matches: Azure Virtual Network provides private connectivity; Azure Load Balancer distributes traffic. Common confusions mix layer-4 and layer-7 services, and regional vs. global routing.

714
MCQeasy

A company runs a critical Azure SQL Database in the West US region. They need a disaster recovery solution that automatically fails over to a secondary region (East US) with a recovery point objective (RPO) of 5 seconds and a recovery time objective (RTO) of less than 1 hour. Additionally, they want to offload read-only workloads to the secondary database during normal operations. Which Azure SQL Database feature should they enable?

A.Active geo-replication with failover groups
B.Point-in-time restore
C.Long-term backup retention
D.Always On availability groups (self-managed)
AnswerA

Failover groups provide automatic failover to a readable secondary database. Active geo-replication synchronizes data with an RPO of 5 seconds and supports readable secondaries. The failover group ensures automatic failover with an RTO of typically less than 1 hour.

Why this answer

Active geo-replication with failover groups is the correct choice because it provides automatic, asynchronous replication of an Azure SQL Database to a secondary region (East US) with an RPO of up to 5 seconds and an RTO of less than 1 hour. Additionally, it supports readable secondary replicas, allowing read-only workloads to be offloaded to the secondary database during normal operations, meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse active geo-replication with failover groups (which supports readable secondaries and automatic failover) with standard active geo-replication (which requires manual failover and does not provide a single endpoint), or they mistakenly think Always On availability groups applies to Azure SQL Database instead of SQL Server on VMs.

How to eliminate wrong answers

Option B is wrong because point-in-time restore (PITR) only recovers the database to a specific point in time within the same region (retention up to 35 days) and does not provide cross-region failover or a readable secondary for offloading read workloads. Option C is wrong because long-term backup retention (LTR) stores backups for up to 10 years for compliance, but it does not enable automatic failover to a secondary region or support readable secondaries for read offloading. Option D is wrong because Always On availability groups (self-managed) is a feature for SQL Server on Azure Virtual Machines, not for Azure SQL Database managed service, and it requires manual configuration and management, not automatic failover with the specified RPO/RTO.

715
MCQmedium

A company wants to deploy containerized microservices on Azure without managing virtual machines. The solution must support automatic scaling based on demand, built-in load balancing, rolling updates for zero-downtime deployments, and a fully managed platform. Which Azure compute service should they choose?

A.Azure Container Apps
B.Azure Container Instances
C.Azure Batch
D.Azure Functions
AnswerA

Azure Container Apps is a serverless platform for running containers. It provides automatic scaling based on HTTP traffic or events, built-in load balancing, and supports rolling updates via revisions. It abstracts away underlying infrastructure, so no VMs to manage.

Why this answer

Azure Container Apps is the correct choice because it provides a fully managed, serverless platform for running containerized microservices without managing virtual machines. It supports automatic scaling based on HTTP traffic or events, built-in load balancing via Envoy, and rolling updates with revision management to ensure zero-downtime deployments. This aligns perfectly with the requirement for a fully managed platform that abstracts away infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Container Instances (ACI) with a managed orchestration solution, but ACI lacks the automatic scaling, load balancing, and rolling update capabilities that Container Apps provides for microservices.

How to eliminate wrong answers

Option B (Azure Container Instances) is wrong because it is designed for running individual containers on demand without built-in orchestration, automatic scaling, or rolling update capabilities—it lacks the microservice management features required. Option C (Azure Batch) is wrong because it is a job-scheduling service for high-performance computing (HPC) and parallel workloads, not for deploying containerized microservices with load balancing and rolling updates. Option D (Azure Functions) is wrong because it is a serverless compute service for event-driven code (functions), not for running containerized microservices; it does not support container orchestration or rolling updates for containers.

716
Multi-Selectmedium

Your company uses Microsoft Entra ID for identity management. You need to design a monitoring solution for sign-in logs to detect suspicious activity. Which TWO Azure services should you include in the design?

Select 2 answers
A.Azure Monitor
B.Microsoft Defender for Cloud Apps
C.Microsoft Sentinel
D.Microsoft Purview
E.Log Analytics workspace
AnswersB, C

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that uses behavioral analytics and UEBA to profile each user's normal sign-in patterns. It can detect impossible-travel behavior, sign-ins from anonymous or risky IPs, and atypical locations or applications, then trigger alerts or conditional access policies based on the calculated risk. Because it is natively integrated with Microsoft Entra ID, it can directly monitor sign-in events and respond to suspicious activities, making it a strong fit for this identity-threat scenario.

Why this answer

Microsoft Defender for Cloud Apps (Option B) is correct because it provides Cloud Access Security Broker (CASB) capabilities that analyze sign-in logs for anomalous behavior, such as impossible travel, suspicious IP addresses, and credential theft. It integrates with Microsoft Entra ID to detect and respond to risky sign-in events in real time, making it a core component for monitoring suspicious activity.

Exam trap

The trap here is that candidates often select Azure Monitor or Log Analytics workspace alone, thinking they can detect suspicious activity, but they lack the built-in threat detection and analytics engines that are specific to security-focused services like Defender for Cloud Apps and Sentinel.

717
MCQeasy

A company is deploying a web application that must be accessible from the internet. The application is hosted on Azure virtual machines in a virtual network. The solution must provide SSL termination, web application firewall (WAF) protection, and URL path-based routing (e.g., /api/* to one backend pool, /app/* to another). The web tier must not be directly exposed to the internet. Which Azure load balancing solution should they use?

A.Azure Application Gateway v2
B.Azure Front Door
C.Azure Load Balancer
D.Azure Traffic Manager
AnswerA

Azure Application Gateway v2 is a regional Layer 7 reverse proxy that performs SSL termination, web application firewall (WAF) inspection, and URL path-based or multi-site routing. It can be configured with a public front-end IP and a backend pool containing VMs with only private IPs, making it ideal for protecting an internet-facing web tier. The v2 SKU adds auto-scaling and zone redundancy, with the WAF policy enforcing OWASP rule sets at the HTTP edge.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that provides SSL termination, a web application firewall (WAF), and URL path-based routing. It can route traffic to different backend pools based on URL paths (e.g., /api/* and /app/*) while keeping the web tier isolated within the virtual network, as the gateway itself is exposed to the internet.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway, but Front Door is designed for global, multi-region scenarios and cannot provide direct VNet integration for a single-region app without exposing backend public IPs, whereas Application Gateway is the correct Layer 7 solution for a single-region VNet deployment.

How to eliminate wrong answers

Option B (Azure Front Door) is wrong because it is a global, multi-region load balancer and application delivery network that operates at the edge, not within a single virtual network; it cannot provide direct SSL termination and WAF for a single-region VNet-hosted app without exposing the backend to the internet via public endpoints. Option C (Azure Load Balancer) is wrong because it operates at Layer 4 (TCP/UDP) and cannot perform SSL termination, WAF inspection, or URL path-based routing. Option D (Azure Traffic Manager) is wrong because it is a DNS-based traffic router that only directs clients to endpoints based on DNS resolution, not a proxy that can terminate SSL, apply WAF rules, or route based on URL paths.

718
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to allow users to sign in to multiple SaaS applications using their Microsoft Entra ID credentials without being prompted again for each application. Which Microsoft Entra ID feature should they enable?

A.Single Sign-On (SSO)
B.Multi-Factor Authentication (MFA)
C.Conditional Access
D.Identity Protection
AnswerA

SSO in Microsoft Entra ID uses the primary authentication token (e.g., SAML, OAuth2/OIDC) to establish a federated session, so subsequent application requests are silently authenticated without re-prompting. This works because Entra ID acts as the trusted broker that issues session cookies or refresh tokens, eliminating per-app credential entry. For this scenario, deploying SSO directly satisfies the requirement for one authentication followed by seamless access across all integrated applications.

Why this answer

Single Sign-On (SSO) enables users to authenticate once with Microsoft Entra ID and then access multiple SaaS applications without being prompted again. This works by using standards like SAML 2.0 or OpenID Connect to issue a session token or cookie that is reused across applications, eliminating repeated credential prompts.

Exam trap

The trap here is that candidates confuse MFA or Conditional Access with SSO, thinking that additional security features inherently reduce sign-in prompts, but in reality, SSO is the specific feature designed to eliminate repeated prompts, while MFA and Conditional Access are complementary security controls that do not provide that functionality.

How to eliminate wrong answers

Option B (Multi-Factor Authentication) is wrong because MFA adds an extra layer of security by requiring a second verification factor, but it does not eliminate repeated sign-in prompts across applications; it actually increases authentication friction. Option C (Conditional Access) is wrong because it is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-ins from untrusted locations) based on signals, but it does not provide the seamless token reuse that SSO offers. Option D (Identity Protection) is wrong because it is a risk-based detection and remediation service that identifies compromised identities and suspicious sign-ins, not a mechanism to avoid repeated authentication prompts.

719
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to integrate their on-premises Active Directory with Microsoft Entra ID to enable single sign-on (SSO) for cloud applications. Users should be able to use the same password for on-premises resources and cloud applications. The company has a large on-premises user base and wants to avoid additional infrastructure for federation. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra ID Connect (Password Hash Synchronization)
B.Microsoft Entra ID Application Proxy
C.Microsoft Entra ID B2B
D.Microsoft Entra ID Domain Services
AnswerA

Password Hash Synchronization (PHS) is the correct choice because it synchronizes a cryptographic hash of each on-premises password to Microsoft Entra ID, enabling users to authenticate to cloud SaaS applications with their existing corporate credentials. Unlike federation options, it requires no additional servers or infrastructure and works even if a user's on-premises password changes, as the hash is updated in near-real-time. PHS can be combined with Microsoft Entra Seamless SSO to give a silent sign-in experience on domain-joined devices. This makes it a lightweight, reliable hybrid identity mechanism.

Why this answer

Password Hash Synchronization (PHS) is the correct choice because it synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID, enabling users to use the same password for both on-premises and cloud resources without requiring any additional federation infrastructure. This meets the requirement for SSO to cloud applications while avoiding the complexity and cost of deploying Active Directory Federation Services (AD FS) or other federation servers.

Exam trap

The trap here is that candidates often confuse federation (e.g., AD FS) as the only way to achieve SSO with password reuse, but Password Hash Synchronization provides a simpler, infrastructure-free alternative that still meets the requirement.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Application Proxy is designed to provide secure remote access to on-premises web applications, not to synchronize identities or enable SSO via password reuse. Option C is wrong because Microsoft Entra ID B2B (Business-to-Business) is used for collaborating with external guest users from other organizations, not for integrating an on-premises AD with Entra ID for internal user SSO. Option D is wrong because Microsoft Entra ID Domain Services provides managed domain services (e.g., group policy, LDAP, Kerberos) for Azure VMs, but it does not synchronize passwords or enable SSO to cloud applications from on-premises AD.

720
MCQeasy

You need to monitor the sign-in activities of users in Microsoft Entra ID and detect risky sign-ins, such as those from anonymous IP addresses. Which service should you use?

A.Microsoft Entra Identity Protection
B.Microsoft Defender XDR
C.Azure Monitor
D.Microsoft Sentinel
AnswerA

Microsoft Entra Identity Protection is the correct service because it is purpose-built for identity risk detection. It applies machine-learning algorithms to signals such as impossible travel, anonymous IP addresses, atypical sign-ins, and leaked credentials to assign a risk level to each sign-in and user. These risk assessments drive conditional access policies and can trigger automated remediation, such as requiring MFA or blocking the sign-in. For monitoring sign-in activities specifically for risk, this is the native Entra ID capability.

Why this answer

Microsoft Entra Identity Protection is the correct service because it is specifically designed to detect and respond to risky sign-in activities, including sign-ins from anonymous IP addresses, using machine learning-based risk detection policies. It integrates directly with Microsoft Entra ID to evaluate sign-in risk in real time and can automatically block or require multi-factor authentication based on configured risk thresholds.

Exam trap

Microsoft often tests the distinction between a dedicated identity risk detection service (Identity Protection) and a broader security or monitoring platform (Defender XDR, Sentinel, or Azure Monitor), leading candidates to choose the more general tool when the question specifically asks for a service that detects risky sign-ins from anonymous IP addresses.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender XDR (Extended Detection and Response) focuses on detecting and responding to security threats across endpoints, email, and applications, not specifically on monitoring sign-in risk from anonymous IP addresses in Entra ID. Option C is wrong because Azure Monitor is a platform for collecting and analyzing telemetry from Azure resources and applications, but it does not have built-in risk detection algorithms for sign-in activities like anonymous IP addresses. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that ingests logs from multiple sources for advanced threat hunting and analysis, but it is not the primary service for real-time, policy-driven risky sign-in detection in Entra ID; that is the role of Identity Protection.

721
MCQhard

You are designing a data storage solution for a global e-commerce platform that handles millions of transactions per day. The platform uses Azure Cosmos DB for its transactional data. The company wants to implement a real-time analytics pipeline to monitor sales trends and detect anomalies. The analytics must be performed on the transactional data with minimal latency (under 5 seconds). The solution must not impact the transactional workload's performance. The analytics queries involve aggregations over time windows and joins with reference data stored in Azure SQL Database. You need to recommend a solution. Which option should you choose?

A.Enable Azure Synapse Link for Cosmos DB and use Synapse serverless SQL to query the transactional data directly.
B.Use Azure Data Factory to copy data from Cosmos DB to Azure Synapse Analytics every minute, and run analytics queries in Synapse.
C.Use Azure Cosmos DB change feed to stream data to Azure Stream Analytics, which performs the aggregations and joins with reference data from Azure SQL Database.
D.Use Azure Databricks with Auto Loader to incrementally load data from Cosmos DB into Delta Lake, and then query with Spark SQL.
AnswerC

The Cosmos DB change feed emits each insert, update, and delete in real time, allowing Azure Stream Analytics to ingest the stream directly via the Cosmos DB connector. Stream Analytics can perform tumbling or hopping window aggregations and join the streaming events with reference data loaded from Azure SQL Database (using a reference input) at sub-second latency, making it the only option that satisfies both the 5-second SLA and the need for real-time joins against look-up data.

Why this answer

Azure Cosmos DB change feed enables real-time streaming of transactional data to Azure Stream Analytics, which can perform low-latency aggregations and joins with reference data from Azure SQL Database without impacting the transactional workload. This architecture meets the sub-5-second latency requirement and avoids any direct query load on Cosmos DB.

Exam trap

The trap here is that candidates often choose Azure Synapse Link (Option A) thinking it provides real-time analytics, but they overlook that Synapse Link's analytical store is refreshed asynchronously (typically every 1-5 minutes) and serverless SQL queries add additional latency, making it unsuitable for sub-5-second requirements.

How to eliminate wrong answers

Option A is wrong because Azure Synapse Link for Cosmos DB uses analytical store and serverless SQL, which is designed for near-real-time analytics but typically incurs higher latency (often >5 seconds) due to the time required to populate the analytical store and the overhead of querying large transactional datasets directly. Option B is wrong because Azure Data Factory copying data every minute introduces at least 60 seconds of latency, far exceeding the 5-second requirement, and the copy process can impact the transactional workload's performance. Option D is wrong because Azure Databricks with Auto Loader is optimized for batch or micro-batch processing, not true real-time streaming, and the incremental load from Cosmos DB would add latency beyond 5 seconds while also requiring complex orchestration to avoid impacting the source.

722
MCQeasy

You are designing a monitoring solution for a cloud-native application that uses Azure Functions, Azure Storage, and Azure Cosmos DB. The solution must provide centralized log collection and analysis, enable proactive alerting on application errors, and support long-term log retention for compliance (7 years). What should you include in the design?

A.Use Azure Storage with cool tier for logs and enable Azure Storage Analytics logs.
B.Store logs in Azure Monitor Metrics with a retention of 93 days.
C.Use Application Insights to collect logs and set retention to 90 days, then export to Azure Blob Storage for archival.
D.Configure diagnostic settings for each Azure resource to send logs and metrics to a Log Analytics workspace.
AnswerD

Configuring diagnostic settings on each Azure resource sends resource logs, activity logs, and metrics to a central Log Analytics workspace, which provides a single repository for storage, querying, alerting, and long-term retention. This approach supports cross-resource KQL queries and allows you to align retention policies with your compliance requirements. It is the recommended Azure-native pattern for a cloud-native application because it centralizes logs and metrics on the platform's unified monitoring plane.

Why this answer

It leverages Log Analytics workspace as a centralized destination for diagnostic settings from Azure Functions, Storage, and Cosmos DB, enabling unified log collection, Kusto Query Language (KQL)-based analysis, proactive alerting, and long-term retention (up to 7 years) for compliance. This design satisfies all requirements: centralized logging, alerting on application errors, and archival-grade retention.

Exam trap

The trap here is that candidates often confuse Application Insights' export-to-blob feature as a complete solution, overlooking that exported logs become cold storage and lose the centralized query and alerting capabilities required by the scenario.

How to eliminate wrong answers

Option A is wrong because Azure Storage cool tier with Storage Analytics logs only provides basic storage-level metrics and logs (e.g., 200/400/500 responses) without the query, alert, or centralized analysis capabilities needed for application errors; it also lacks native 7-year retention control. Option B is wrong because Azure Monitor Metrics retain data for a maximum of 93 days (93 days for most metrics, 30 days for some), which falls far short of the 7-year compliance requirement and does not support log-based querying or alerting on application errors. Option C is wrong because Application Insights has a default retention of 90 days (extendable to 730 days with additional cost), and while export to Azure Blob Storage can archive logs, it breaks centralized querying and alerting—logs in blob storage are cold and not searchable via KQL, requiring additional processing to analyze.

723
MCQhard

A company stores petabytes of sensor data in Azure Data Lake Storage Gen2. They need to run complex analytics queries that involve joining multiple datasets and aggregating time-series data. The queries must complete within seconds. Which Azure service should they use for querying?

A.Azure Stream Analytics
B.Azure Data Explorer
C.Azure Synapse Analytics
D.Azure Databricks
AnswerC

Azure Synapse Analytics is the correct choice because it combines a massively parallel processing (MPP) SQL engine with direct query access to data stored in Azure Data Lake Storage through both dedicated SQL pools and serverless SQL, enabling fast interactive T-SQL queries over petabyte volumes. Its dedicated pool distributes rows across 60 compute nodes with columnstore indexes, while serverless provides per-query billing without provisioning. This architecture supports complex joins, aggregations, and BI reporting at the scale and concurrency expected from a data warehouse, making it the best fit for the sensor data lake.

Why this answer

Azure Synapse Analytics (Option C) is correct because it provides a unified analytics platform that can directly query petabyte-scale data in Azure Data Lake Storage Gen2 using T-SQL or Spark, and its distributed query engine (PolyBase or Synapse SQL) can perform complex joins and time-series aggregations with sub-second response times when combined with appropriate indexing and materialized views.

Exam trap

The trap here is that candidates often confuse Azure Data Explorer (Option B) as the best choice for time-series data, but the question specifies complex joins across multiple datasets and direct querying of Data Lake Storage Gen2, which Synapse handles natively while Data Explorer requires data ingestion and is not designed for multi-table joins at petabyte scale.

How to eliminate wrong answers

Option A is wrong because Azure Stream Analytics is a real-time stream processing service designed for low-latency queries on streaming data, not for complex ad-hoc analytics on petabytes of stored historical data in Data Lake Storage Gen2. Option B is wrong because Azure Data Explorer is optimized for interactive analytics on large volumes of time-series and log data, but it requires data to be ingested into its own storage engine, not directly querying Data Lake Storage Gen2, and it lacks the full T-SQL and Spark capabilities needed for complex joins across multiple datasets. Option D is wrong because Azure Databricks is a big data analytics platform using Apache Spark, which can handle complex queries but typically requires data to be loaded into Spark DataFrames or tables, and it may not achieve consistent sub-second query completion without significant optimization and caching, unlike Synapse's dedicated SQL pool or serverless SQL.

724
Multi-Selecthard

Which THREE factors should you consider when selecting a partition key for an Azure Cosmos DB container? (Select three.)

Select 3 answers
A.Even distribution of request unit (RU) consumption
B.Low cardinality to reduce overhead
C.High cardinality (many distinct values)
D.Property with large binary data
E.Property frequently used as a filter in queries
AnswersA, C, E

An effective partition key must result in a relatively even distribution of request unit (RU) consumption across all logical partitions, not just a high number of distinct values. If a particular key value receives a disproportionate share of reads or writes, the physical partition hosting it becomes hot and triggers throttling (HTTP 429) for that traffic. Therefore, when evaluating candidate keys, you should model the expected workload and confirm that no single key value accounts for an excessive fraction of the total RU spend.

Why this answer

An even distribution of request unit (RU) consumption across physical partitions prevents hot partitions, which can throttle throughput and degrade performance. In Azure Cosmos DB, the partition key determines how data and throughput are distributed; if RU consumption is skewed, some partitions become overloaded while others remain underutilized, violating the design goal of uniform load.

Exam trap

The trap here is that candidates confuse low cardinality with efficiency, but Cosmos DB requires high cardinality to avoid storage limits and hot partitions, and they may also mistakenly think large binary properties are acceptable partition keys despite the 2 KB limit and indexing overhead.

725
MCQhard

Your organization is migrating a legacy on-premises application to Azure. The application uses a monolithic architecture and requires high availability. The application tier runs on Windows Server and uses a SQL Server database. You need to design a migration strategy that minimizes changes to the application code while maximizing availability. The application can be stateless if session state is externalized. You have the following requirements: (1) The application must be resilient to Azure region failures. (2) The database must have an RPO of 5 minutes and RTO of 1 hour. (3) The migration must be completed within 6 months. (4) The solution should use platform-as-a-service (PaaS) services where possible to reduce operational overhead. Which approach should you recommend?

A.Rehost the application on Azure VMs in an availability set and use SQL Server Always On Availability Groups.
B.Migrate the web tier to Azure App Service with staging slots and use Azure SQL Database with active geo-replication.
C.Refactor the application into microservices and deploy to Azure Kubernetes Service.
D.Containerize the application using Docker and deploy to Azure Container Instances in paired regions.
AnswerB

Azure App Service with staging slots gives you zero-downtime deployments through slot swaps, and you can use external session state (e.g., Redis Cache) so the web tier can scale out. Azure SQL Database with active geo-replication creates a readable secondary in a paired region, supporting manual or automatic failover to meet RPO/RTO targets. This PaaS solution requires minimal or no code changes—much less than a microservices refactor—and offloads patching, high availability, and backup management to the platform.

Why this answer

It uses Azure App Service (PaaS) to host the stateless web tier with staging slots for zero-downtime deployments and Azure SQL Database with active geo-replication to meet the RPO of 5 minutes and RTO of 1 hour. This approach minimizes code changes by externalizing session state (e.g., using Azure Cache for Redis) and leverages PaaS to reduce operational overhead while providing regional failover resilience.

Exam trap

The trap here is that candidates often choose Option A (rehost on VMs with Always On Availability Groups) because it seems familiar for SQL Server high availability, but they overlook the requirement to minimize operational overhead and the need for regional resilience, which PaaS services like App Service and Azure SQL Database with active geo-replication address more effectively.

How to eliminate wrong answers

Option A is wrong because rehosting on Azure VMs with an availability set only protects against datacenter failures within a single region, not Azure region failures, and it increases operational overhead (IaaS management) rather than using PaaS. Option C is wrong because refactoring into microservices and deploying to AKS requires significant code changes and a longer migration timeline, contradicting the requirement to minimize code changes and complete migration within 6 months. Option D is wrong because Azure Container Instances in paired regions does not provide built-in high availability or automated failover for the database tier, and it lacks the session state externalization and PaaS database capabilities needed to meet the RPO/RTO targets.

726
Multi-Selecthard

Which THREE Azure Monitor capabilities can be used to detect and diagnose performance issues in a multi-tier application?

Select 3 answers
A.Azure Monitor Workbooks
B.Azure Policy
C.Live Metrics Stream in Application Insights
D.Application Insights Profiler
E.Application Map in Application Insights
AnswersC, D, E

Live Metrics Stream in Application Insights delivers real-time telemetry with sub-second latency, enabling you to see incoming requests, failures, and performance counters as they occur. Crucially, it uses live sampling and filtering, allowing you to isolate specific operations or attribute values on demand, which makes it an essential tool for detecting issues immediately during a deployment or incident. Unlike other tools, it does not persist data for retrospective analysis, but it is unmatched for live detection and validation.

Why this answer

Live Metrics Stream in Application Insights (Option C) provides real-time monitoring of application performance metrics, such as request rates, response times, and failure rates, with sub-second latency. This allows immediate detection of performance issues as they occur, making it ideal for diagnosing live problems in a multi-tier application.

Exam trap

The trap here is that candidates may confuse Azure Monitor Workbooks (a visualization tool) with a diagnostic capability, or think Azure Policy can monitor performance, when in fact only Application Insights features like Live Metrics Stream, Profiler, and Application Map provide real-time or deep diagnostic insights.

727
Multi-Selectmedium

You are designing a data storage solution for a multi-tenant SaaS application. Each tenant's data must be isolated and encrypted with a tenant-specific key. The solution must support automatic key rotation and the ability to revoke a tenant's access immediately by disabling their key. The data will be stored in Azure Blob Storage. Which two actions should you include in your design? (Choose two.)

Select 2 answers
A.Create a separate Azure Key Vault for each tenant and store the tenant's customer-managed key in that vault.
B.Use Azure Disk Encryption with BitLocker for each tenant's virtual machine disks.
C.Configure Azure Blob Storage encryption scopes, each using a tenant-specific customer-managed key from the tenant's Key Vault.
D.Store all tenant data in a single container and use a single customer-managed key stored in Azure Key Vault Managed HSM.
E.Enable Azure Storage Service Encryption with Microsoft-managed keys and use Azure Policy to enforce per-tenant encryption.
AnswersA, C

Using a separate Azure Key Vault per tenant provides strong isolation of keys. Each tenant's key is stored in its own vault, and you can disable the key in that vault to immediately revoke access to that tenant's data. This also simplifies key management and auditing per tenant. Azure Blob Storage supports customer-managed keys from a Key Vault, and you can configure each storage account or encryption scope to use a specific key.

Why this answer

The requirements are per-tenant encryption with tenant-specific keys, automatic key rotation, and immediate revocation by disabling a key. Creating a separate Key Vault per tenant and using encryption scopes in Blob Storage that reference those keys achieves this. Encryption scopes allow different containers or blobs to be encrypted with different keys, and disabling a key in Key Vault immediately blocks access to data encrypted with that key.

This design provides strong isolation and meets all requirements.

Exam trap

The trap here is assuming that a single key with access policies can provide per-tenant isolation; revoking one tenant's access would affect all tenants if they share a key.

728
MCQmedium

A company backs up their Azure VMs using Azure Backup. They need to meet compliance that requires backups to be stored in a separate geographic region. Additionally, they want to be able to restore the entire VM to that secondary region in case of a regional disaster. What should they configure?

A.Use a Recovery Services vault with Locally Redundant Storage (LRS) and enable cross-region restore
B.Use a Recovery Services vault with Geo-Redundant Storage (GRS) and enable cross-region restore
C.Use Azure Site Recovery to replicate the entire VM to the secondary region
D.Manually copy backup snapshots to a storage account in the secondary region
AnswerB

A Recovery Services vault configured with geo-redundant storage (GRS) asynchronously replicates the backup data to the Azure paired secondary region, creating the exact copy needed for secondary-region recovery. By then enabling cross-region restore on the vault, Azure Backup exposes the replicated recovery points as native restore items in the secondary region, satisfying both the backup compliance requirement and the need to restore VMs in a different region. This is the only option that provides a fully managed, policy-driven backup while also enabling restore to the secondary region.

Why this answer

Azure Backup with a Recovery Services vault using Geo-Redundant Storage (GRS) replicates backup data to a paired secondary region, meeting the compliance requirement for geographic separation. Enabling cross-region restore allows the entire VM to be restored in that secondary region during a regional disaster, as the backup data is already available there.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (continuous replication for DR) with Azure Backup (snapshot-based backup with cross-region restore), leading them to select Option C, which does not meet the backup compliance requirement for stored backups in a separate region.

How to eliminate wrong answers

Option A is wrong because Locally Redundant Storage (LRS) keeps data only within a single datacenter in the primary region, failing the compliance requirement for storage in a separate geographic region. Option C is wrong because Azure Site Recovery is a disaster recovery solution that replicates the VM for continuous replication and failover, not for backup storage or restore from backup snapshots; it addresses different RPO/RTO needs but does not meet the backup compliance requirement. Option D is wrong because manually copying backup snapshots to a secondary region is inefficient, error-prone, and does not leverage Azure Backup's built-in cross-region restore capability, which is designed for automated, compliant disaster recovery.

729
Multi-Selecthard

Which THREE components are required to implement a complete monitoring solution with Azure Monitor? (Choose three.)

Select 3 answers
A.Application Insights for every application
B.Azure Policy assignments
C.Alert rules to notify on conditions
D.A Log Analytics workspace for log storage
E.Data sources such as Azure resources and applications
AnswersC, D, E

Alert rules are the active, response-enabling component of a monitoring solution: they evaluate metric or log queries on a predefined schedule and, when conditions are breached, fire notifications or automated actions via action groups. Without alert rules, telemetry is merely stored and visualized, meaning issues like CPU spikes, request failures, or storage capacity overruns would go unnoticed until someone manually queries the workspace. A truly complete monitoring solution must include alerting to convert collected data into actionable notifications, enabling proactive incident response and minimizing downtime.

Why this answer

Alert rules (C) are a core component of a complete monitoring solution because they define conditions that trigger notifications or automated actions when monitored metrics or log data cross thresholds. Without alert rules, collected data remains passive and cannot proactively inform administrators of issues, making the solution incomplete.

Exam trap

The trap here is that candidates often confuse optional monitoring tools (like Application Insights) with mandatory components, or they mistakenly think governance tools (like Azure Policy) are part of the monitoring pipeline, when in fact the three required components are data sources, a Log Analytics workspace, and alert rules.

730
MCQmedium

A company uses Microsoft Entra ID to manage identities for employees and partners. They need to allow partners to self-service reset their passwords using a mobile app notification. Which feature should you enable?

A.Microsoft Entra ID Self-Service Password Reset (SSPR)
B.Microsoft Entra ID Identity Protection
C.Microsoft Intune
D.Microsoft Entra ID Privileged Identity Management
AnswerA

Microsoft Entra ID Self-Service Password Reset (SSPR) is the correct choice because it directly addresses the requirement for users to reset their own passwords without IT intervention. SSPR works by having users pre-register authentication methods—such as the Microsoft Authenticator mobile app notification, a phone number, or security questions—and then using one of those methods to verify their identity during the reset flow. This feature is tightly integrated with Entra ID and can be configured with Conditional Access policies to enforce appropriate security controls, making it the right identity-based solution for password self-service.

Why this answer

Microsoft Entra ID Self-Service Password Reset (SSPR) is the correct feature because it allows users, including partners configured as external users in the tenant, to reset their own passwords without administrator intervention. SSPR supports multiple authentication methods, including mobile app notification via the Microsoft Authenticator app, which satisfies the requirement for a mobile app notification-based reset. This feature is specifically designed for password reset scenarios and can be scoped to include guest users when properly configured.

Exam trap

The trap here is that candidates often confuse Identity Protection (which deals with risk and conditional access) with SSPR, because both involve authentication methods, but Identity Protection does not enable password reset functionality.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection is a risk-based detection and remediation tool that identifies suspicious sign-in activities and potential vulnerabilities, but it does not provide self-service password reset capabilities. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not a password reset feature for user accounts. Option D is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not self-service password reset for standard users or partners.

731
MCQmedium

A company is designing an Azure Kubernetes Service (AKS) cluster for a microservices application. They need to ensure that pods can securely access Azure resources such as Azure Key Vault and Azure SQL Database without using service principals or connection strings. Which AKS feature should they enable?

A.Azure RBAC for Kubernetes authorization
B.Azure Policy for AKS
C.Microsoft Entra Workload ID
D.Azure CNI network plugin
AnswerC

Microsoft Entra Workload ID is the correct solution because it creates a federated identity credential that lets a Kubernetes pod authenticate to Azure services using an Azure AD workload identity. This identity is automatically projected into the pod as a token, enabling secure, passwordless access to Azure resources like Azure SQL or Blob Storage without storing secrets. It directly solves the required scenario by mapping the application's identity to Azure resource permissions.

Why this answer

Microsoft Entra Workload ID (formerly Azure AD Workload Identity) enables pods in AKS to authenticate to Azure resources like Key Vault and Azure SQL Database using federated identity credentials, eliminating the need for service principals or connection strings. It works by projecting an Entra ID-managed identity into the pod via a sidecar or mutating webhook, allowing the pod to obtain tokens directly from the Microsoft identity platform.

Exam trap

The trap here is that candidates often confuse Azure RBAC for Kubernetes authorization (which controls Kubernetes API permissions) with Azure RBAC for Azure resources, or assume that Azure CNI or Azure Policy can somehow provide identity-based access to Azure services.

How to eliminate wrong answers

Option A is wrong because Azure RBAC for Kubernetes authorization controls access to Kubernetes resources (e.g., pods, deployments) within the cluster, not access to external Azure services like Key Vault or SQL Database. Option B is wrong because Azure Policy for AKS enforces compliance and governance rules on the cluster (e.g., restricting container privileges), but does not provide identity-based authentication to Azure resources. Option D is wrong because Azure CNI (Container Networking Interface) provides IP-per-pod networking and VNet integration, but has no role in identity management or secure access to Azure services.

732
MCQeasy

Refer to the exhibit. You deploy this ARM template to a resource group in the East US region. You specify the parameter storageAccountType as 'Standard_GRS'. Which of the following is true about the deployed storage account?

A.The storage account name will be 'storage' followed by a random string.
B.The storage account will be deployed in the same region as specified by the parameter.
C.The storage account is zone-redundant and replicates data across availability zones.
D.The storage account is geo-redundant and replicates data to a paired region.
AnswerD

The sku.name value Standard_GRS explicitly designates Geo-Redundant Storage. This tier writes data to three copies in the primary region and then asynchronously copies it to a Microsoft-chosen paired secondary region. Therefore, the storage account is indeed geo-redundant and replicates its contents across a regional pair, which matches the statement exactly.

Why this answer

The parameter 'storageAccountType' is set to 'Standard_GRS', which specifies geo-redundant storage (GRS). GRS replicates your data synchronously three times within a single region using LRS, then asynchronously replicates to a paired secondary region, ensuring durability even during a regional outage.

Exam trap

The trap here is that candidates confuse 'Standard_GRS' with zone-redundant storage (ZRS) or assume the parameter controls the region, when in fact the region is determined by the resource group's location and the replication type is explicitly defined by the storage account SKU.

How to eliminate wrong answers

Option A is wrong because the ARM template uses the 'uniqueString' function with the resource group ID to generate a deterministic name, not a random string; the name will be 'storage' concatenated with a unique hash. Option B is wrong because the 'location' property is set to '[resourceGroup().location]', which deploys the storage account in the same region as the resource group (East US), not as specified by the parameter. Option C is wrong because 'Standard_GRS' is geo-redundant, not zone-redundant; zone-redundant storage (ZRS) uses 'Standard_ZRS' or 'Premium_ZRS' and replicates across availability zones within a single region.

733
MCQeasy

A company stores sensitive customer data in Azure Blob Storage. They need to ensure that data at rest is encrypted using a customer-managed key stored in Azure Key Vault. Which of the following should they use?

A.Azure Storage Service Encryption with customer-managed keys in Azure Key Vault
B.Azure Disk Encryption
C.Azure Storage Service Encryption with Microsoft-managed keys
D.Azure Information Protection
AnswerA

Azure Storage Service Encryption (SSE) is enabled by default for all Azure Storage accounts, including Blob Storage, encrypting data at rest before it is persisted to disk. By specifying customer-managed keys (CMK) in Azure Key Vault, you take ownership of the encryption key lifecycle — including rotation, versioning, and revocation — rather than relying on Microsoft-held keys. This also enables auditability of key usage via Key Vault logs, and can be integrated with Azure Policy to enforce CMK across subscriptions. For a scenario requiring customer-managed encryption for sensitive customer data in Blob Storage, SSE with CMK is the appropriate mechanism.

Why this answer

Azure Storage Service Encryption (SSE) encrypts data at rest in Azure Blob Storage. When configured with customer-managed keys (CMK) stored in Azure Key Vault, the customer controls the encryption key lifecycle, including rotation and revocation, meeting the requirement for customer-managed key control. This is the only option that directly applies to Blob Storage data at rest with CMK support.

Exam trap

The trap here is that candidates confuse Azure Disk Encryption (which encrypts VM disks) with Azure Storage Service Encryption (which encrypts Blob Storage data), leading them to select the wrong service for the given scenario.

How to eliminate wrong answers

Option B is wrong because Azure Disk Encryption encrypts OS and data disks of virtual machines, not Azure Blob Storage data. Option C is wrong because it uses Microsoft-managed keys, not customer-managed keys as required. Option D is wrong because Azure Information Protection is a classification and labeling solution for documents and emails, not an encryption mechanism for data at rest in Blob Storage.

734
MCQmedium

A global e-commerce company runs a product catalog application that requires low-latency reads and writes from multiple geographic regions. The data is key-value structured and must be replicated with multi-region write capability. The company needs a fully managed NoSQL database service with guaranteed 99th percentile latency and automatic conflict resolution. Which Azure data service should they choose?

A.Azure Cosmos DB
B.Azure Table Storage
C.Azure Redis Cache
D.Azure SQL Database
AnswerA

Azure Cosmos DB is a globally distributed NoSQL database engineered for product-catalog workloads that require active-active writes across multiple Azure regions. It supports a choice of APIs (SQL, MongoDB, Cassandra, etc.), and with multi-region writes it provides automatic conflict resolution, turnkey global distribution, and deterministic 99th-percentile latency SLAs. For an ecommerce catalog, Cosmos DB's partition-key design and tunable consistency levels allow low-latency reads and writes at scale while meeting a strict SLO.

Why this answer

Azure Cosmos DB is the correct choice because it is a fully managed NoSQL database that supports multi-region writes with automatic conflict resolution, guarantees 99th percentile latency, and provides low-latency reads and writes globally. Its multi-master replication and tunable consistency models meet the key-value structured data requirements and the need for high availability across geographic regions.

Exam trap

The trap here is that candidates may confuse Azure Table Storage's NoSQL nature with Cosmos DB's multi-region write and latency guarantees, overlooking the critical requirements for automatic conflict resolution and 99th percentile latency SLAs.

How to eliminate wrong answers

Option B is wrong because Azure Table Storage is a NoSQL key-value store but does not support multi-region write capability or automatic conflict resolution, and it lacks guaranteed 99th percentile latency SLAs. Option C is wrong because Azure Redis Cache is an in-memory data store, not a fully managed NoSQL database, and it does not provide multi-region write replication or automatic conflict resolution for persistent data. Option D is wrong because Azure SQL Database is a relational database, not a NoSQL key-value store, and it does not natively support multi-region writes with automatic conflict resolution.

735
Matchingmedium

Match each Azure security service to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Unified security management and threat protection

Cloud-native SIEM and SOAR

Manage secrets, keys, and certificates

Protect against distributed denial-of-service attacks

Managed cloud network security service

Why these pairings

Correct matches: Azure Sentinel (intelligent security analytics), Azure Firewall (network firewall). Common confusions: Security Center with Key Vault (secret management), Key Vault with DDoS Protection, DDoS Protection with Security Center.

736
MCQmedium

Your company is designing a new application that will process large volumes of streaming data from IoT devices. The data will be ingested, processed in near real-time, and stored for long-term analytics. You need to design a solution that meets the following requirements: (1) Ingest up to 1 million events per second. (2) Process events with a latency of less than 10 seconds. (3) Store processed data for 7 years for compliance. (4) Enable ad-hoc querying of the stored data. Which combination of Azure services should you recommend?

A.Azure IoT Hub, Azure Stream Analytics, and Azure Cosmos DB.
B.Azure Service Bus, Azure Functions, and Azure SQL Database.
C.Azure Event Hubs, Azure Functions, and Azure Cosmos DB.
D.Azure Event Hubs, Azure Stream Analytics, and Azure Data Lake Storage Gen2.
AnswerD

This stack is correct because Azure Event Hubs is a fully managed, partition-based event ingestion service that can capture millions of events per second with low latency. Azure Stream Analytics provides a SQL-like processing engine with tumbling, hopping, and sliding windows to aggregate and filter the data in real time, and it can write output directly to Azure Data Lake Storage Gen2. ADLS Gen2 offers hierarchical namespace, fine-grained POSIX ACLs, and low per-terabyte cost, making it ideal for long-term archival that can be queried on demand by engines like Synapse, Databricks, or Power BI.

Why this answer

Azure Event Hubs can ingest up to 1 million events per second with low latency, Azure Stream Analytics processes the streaming data in near real-time (sub-10-second latency) using temporal windowing and SQL-like queries, and Azure Data Lake Storage Gen2 provides cost-effective, scalable storage for 7 years of compliance data while supporting ad-hoc querying via tools like Azure Synapse Analytics or PolyBase. This combination meets all requirements: high-throughput ingestion, low-latency processing, long-term retention, and queryability.

Exam trap

The trap here is that candidates often choose Azure Cosmos DB for storage because of its low-latency querying, but they overlook the cost and scalability requirements for 7-year compliance storage, where Azure Data Lake Storage Gen2 is the correct choice for cost-effective, queryable archival.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL database optimized for low-latency transactional workloads, not for long-term, cost-effective storage of large volumes of historical data for 7 years; it would be prohibitively expensive and lacks native ad-hoc querying over petabyte-scale data. Option B is wrong because Azure Service Bus is a message broker designed for enterprise messaging with lower throughput (typically up to 20,000 messages per second) and does not support 1 million events per second; Azure Functions has a maximum execution timeout of 10 minutes and is not designed for continuous, high-throughput stream processing with sub-10-second latency. Option C is wrong because while Azure Event Hubs handles ingestion, Azure Functions is not optimized for sustained, high-throughput stream processing (it scales per event and incurs cold-start latency), and Azure Cosmos DB is not suitable for 7-year compliance storage due to high cost and lack of native ad-hoc querying over historical data.

737
MCQmedium

You are the Azure architect for a healthcare organization that needs to store patient medical records (unstructured data) and provide secure access to doctors and nurses via a web application. The data must be encrypted at rest and in transit. Access must be authorized based on the requester's role (doctor, nurse, admin). The solution must be cost-effective and support high concurrency. You decide to use Azure Blob Storage. You need to design the access control mechanism. What should you recommend?

A.Enable storage service encryption and use HTTPS.
B.Use shared access signatures (SAS) with stored access policies.
C.Use Azure RBAC with Microsoft Entra ID authentication.
D.Use storage account access keys and distribute them to users.
AnswerC

Azure RBAC with Microsoft Entra ID authentication assigns built-in or custom roles scoped to the storage account or container, so doctors, nurses and admins receive permissions matching their role. This satisfies the stem's role-based authorisation requirement while remaining cost-effective and supporting high concurrency.

Why this answer

Use Azure RBAC with Microsoft Entra ID authentication. Azure RBAC (Role-Based Access Control) integrated with Microsoft Entra ID (formerly Azure AD) allows you to assign permissions to users based on their roles (e.g., doctor, nurse, admin) for fine-grained access to Blob Storage. This meets the requirement for role-based authorization without managing separate keys or tokens.

Option A is incorrect because encryption at rest and HTTPS only address data protection, not access control. Option B is incorrect because shared access signatures (SAS) grant time-limited access to specific resources but are not tied to user roles. Option D is incorrect because storage account access keys provide full administrative access to the entire storage account, not role-based permissions.

738
MCQmedium

A company uses Microsoft Entra ID. They want to allow external business partners to request access to a specific internal application. The access must be time-limited and require approval from a manager within the partner's organization. Additionally, access should automatically expire after the defined period. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Entitlement Management
B.Microsoft Entra ID B2B Collaboration
C.Microsoft Entra ID Identity Governance
D.Microsoft Entra ID Privileged Identity Management (PIM)
AnswerA

Microsoft Entra ID Entitlement Management enables you to create access packages that external users can request. You can configure approval workflows, set time limits, and auto-expire access. It is part of Microsoft Entra ID Identity Governance.

Why this answer

Microsoft Entra ID Entitlement Management enables organizations to manage access requests for internal and external users through access packages. It supports time-limited access with automatic expiration and allows delegation of approval to a manager within the partner's organization via connected organizations. This directly meets the requirement for external partner self-service access with time-bound, approved access.

Exam trap

The trap here is that candidates often confuse Entitlement Management with B2B Collaboration, thinking B2B alone provides access control and expiration, when in fact B2B only handles identity creation and invitation, while Entitlement Management adds the governance layer for time-limited, approved access.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID B2B Collaboration provides the underlying invitation and redemption mechanism for external users but does not include built-in time-limited access, approval workflows, or automatic expiration; it requires additional configuration with Entitlement Management or other features. Option C is wrong because Microsoft Entra ID Identity Governance is an overarching category that includes Entitlement Management, access reviews, and lifecycle workflows, but it is not a specific feature that directly handles external partner access requests with time limits and manager approval. Option D is wrong because Microsoft Entra ID Privileged Identity Management (PIM) is designed for managing, controlling, and monitoring privileged roles within an organization, not for granting time-limited access to applications for external business partners.

739
MCQeasy

A startup is building a new mobile app backend. They need a fully managed relational database service with built-in high availability, automatic backups, and built-in intelligence to optimize performance. They want to minimize administrative overhead for tasks like patching and scaling. Which Azure service should they use?

A.Azure SQL Database
B.SQL Server on Azure Virtual Machines
C.Azure Database for MySQL
D.Azure Cosmos DB
AnswerA

Azure SQL Database is the correct choice because it is a fully managed Platform-as-a-Service relational database that eliminates patching, backups, and high-availability configuration. Its built-in intelligent query optimization, automatic tuning, and geo-replication capabilities align directly with the requirement for a fully managed backend. You simply provision the logical server and database, and Azure handles infrastructure redundancy, automated backups with point-in-time restore, and a 99.99% SLA, freeing your team to focus on application development.

Why this answer

Azure SQL Database is a fully managed Platform-as-a-Service (PaaS) relational database that includes built-in high availability (99.99% SLA), automatic backups with point-in-time restore, and built-in intelligence features like automatic tuning, adaptive query processing, and intelligent insights. This minimizes administrative overhead for patching, scaling, and performance optimization, making it ideal for a startup that wants to focus on app development rather than database management.

Exam trap

The trap here is that candidates often confuse 'fully managed' with 'IaaS' or pick Azure Database for MySQL because it is also fully managed, but they overlook the specific requirement for 'built-in intelligence to optimize performance,' which is a hallmark of Azure SQL Database's automatic tuning features, not available in Azure Database for MySQL.

How to eliminate wrong answers

Option B is wrong because SQL Server on Azure Virtual Machines is an Infrastructure-as-a-Service (IaaS) offering that requires you to manage patching, backups, high availability setup (e.g., Always On Availability Groups), and scaling manually, increasing administrative overhead. Option C is wrong because Azure Database for MySQL is a fully managed relational database, but it lacks the built-in intelligence features (e.g., automatic tuning, intelligent insights) that Azure SQL Database provides, and the question specifically asks for 'built-in intelligence to optimize performance.' Option D is wrong because Azure Cosmos DB is a NoSQL database (supporting document, key-value, graph, and column-family models), not a relational database, and it does not use SQL as its primary query language (though it has a SQL API, it is not a relational database engine).

740
MCQmedium

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to ensure that an alert is generated when an Azure VM is created with an open inbound SSH port (22) from the internet. The solution should use existing Azure resources and minimize administrative overhead. What should you use?

A.Create a Microsoft Sentinel analytics rule using the Azure Activity data connector.
B.Create an Azure Policy with audit effect and configure a Sentinel data connector for Azure Policy.
C.Create an Azure Monitor metric alert on the 'Network In' metric.
D.Enable Microsoft Defender for Cloud and configure a continuous export to Sentinel.
AnswerA

The Azure Activity data connector ingests control-plane events for virtual machine creation and updates. An analytics rule can filter for `Microsoft.Compute/virtualMachines/write` and use KQL to correlate the resource ID with NSG flow logs, network security rules, or resource properties to determine when a new VM is publicly accessible with port 22 open. This is the only option that combines the exact ARM event with a configurable check for SSH port exposure inside a single detection rule.

Why this answer

Microsoft Sentinel's Azure Activity data connector ingests resource logs from Azure's control plane (Azure Resource Manager). By creating an analytics rule that detects a 'Microsoft.Compute/virtualMachines/write' operation with a network security group rule allowing inbound SSH (port 22) from 'Internet' (any IP), you can generate an alert without deploying additional agents or infrastructure. This minimizes administrative overhead by using existing Sentinel resources and the built-in Activity log connector.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Defender for Cloud or Azure Policy, thinking they need a security-specific service, when the simplest path is to use the already-connected Azure Activity data connector in Sentinel to monitor control-plane operations for risky configurations.

How to eliminate wrong answers

Option B is wrong because Azure Policy with audit effect can evaluate compliance and log to the Activity Log, but it does not natively generate Sentinel alerts; you would need a separate data connector for Azure Policy (which is not a standard Sentinel connector) and additional logic to create alerts, increasing overhead. Option C is wrong because the 'Network In' metric on Azure Monitor measures data throughput at the VM's virtual NIC, not inbound SSH port 22 access; it cannot detect open ports or security rules. Option D is wrong because enabling Microsoft Defender for Cloud and configuring continuous export to Sentinel adds unnecessary complexity and cost; while Defender for Cloud can detect open SSH ports, the question specifically requires using existing resources with minimal overhead, and the Azure Activity data connector alone suffices.

741
MCQhard

Your organization uses Microsoft Entra ID and requires that all external users invited via B2B collaboration must authenticate using multi-factor authentication (MFA). You need to enforce this for all guest users. What should you configure?

A.Microsoft Entra B2B collaboration settings
B.Microsoft Entra Identity Protection user risk policy
C.Microsoft Entra ID MFA registration policy
D.Microsoft Entra Conditional Access policy
AnswerD

A Microsoft Entra Conditional Access policy is the correct mechanism because it can target guest users—or all external identities—and apply the "Require MFA" grant control directly at each authentication attempt. You can further scope the policy to specific cloud apps, conditions, or locations, giving fine-grained enforcement. This is the standard identity-driven control for ensuring guests must complete MFA before accessing resources, making it the only option here that actually forces MFA at sign-in.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to enforce MFA for guest users by targeting the 'Guest or external users' identity type and requiring MFA as a grant control. This provides granular control over authentication requirements for B2B collaboration users, unlike the other options which either lack enforcement capability or apply to different scenarios.

Exam trap

The trap here is confusing MFA registration (a prerequisite) with MFA enforcement (a runtime control), leading candidates to select Option C, which only ensures users have registered for MFA but does not require them to actually use it during sign-in.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra B2B collaboration settings only control invitation behavior (e.g., who can invite, allowed domains) and do not enforce MFA during authentication. Option B is wrong because Identity Protection user risk policy triggers based on detected risk signals (e.g., leaked credentials) and does not enforce MFA for all guest users unconditionally. Option C is wrong because the MFA registration policy only requires users to register for MFA but does not enforce MFA during sign-in; it is a prerequisite, not an enforcement mechanism.

742
MCQeasy

A company wants to store application configuration settings and secrets (e.g., database connection strings, API keys) securely with automatic rotation. Access must be controlled and audited. Which Azure service should they use?

A.Azure Key Vault
B.Azure App Configuration
C.Azure Storage Queues
D.Azure Service Bus
AnswerA

Azure Key Vault is a specialized cloud service for securely storing and controlling access to secrets, encryption keys, and certificates. It uses Azure Active Directory authentication and fine-grained access policies to govern who can read or modify secret versions, and it natively integrates with Azure services (e.g., App Service) via Key Vault references for automatic secret rotation with zero downtime. It also provides audit logging, soft-delete, and purge protection, making it the only option here designed specifically for secrets management.

Why this answer

Azure Key Vault is the correct choice because it is designed specifically for securely storing and managing secrets, keys, and certificates. It supports automatic rotation of secrets via integration with Azure managed identities and event grid notifications, and provides fine-grained access control through Azure RBAC and access policies, with full auditing via Azure Monitor and diagnostic logs.

Exam trap

The trap here is that candidates often confuse Azure App Configuration with Key Vault because both deal with configuration, but App Configuration is for non-sensitive settings and feature flags, while Key Vault is the only service that provides secure secret storage with rotation and auditing.

How to eliminate wrong answers

Option B (Azure App Configuration) is wrong because it is optimized for managing application configuration settings and feature flags, not for storing secrets; it lacks native automatic rotation and secret-specific access policies. Option C (Azure Storage Queues) is wrong because it is a message queue service for asynchronous communication, not a secure store for secrets or configuration. Option D (Azure Service Bus) is wrong because it is an enterprise message broker for reliable messaging and pub/sub patterns, not a secrets management service.

743
MCQhard

Your organization is migrating a legacy on-premises application to Azure. The application uses a proprietary authentication protocol that is not supported by Microsoft Entra ID. You need to integrate the application with Microsoft Entra ID without modifying the application code. What should you do?

A.Use Azure Active Directory B2C with custom policies to translate the authentication protocol.
B.Deploy Azure Active Directory Domain Services and domain-join the application servers.
C.Configure Microsoft Entra ID Application Proxy to provide secure remote access and pass through authentication.
D.Implement Azure Active Directory Connect with pass-through authentication.
AnswerC

Microsoft Entra ID Application Proxy is the correct service because it publishes on-premises legacy applications through an outbound connector on your network without requiring a VPN or DMZ. In pass-through mode, the proxy forwards requests directly to the app and lets the app perform its own authentication, which is ideal for protocols that Microsoft Entra ID cannot understand. In pre-authentication mode, it can also use Kerberos constrained delegation or header injection to enable single sign-on while keeping Microsoft Entra ID as the front-end identity provider.

Why this answer

Microsoft Entra ID Application Proxy can be configured to publish on-premises applications that use legacy authentication protocols. It acts as a reverse proxy, terminating the external connection and forwarding requests to the internal application. Because it can be set to pass through authentication without requiring any changes to the application code, it allows the proprietary authentication protocol to continue working while still integrating with Microsoft Entra ID for access control and conditional access policies.

Exam trap

The trap here is that candidates often confuse pass-through authentication (which validates passwords against on-premises AD) with Application Proxy's pass-through mode (which forwards authentication headers unchanged), leading them to incorrectly select Azure AD Connect with pass-through authentication (Option D) instead of the correct Application Proxy solution.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C with custom policies is designed for customer-facing identity scenarios and requires modifying the application to redirect authentication flows, not for pass-through of a proprietary protocol without code changes. Option B is wrong because deploying Azure AD DS and domain-joining the application servers would require the application to support Kerberos or NTLM authentication, which it does not (it uses a proprietary protocol), and it does not integrate with Microsoft Entra ID for modern authentication. Option D is wrong because Azure AD Connect with pass-through authentication is used to synchronize on-premises directory objects and validate passwords against on-premises Active Directory, but it does not proxy or translate proprietary authentication protocols for an application.

744
MCQmedium

Your company runs a web application on Azure App Service (Standard tier) in a single region. You need to design a disaster recovery solution that can fail over to another region within 30 minutes. The application uses Azure SQL Database (General Purpose tier) and Azure Blob Storage. What should you implement?

A.Use Azure Traffic Manager with priority routing to a second App Service instance, use Azure SQL Database backup to a secondary region, and use Azure Storage zone-redundant storage (ZRS).
B.Configure App Service auto-scaling, use Azure SQL Database geo-replication with readable secondary, and use Azure Storage read-access geo-redundant storage (RA-GRS).
C.Configure App Service backup to a secondary region, use Azure SQL Database active geo-replication with auto-failover group, and use geo-redundant storage (GRS) for Blob Storage.
D.Configure App Service deployment slots, use Azure SQL Database geo-restore, and use Azure Storage locally-redundant storage (LRS).
AnswerC

App Service backup to a secondary region ensures that web application content, configuration, and files are recoverable in a different geographic location; the backup can be stored in a paired region and restored to a new App Service instance. Azure SQL Database active geo-replication with an auto-failover group continuously replicates data to a readable secondary database in another region and automatically promotes it during an outage, typically achieving an RTO of about one minute and an RPO of zero for committed transactions. Geo-redundant storage (GRS) replicates blobs asynchronously to a paired region, providing regional resilience and allowing manual or automated failover. This combination covers all layers—compute, database, and storage—with automated or nearly automated failover paths, making it the correct DR architecture.

Why this answer

It meets the 30-minute RTO by using Azure SQL Database active geo-replication with auto-failover groups, which provides automated, rapid failover to a secondary region. App Service backup to a secondary region ensures the web app can be restored quickly, and geo-redundant storage (GRS) for Blob Storage provides durable replication across regions, enabling failover within the required time frame.

Exam trap

The trap here is that candidates often confuse zone-redundant storage (ZRS) or locally-redundant storage (LRS) with geo-redundant options, failing to recognize that cross-region replication is mandatory for disaster recovery, and they may overlook the RTO constraints of geo-restore for SQL Database.

How to eliminate wrong answers

Option A is wrong because Azure Storage zone-redundant storage (ZRS) replicates data within a single region, not across regions, so it does not provide disaster recovery for a multi-region failover scenario. Option B is wrong because App Service auto-scaling only handles load within a region, not failover to another region, and read-access geo-redundant storage (RA-GRS) provides read access but does not guarantee failover within 30 minutes for writes. Option D is wrong because App Service deployment slots are for staging and swapping within the same region, not for cross-region failover, and Azure SQL Database geo-restore can take hours to complete, exceeding the 30-minute RTO.

745
MCQmedium

Your company uses Microsoft Sentinel for security monitoring. You need to design a solution that automatically responds to incidents involving high-severity alerts. The response should include creating an incident in Microsoft Teams and sending an email to the security team. What should you use?

A.Microsoft Sentinel automation rules and playbooks
B.Azure Policy with remediation tasks
C.Azure Monitor alert rules with action groups
D.Microsoft Defender for Cloud security alerts
AnswerA

Automation rules in Microsoft Sentinel are the native incident-response engine; they evaluate incidents as they are created or updated and can immediately trigger a playbook, which is an Azure Logic Apps workflow. A playbook can call the Teams connector to post a message to a security channel, send email through Outlook, open a ticket, or run containment actions, making it the only option here that directly addresses the requirement to create Teams messages and send emails during incident response.

Why this answer

Microsoft Sentinel automation rules and playbooks (built on Azure Logic Apps) are specifically designed to orchestrate automated responses to security incidents. When a high-severity alert triggers an incident, an automation rule can invoke a playbook that creates a Microsoft Teams message and sends an email via connectors like Office 365 Outlook, meeting the exact requirements.

Exam trap

The trap here is that candidates confuse Azure Monitor action groups (which can send emails/SMS for metric alerts) with Sentinel's incident-specific automation, overlooking that Sentinel requires its own automation rules and playbooks to orchestrate security response workflows.

How to eliminate wrong answers

Option B is wrong because Azure Policy with remediation tasks enforces compliance rules on Azure resources (e.g., ensuring encryption is enabled) and cannot trigger incident response workflows in Microsoft Teams or send emails based on Sentinel alerts. Option C is wrong because Azure Monitor alert rules with action groups are designed for infrastructure and application monitoring (e.g., CPU usage, HTTP errors), not for security incident response; they lack the context of Sentinel's threat intelligence and cannot create Teams incidents natively. Option D is wrong because Microsoft Defender for Cloud security alerts provide security posture recommendations and threat detections but do not include built-in automation to create Teams incidents or send emails; they rely on Sentinel or other tools for response orchestration.

746
MCQeasy

You are designing a disaster recovery solution for a critical application running in Azure. The application uses Azure SQL Database. The recovery point objective (RPO) is 5 seconds, and the recovery time objective (RTO) is 30 minutes. Which Azure SQL Database configuration should you recommend?

A.Point-in-time restore to a different region
B.Active geo-replication
C.Auto-failover groups
D.Azure Backup for SQL Server in Azure VM
AnswerB

Active geo-replication maintains a readable secondary database in a different region using asynchronous replication with an RPO of up to 5 seconds. The application can initiate a manual failover to the secondary, which typically completes in under 30 seconds, satisfying the RTO of 30 minutes. This makes it the ideal choice for critical databases that require minimal data loss and fast recovery.

Why this answer

Active geo-replication is the correct choice because it provides a continuous, asynchronous replication of data to a secondary database in a different Azure region, enabling an RPO of 5 seconds (typically under 5 seconds) and an RTO of 30 minutes or less by manually initiating a failover. This meets the stringent RPO and RTO requirements for a critical application using Azure SQL Database.

Exam trap

The trap here is that candidates often choose auto-failover groups (Option C) because they assume automatic failover is faster, but the RTO can be longer due to the grace period and the fact that automatic failover may not trigger within 30 minutes if the primary region is degraded but not fully down.

How to eliminate wrong answers

Option A is wrong because point-in-time restore to a different region restores from backups, which have an RPO of at least 1 hour (based on backup frequency) and an RTO that can exceed several hours, failing the 5-second RPO and 30-minute RTO. Option C is wrong because auto-failover groups use the same underlying geo-replication technology but add automatic failover, which can introduce a longer RTO due to the grace period and potential data loss from the asynchronous replication, and the RPO is still typically 5 seconds but the automatic failover may not meet the 30-minute RTO if the primary region is completely unavailable. Option D is wrong because Azure Backup for SQL Server in Azure VM is designed for SQL Server on VMs, not Azure SQL Database, and its RPO is typically 1 hour or more with an RTO that can be hours, making it unsuitable for the stated requirements.

747
MCQeasy

Refer to the exhibit. You assign this Azure Policy to a resource group. A user attempts to create a new Azure SQL Server without specifying an administrator login. What will happen?

A.The SQL Server is created with a default administrator login.
B.The SQL Server creation is denied.
C.The policy is ignored because the condition is not met.
D.The SQL Server is created but a compliance alert is generated.
AnswerB

When the policy condition detects that the `administratorLogin` field is absent, the `deny` effect is triggered during policy evaluation, causing the deployment request to fail. Azure Resource Manager enforces this policy before the SQL Server is provisioned, so the creation operation is blocked and no resource is created. This is a hard enforcement action, not a soft warning.

Why this answer

The Azure Policy assigned to the resource group includes a condition that checks if the 'administratorLogin' property is missing or null when creating a SQL Server. Since the user does not specify an administrator login, the condition evaluates to true, triggering the 'deny' effect. This prevents the creation of the SQL Server entirely, as Azure Policy enforces compliance before the resource is provisioned.

Exam trap

The trap here is that candidates may assume Azure SQL Server has a default administrator login or that the policy would only generate an alert, but Azure Policy's 'deny' effect proactively blocks non-compliant resource creation, not just reports on it.

How to eliminate wrong answers

Option A is wrong because Azure SQL Server requires an administrator login to be specified; there is no default login, and the policy explicitly denies creation when it is missing. Option C is wrong because the condition is met—the administrator login is not specified—so the policy is not ignored; it actively denies the request. Option D is wrong because the policy's 'deny' effect blocks creation before the resource is deployed, so no SQL Server is created to generate a compliance alert; alerts only occur for 'audit' or 'modify' effects, not 'deny'.

748
Multi-Selectmedium

Which TWO of the following are requirements for using Azure Site Recovery to protect Azure VMs? (Choose two.)

Select 2 answers
A.VMs must use unmanaged disks
B.VMs must be using managed disks
C.VMs must be connected to a virtual network that has a VPN gateway to the target region
D.The source region must be a supported Azure region
E.VMs must be at least Standard_D2s_v3 size
AnswersB, D

Managed disks are a hard prerequisite for Azure Site Recovery of Azure IaaS VMs. ASR performs crash-consistent and app-consistent snapshots of these disks and replays them onto replica managed disks in the target region. Without managed disks, the replication engine has no supported configuration to process.

Why this answer

Azure Site Recovery for Azure VMs requires that the VMs use managed disks. Unmanaged disks are not supported because Site Recovery relies on the managed disk snapshot and replication capabilities to enable consistent, application-aware replication across regions. Managed disks also provide better performance, reliability, and integration with Azure's recovery services.

Exam trap

The trap here is that candidates often assume a VPN gateway is required for cross-region replication, but Azure Site Recovery uses the Azure internal network or public endpoints by default, and a VPN gateway is only needed if you choose private endpoint connectivity for security isolation.

749
MCQhard

Your company runs a stateless web application on Azure Kubernetes Service (AKS). You need to design a disaster recovery solution that ensures the application is available in another Azure region within 30 minutes of a regional failure. The solution must balance cost and complexity. What should you recommend?

A.Use Azure SQL Database active geo-replication for the application's database.
B.Use Azure Front Door to route traffic to a single AKS cluster with pods running in multiple regions.
C.Use Azure Traffic Manager to distribute traffic across two AKS clusters in different regions.
D.Deploy a single AKS cluster with nodes in multiple availability zones.
AnswerC

Azure Traffic Manager operates at the DNS level and can use priority routing to direct all traffic to the primary-region AKS cluster while continuously health-checking its endpoint; when the primary fails, Traffic Manager automatically fails over to the secondary-region cluster, meeting the RTO by keeping the stateless service available. Both clusters should be configured identically and expose the application through a load balancer or ingress service so users are seamlessly redirected.

Why this answer

Azure Traffic Manager can distribute traffic across two AKS clusters in different regions using DNS-based routing, such as priority or performance routing, enabling failover within the required 30-minute RTO. This approach balances cost and complexity by avoiding the need for active-active replication or complex multi-region pod configurations, while still meeting the stateless application's DR requirements.

Exam trap

The trap here is that candidates often confuse high availability within a region (availability zones) with disaster recovery across regions, leading them to choose Option D, which only protects against zonal failures, not regional outages.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database active geo-replication is a database-level solution, but the question specifies a stateless web application, implying the database is not the primary concern; moreover, it adds unnecessary cost and complexity for a stateless app. Option B is wrong because Azure Front Door routes traffic to a single AKS cluster, and while it can distribute traffic across regions, it requires pods to be deployed in multiple regions within that single cluster, which contradicts the single-cluster design and introduces complexity without clear DR isolation. Option D is wrong because deploying a single AKS cluster with nodes in multiple availability zones provides high availability within a single region, not disaster recovery across regions, and thus cannot ensure availability in another Azure region during a regional failure.

750
MCQmedium

Your company uses Microsoft Entra ID to manage identities for 5,000 employees. You plan to implement Microsoft Entra ID Governance to automate the user provisioning lifecycle for a third-party SaaS application. The application supports SCIM 2.0. You need to ensure that user accounts are automatically created, updated, and disabled in the application based on changes in Entra ID. What should you do?

A.Use Microsoft Graph API to write a custom provisioning solution
B.Configure Microsoft Entra B2B collaboration for the application
C.Publish the application using Microsoft Entra Application Proxy
D.Configure automatic provisioning in Microsoft Entra ID using the SCIM endpoint
AnswerD

Configuring automatic provisioning in Microsoft Entra ID with the application's SCIM endpoint is the correct approach because SCIM is a standardized, cloud-scale protocol for automating user lifecycle management. Microsoft Entra ID will act as the SCIM client and call the app's SCIM 2.0 API to create, update, and deactivate users and groups in sync with changes in your identity source. This is a built-in feature, eliminating custom code and providing attribute mapping, scoping filters, and synchronization logs out of the box.

Why this answer

Microsoft Entra ID's automatic provisioning feature natively supports SCIM 2.0 endpoints, enabling automated creation, update, and deactivation of user accounts in third-party SaaS applications based on changes in Entra ID. This eliminates the need for custom code and provides a managed, scalable solution for the user provisioning lifecycle.

Exam trap

The trap here is that candidates may confuse the purpose of Application Proxy (remote access) or B2B collaboration (external identities) with provisioning automation, or assume that a custom Graph API solution is necessary when the built-in SCIM provisioning service is the correct, managed approach.

How to eliminate wrong answers

Option A is wrong because using Microsoft Graph API to write a custom provisioning solution would require significant development effort and ongoing maintenance, whereas the built-in provisioning service already handles SCIM-based automation without custom code. Option B is wrong because Microsoft Entra B2B collaboration is designed for external user access and guest identity management, not for automating the provisioning lifecycle of internal employees in a SaaS application. Option C is wrong because Microsoft Entra Application Proxy is used for secure remote access to on-premises web applications, not for provisioning user accounts to cloud SaaS applications.

Page 9

Page 10 of 11

Page 11

All pages