Courseiva

Microsoft Azure Solutions Architect Expert AZ-305 (AZ-305) — Questions 751–795

795 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
Multi-Selecteasy

Which TWO Azure services can be used to provide cross-region disaster recovery for Azure App Service web applications with a custom domain? (Select TWO.)

Select 2 answers
A.Azure DNS
B.Azure Front Door
C.Azure CDN
D.Azure Application Gateway
E.Azure Traffic Manager
AnswersB, E

Azure Front Door is a global, cloud-native entry point that uses anycast with the Microsoft global edge network to route HTTP/HTTPS traffic to the nearest healthy origin. It performs global load balancing, automatic failover, TLS termination, URL-based routing, and health probes at the application layer (L7). Its ability to monitor multiple regional backends and shift traffic instantly in response to health checks makes it a correct answer for providing cross-region resiliency.

Why this answer

Azure Front Door (B) provides global load balancing and traffic routing based on latency or priority, enabling cross-region failover for App Service web applications. It supports custom domains with TLS termination and health probes to automatically redirect traffic to a secondary region during a disaster. Azure Traffic Manager (E) also offers DNS-based traffic routing with priority or performance profiles, allowing failover to a secondary App Service instance in another region, and works with custom domains via CNAME records.

Exam trap

The trap here is that candidates often confuse Azure DNS (a domain registration and resolution service) with Traffic Manager (a DNS-based traffic routing service), or assume Azure Application Gateway can route cross-region traffic when it is strictly regional.

752
MCQeasy

Your organization uses Microsoft Purview for data governance. You need to classify sensitive data in Azure SQL Database and automatically apply sensitivity labels. What should you configure?

A.Azure Information Protection scanner
B.Microsoft Purview Data Map with scanning and labeling
C.Microsoft Sentinel with a workbook
D.Azure Policy with built-in SQL classification policy
AnswerB

Microsoft Purview Data Map natively integrates with Azure SQL Database through system-assigned managed identities, performs automated scanning of schema and sensitive data patterns (e.g., PII, credentials), and applies sensitivity labels automatically via built-in classification rules. These labels can be enforced with Microsoft Defender for Cloud, and the Data Map provides a centralized catalog for governance, making this the correct tool.

Why this answer

Microsoft Purview Data Map with scanning and labeling is the correct solution because it integrates with Azure SQL Database to automatically scan for sensitive data types (e.g., credit card numbers, social security numbers) and apply sensitivity labels defined in Microsoft Purview Information Protection. This native integration uses the Purview scanning infrastructure to classify data at rest and propagate labels directly to the SQL database, meeting the requirement for automated classification and labeling.

Exam trap

The trap here is that candidates often confuse Azure Policy's 'SQL classification' built-in initiative (which only audits or enforces the presence of classification) with the actual scanning and labeling capability, leading them to choose Option D instead of recognizing that Purview Data Map is the service that performs the automated classification work.

How to eliminate wrong answers

Option A is wrong because Azure Information Protection (AIP) scanner is designed for on-premises file shares and SharePoint, not for Azure SQL Database; it cannot scan or label data within a PaaS database. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution for security monitoring and threat detection, not a data classification or labeling tool; it lacks the capability to scan database schemas or apply sensitivity labels. Option D is wrong because Azure Policy with built-in SQL classification policy only enforces compliance rules (e.g., requiring classification to be enabled) but does not perform automatic scanning or labeling of sensitive data; it is a governance policy, not a classification engine.

753
MCQeasy

You need to monitor the performance and health of your Azure virtual machines, including custom metrics and logs. You also need to set up alerts based on specific thresholds. Which Azure service should you use?

A.Application Insights
B.Azure Service Health
C.Log Analytics
D.Azure Monitor
AnswerD

Azure Monitor is the correct answer because it is the comprehensive monitoring service that collects, analyzes, and responds to telemetry from Azure, on-premises, and hybrid resources, including compute capacity and health. It includes metric-based monitoring, guest-level performance counters through agents, resource health, activity logs, and alerting—all with native integration to dashboards and workbooks. For VMs, VM Insights (which relies on Log Analytics) extends this capability, while the platform itself remains Azure Monitor.

Why this answer

Azure Monitor is the correct choice because it provides a comprehensive solution for collecting, analyzing, and acting on telemetry from Azure virtual machines, including custom metrics and logs. It integrates with the Azure Monitor Agent to gather performance counters and event logs, and supports metric alerts and log alerts based on specific thresholds, directly meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse Log Analytics (a data store and query tool) with Azure Monitor (the full monitoring and alerting platform), leading them to select Option C when Azure Monitor is the correct overarching service that includes Log Analytics and alerting capabilities.

How to eliminate wrong answers

Option A is wrong because Application Insights is an Application Performance Management (APM) service focused on monitoring live web applications, not infrastructure-level metrics and logs from Azure VMs. Option B is wrong because Azure Service Health provides information about Azure service-level issues and planned maintenance, not custom metrics, logs, or threshold-based alerts for individual VMs. Option C is wrong because Log Analytics is a component within Azure Monitor that stores and queries log data, but it is not the overarching service for monitoring, alerting, and metrics; Azure Monitor is the parent service that includes Log Analytics.

754
MCQmedium

Your organization is designing a monitoring solution for a critical application running on Azure VMs. You need to collect performance metrics and logs from the VMs and send them to a centralized Log Analytics workspace. You also need to visualize the data in near real-time. Which combination of services should you use?

A.Azure Monitor Agent and Azure Workbooks
B.Azure Diagnostics extension and VM Insights
C.Azure Monitor Agent and Azure Sentinel
D.Log Analytics Agent and Azure Dashboards
AnswerA

Azure Monitor Agent (AMA) is the current, unified data collection agent for Azure Monitor, replacing the legacy Log Analytics and Diagnostics agents. It uses data collection rules (DCRs) to route VM telemetry into a Log Analytics workspace with low overhead and support for near real-time streaming. Azure Workbooks then provide interactive, customizable visualizations and queries over that data, making this combination ideal for a modern monitoring and visualization solution.

Why this answer

Azure Monitor Agent is the current recommended agent for collecting performance metrics and logs from Azure VMs and sending them to a Log Analytics workspace. Azure Workbooks provide interactive, near real-time visualizations by querying the workspace data. This combination meets the requirements for centralized collection and visualization without unnecessary overhead.

Exam trap

The trap here is confusing Azure Sentinel (a SIEM) with Azure Monitor (a general monitoring solution), leading candidates to select a security-focused tool for a performance monitoring requirement.

How to eliminate wrong answers

Option B is wrong because VM Insights uses the Azure Monitor Agent (or legacy Log Analytics agent) to collect data, but it is a monitoring solution focused on VM health and dependencies, not a direct tool for building custom near real-time visualizations; the Diagnostics extension is legacy and does not send data to Log Analytics by default. Option C is wrong because Azure Sentinel is a SIEM (Security Information and Event Management) tool designed for security analytics and threat detection, not for general performance monitoring and visualization. Option D is wrong because the Log Analytics Agent is legacy and being deprecated in favor of Azure Monitor Agent, and Azure Dashboards are static views that do not support interactive near real-time querying like Workbooks do.

755
MCQhard

A media company uploads large video files to Azure Blob Storage. Users frequently access recent videos, while older videos are rarely accessed after 30 days. The company wants to minimize storage costs while ensuring that recently accessed videos are immediately available. Which storage tier strategy should you recommend?

A.Use Premium tier for all files
B.Use Cool tier for all files with lifecycle management to Archive
C.Use Hot tier for the first 30 days, then automatically move to Cool tier
D.Use Archive tier for all files and rehydrate on access
AnswerC

Hot tier for the first 30 days gives immediate low-latency access during the peak viewing and editing window, and the lifecycle rule fires automatically to transition blobs to Cool after the access pattern cools down. Cool tier then cuts storage cost by roughly 40-50% while still offering sub-second latency for occasional replays. Because lifecycle evaluation runs once per day, the rule must be set to '30 days after last modification' to avoid a 31-day gap; this simple policy balances cost and availability without manual intervention.

Why this answer

It balances cost and performance by using the Hot tier for the first 30 days (when videos are frequently accessed) and then automatically transitioning to the Cool tier via Azure Blob Storage lifecycle management. This ensures immediate availability for recent uploads while minimizing storage costs for older, rarely accessed content. The Cool tier offers lower storage costs than Hot but still provides low-latency access, meeting the requirement that recently accessed videos are immediately available.

Exam trap

The trap here is that candidates may assume Cool tier is always the cheapest option for infrequent access, but they overlook that Archive tier, while cheaper, introduces unacceptable rehydration delays for the 'immediately available' requirement, and that Hot tier is necessary for the initial high-access period to avoid access costs and latency.

How to eliminate wrong answers

Option A is wrong because using Premium tier for all files incurs significantly higher costs (designed for high transaction rates and low latency) without any cost optimization for rarely accessed older videos. Option B is wrong because using Cool tier from the start means recently uploaded videos (accessed frequently) are stored in a tier optimized for infrequent access, which has higher access costs and may introduce latency on first access compared to Hot tier. Option D is wrong because Archive tier has the lowest storage cost but requires rehydration (which can take up to 15 hours) before videos can be accessed, violating the requirement that recently accessed videos are immediately available.

756
MCQhard

Your organization is deploying a critical application in Azure that must maintain an uptime SLA of 99.99%. The application runs on Azure Virtual Machines in a single region. You need to design a monitoring solution that alerts the operations team within 5 minutes of any VM unavailability. The solution must minimize false positives and avoid alert fatigue. What should you include in the design?

A.Configure Azure Monitor VM insights with availability metric alerts set to fire when the VM is unavailable for 2 out of the last 5 minutes.
B.Create an Azure Service Health alert for the 'Virtual machine' service.
C.Create an Azure Monitor alert based on the Activity Log for 'Virtual Machine Guest OS Unresponsive' events.
D.Deploy the Log Analytics agent on each VM and create an alert for when heartbeat data is missing for 5 minutes.
AnswerA

VM insights availability metric uses a combination of VM heartbeat and compute state to produce a rolling availability percentage. Alerting on 2 unavailable minutes out of the last 5 reliably signals sustained unavailability while ignoring transient network or agent blips. This dynamic-threshold approach directly measures the VM's availability and is the most precise option for a critical application requiring immediate detection of downtime.

Why this answer

VM insights availability metric alerts use the 'VM Availability' metric (a composite metric from the Azure Monitor agent) that tracks the VM's running state. Configuring it to fire when the VM is unavailable for 2 out of the last 5 minutes provides a 2-minute evaluation window, which balances the 5-minute notification requirement with a tolerance for transient blips, minimizing false positives. This approach directly monitors the VM's availability at the hypervisor level without relying on guest OS signals, ensuring reliable uptime detection for the 99.99% SLA.

Exam trap

The trap here is that candidates often confuse guest OS-level monitoring (heartbeats or guest OS events) with hypervisor-level availability monitoring, leading them to choose options that depend on the guest OS being responsive, which fails when the VM is truly unavailable.

How to eliminate wrong answers

Option B is wrong because Azure Service Health alerts notify about Azure service-level issues (e.g., regional outages or platform maintenance), not individual VM unavailability, so they cannot detect a single VM going down within 5 minutes. Option C is wrong because the Activity Log alert for 'Virtual Machine Guest OS Unresponsive' events relies on the guest OS to report its own unresponsiveness, which can fail if the OS is completely hung or the agent is down, leading to missed alerts and false negatives. Option D is wrong because the Log Analytics agent heartbeat alert (missing for 5 minutes) introduces a delay of at least 5 minutes before firing, and the heartbeat is sent every 60 seconds by default, so a 5-minute absence window could miss the 5-minute notification target and may generate false positives if the agent is slow to report.

757
MCQhard

Refer to the exhibit. You are analyzing a deployment of Azure Storage account with customer-managed key encryption. The deployment fails with an error indicating that the key vault is not accessible. Which of the following is the most likely cause?

A.The key vault name is misspelled in the keyUri
B.The key vault has a firewall enabled and does not allow access from the storage account
C.The key vault is in a different Azure region than the storage account
D.The user-assigned managed identity does not have permissions to access the key
AnswerD

For a storage account using a customer-managed key with a user-assigned managed identity, that identity must be explicitly granted at least get, wrapKey, and unwrapKey permissions on the key vault through an access policy or Azure RBAC (for example, the 'Key Vault Crypto Service Encryption User' role). Without these key-level permissions, Azure Storage cannot retrieve the encryption key or perform wrap/unwrap operations, resulting in a 403 Forbidden error when the storage account attempts to access the keyUri. This matches the symptom and is the correct root cause when other configuration settings like network rules and key version are verified correct.

Why this answer

When using customer-managed keys (CMK) with Azure Storage encryption, the storage account must authenticate to the key vault to retrieve the key. If a user-assigned managed identity is specified in the encryption policy, that identity must have at least 'Get', 'Wrap Key', and 'Unwrap Key' permissions on the key vault. Without these permissions, the storage account cannot access the key, resulting in a deployment failure with a 'key vault not accessible' error.

Exam trap

The trap here is that candidates often assume the error is due to a network firewall or a naming mistake, but Azure explicitly requires the managed identity to have cryptographic permissions on the key vault, and the error message 'not accessible' is a generic wrapper for permission failures.

How to eliminate wrong answers

Option A is wrong because a misspelled keyUri would cause a different error (e.g., 'KeyVaultKeyNotFound' or 'InvalidKeyUri'), not a generic 'key vault not accessible' error; the error message specifically indicates the vault itself is unreachable, not that the key name is incorrect. Option B is wrong because while a key vault firewall can block access, the error message 'key vault is not accessible' in the context of CMK deployment typically points to a permissions issue rather than a network restriction; if the firewall were the cause, the error would more likely indicate a network connectivity failure or a 'Forbidden' response. Option C is wrong because Azure Key Vault and Azure Storage can be in different regions when using CMK; there is no regional dependency requirement for this integration.

758
MCQmedium

A company runs a critical application on Azure VMs in a single region. The application writes data to Azure SQL Database (PaaS) and Azure Blob Storage. The company needs a disaster recovery plan with an RPO of less than 5 minutes for the database and less than 15 minutes for the blob storage, and an RTO of less than 1 hour for the entire solution. What should they recommend?

A.Use Azure Site Recovery for VMs, geo-replication for Azure SQL Database, and geo-redundant storage (GRS) for Blob Storage.
B.Use Azure Backup for VMs, geo-redundant storage for SQL Database backups, and geo-redundant storage for Blob Storage.
C.Use Azure Site Recovery for VMs, active geo-replication for Azure SQL Database, and read-access geo-redundant storage (RA-GRS) for Blob Storage.
D.Use Azure Front Door with multi-region deployment of VMs and Azure Cosmos DB for the database.
AnswerC

ASR replicates VMs with minutes RPO. Active geo-replication for Azure SQL Database provides a readable secondary with RPO seconds. RA-GRS provides a readable copy in the secondary region with ~15 minute RPO, meeting the blob requirement.

Why this answer

Azure Site Recovery provides the VM replication needed to meet the RTO of under 1 hour, active geo-replication for Azure SQL Database offers a configurable RPO of as low as 5 seconds (well under the 5-minute requirement), and RA-GRS for Blob Storage provides read-access to a secondary region with an RPO typically under 15 minutes, enabling fast failover and read access during a disaster.

Exam trap

The trap here is that candidates often confuse geo-redundant storage (GRS) with read-access geo-redundant storage (RA-GRS), not realizing that GRS requires a storage account failover to access the secondary region, which can take up to an hour and thus fails the RTO requirement.

How to eliminate wrong answers

Option A is wrong because geo-redundant storage (GRS) for Blob Storage does not provide read access to the secondary region during a disaster; you must initiate a failover to read data, which can exceed the RTO of 1 hour. Option B is wrong because Azure Backup for VMs is a backup solution, not a replication solution, and cannot achieve an RTO of under 1 hour for full VM failover; additionally, geo-redundant storage for SQL Database backups does not provide the sub-5-minute RPO required, as backups are typically taken every 5–10 minutes. Option D is wrong because Azure Front Door with multi-region VMs and Cosmos DB does not address the existing Azure SQL Database and Blob Storage requirements; it changes the architecture entirely and does not meet the stated RPO/RTO for the current services.

759
MCQmedium

Your company has a critical application that uses Azure Kubernetes Service (AKS) in a single region. You need to design a disaster recovery solution that can automatically fail over to a secondary region in the event of a regional outage. The application data is stored in Azure Cosmos DB. What should you do?

A.Use Azure Front Door to route traffic to the primary AKS cluster and enable Cosmos DB automatic failover.
B.Use Azure Backup for AKS with cross-region restore and Cosmos DB geo-redundancy.
C.Replicate the AKS cluster to another region using Azure Site Recovery.
D.Deploy a secondary AKS cluster in another region, use Azure Traffic Manager for global load balancing, and enable Cosmos DB multi-region writes.
AnswerD

Deploying a secondary AKS cluster in another region provides compute placement outside the primary region's blast radius, and Azure Traffic Manager uses DNS-based routing to automatically direct user traffic to the healthy cluster when health probes detect a regional failure. Enabling Cosmos DB multi-region writes creates an active-active data platform where both AKS clusters can read and write local replicas, eliminating a single point of failure for data. This combination achieves regional failover at both compute and data layers, satisfying strict RTO/RPO requirements without manual intervention.

Why this answer

It provides a comprehensive disaster recovery solution for both the compute and data tiers. Deploying a secondary AKS cluster in another region ensures compute capacity is available after a regional outage. Azure Traffic Manager (using priority routing) directs traffic to the primary cluster and automatically fails over to the secondary.

Enabling Cosmos DB multi-region writes allows the application to write to the secondary region without conflict, ensuring data availability and consistency during failover.

Exam trap

The trap here is that candidates often confuse Azure Front Door (which is for global HTTP load balancing with acceleration) with Azure Traffic Manager (which is for DNS-based global traffic routing and failover), and they overlook that AKS clusters cannot be replicated via Azure Site Recovery because it is designed for VM-level replication, not container orchestration platforms.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global load balancer for HTTP/S traffic but does not natively support automatic failover for AKS clusters; it would require manual configuration or custom health probes, and enabling Cosmos DB automatic failover alone does not address the compute tier's availability. Option B is wrong because Azure Backup for AKS with cross-region restore is a backup solution, not an automated failover mechanism; it involves restoring from backups, which incurs significant recovery time (RTO) and does not provide real-time failover. Option C is wrong because Azure Site Recovery is designed for IaaS VMs, not for AKS clusters; it cannot replicate Kubernetes control planes, node pools, or containerized workloads effectively, and it does not support Cosmos DB data replication.

760
MCQhard

A global e-commerce company uses Azure Cosmos DB to store its product catalog. The catalog is read-heavy, with users worldwide expecting consistent reads with a 99th percentile latency under 10 ms. Writes to the catalog are performed by a central admin team in one region. The company needs to minimize write latency and cost while ensuring that users always see the same data within a single session. Which Cosmos DB configuration should the company choose?

A.Single-master write region with Strong consistency and multiple read regions
B.Multi-master write with Eventual consistency and all regions enabled for writes
C.Single-master write region with Session consistency and multiple read regions
D.Multi-master write with Strong consistency and two regions
AnswerC

Session consistency deployed with a single-master write region and multiple read regions is the optimal balance: all writes are sent to one regional endpoint, minimizing write latency and avoiding cross-region conflict resolution. The Cosmos DB SDK manages session tokens to ensure that within the same user session, reads are served from any read region yet still reflect the most recent writes performed in that session, satisfying the requirement for session consistency. This design provides low-latency reads globally for the e-commerce workload, where users access the application from various geographic regions, without the cost or complexity of multi-master writes.

Why this answer

Session consistency provides the required 'read your own writes' guarantee within a single session, which ensures users always see the same data during their session without the latency and cost penalties of Strong consistency. Single-master writes minimize write latency by directing all writes to one region (the central admin team's region), while multiple read regions allow global users to read from the nearest region with sub-10 ms latency. This configuration balances cost, performance, and consistency needs for a read-heavy catalog with centralized writes.

Exam trap

The trap here is that candidates often confuse 'strong consistency' with 'always correct' and overlook that Session consistency is sufficient for per-session guarantees, while Strong consistency adds unnecessary latency and cost for a read-heavy catalog with centralized writes.

How to eliminate wrong answers

Option A is wrong because Strong consistency with multiple read regions requires all replicas to acknowledge reads, which increases read latency and cost, and does not minimize write latency as writes must still propagate synchronously to all read regions. Option B is wrong because Multi-master writes with Eventual consistency would allow writes from any region, but the central admin team writes from one region, and eventual consistency does not guarantee that users see their own writes within a session, violating the 'same data within a single session' requirement. Option D is wrong because Multi-master writes with Strong consistency across two regions would introduce high write latency (due to synchronous replication) and increased cost, while the scenario only needs single-master writes from one admin region.

761
MCQmedium

A multinational company plans to deploy a new application on Azure. The application must comply with GDPR and requires data residency in the EU. The solution should minimize latency for users in Europe and provide disaster recovery across regions. Which Azure architecture should the company implement?

A.Deploy the application in two EU regions with Azure Front Door and Azure SQL Database geo-replication.
B.Deploy the application in a single Azure region in Ireland with Azure Site Recovery for DR.
C.Deploy the application in two EU regions with Azure Traffic Manager and Azure Cosmos DB multi-region writes.
D.Deploy the application in a single EU region with Azure Site Recovery and Azure Redis Cache.
AnswerC

This option correctly satisfies both the low-latency and EU-data-residency requirements. Azure Traffic Manager performs DNS-based traffic routing to the nearest available regional endpoint, so users are directed to the closest of the two EU-deployed regions, reducing network round-trip time, while Azure Cosmos DB in multi-region write mode allows the application to write and read in either EU region with replication confined to the configured EU geography. Because Cosmos DB multi-region writes provide active-active replication with automatic failover and 99.999% availability, the solution achieves resilience across two EU regions without requiring cross-region data egress. Traffic Manager and Cosmos DB together give both geo-routing and globally distributed data plane behavior, but when all regions are within the EU, data stays inside EU boundaries.

Why this answer

It meets all requirements: deploying in two EU regions ensures data residency within the EU, Azure Traffic Manager provides low-latency routing for European users via DNS-based traffic distribution, and Azure Cosmos DB multi-region writes enable active-active disaster recovery with automatic failover and no data loss, minimizing latency for writes across regions.

Exam trap

The trap here is that candidates often confuse Azure Front Door (HTTP/HTTPS layer 7) with Azure Traffic Manager (DNS layer 4) and assume SQL Database geo-replication provides zero data loss, but Cosmos DB multi-region writes are the only option that guarantees RPO=0 for active-active DR across EU regions.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database geo-replication is asynchronous, which can lead to data loss during a disaster (RPO > 0), and Azure Front Door is primarily an HTTP/HTTPS load balancer with global anycast, not optimized for DNS-based regional failover as required for disaster recovery across two EU regions. Option B is wrong because deploying in a single region violates the disaster recovery requirement; Azure Site Recovery alone cannot provide cross-region DR without a secondary region, and a single region cannot ensure low latency for all European users. Option D is wrong because a single EU region fails to meet the disaster recovery requirement, and Azure Redis Cache is an in-memory cache that does not provide data persistence or geo-replication for DR, nor does it address multi-region latency.

762
MCQhard

A business-critical App Service application must survive a full regional outage. The recovery design should fail over automatically based on endpoint health and avoid DNS-cache delay where possible. Which service should front the regional deployments?

A.Azure Load Balancer
B.Azure Application Security Groups
C.Azure Front Door
D.Azure Traffic Manager only
AnswerC

Azure Front Door is a global, cloud-native entry point that provides HTTP/S load balancing, SSL offload, path-based routing, and—critically—health-probe-driven automatic failover across multiple regions. By continuously probing the health of backends, Front Door can detect a regional outage and route traffic to the nearest healthy regional endpoint, typically in seconds, without relying on client DNS cache timeouts. It also supports session affinity, URL rewrite, and Web Application Firewall (WAF) policies, making it the correct choice for a business-critical web app that must survive a full region failure.

Why this answer

Azure Front Door is the correct choice because it provides global HTTP/HTTPS load balancing with automatic failover across regions based on real-time endpoint health probes. It uses Anycast routing to direct traffic to the nearest healthy region, which avoids DNS-cache delay inherent in DNS-based solutions like Traffic Manager. This ensures sub-second failover and meets the requirement for a business-critical app that must survive a full regional outage.

Exam trap

The trap here is that candidates confuse Azure Traffic Manager's DNS-based global routing with Azure Front Door's Anycast-based global routing, overlooking the critical DNS-cache delay that Traffic Manager introduces.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 and is regional, not global; it cannot fail over traffic across regions in a full regional outage. Option B is wrong because Azure Application Security Groups are a network security feature for grouping VMs and applying security rules, not a traffic routing or failover service. Option D is wrong because Azure Traffic Manager is DNS-based and relies on client DNS caching, which can cause delays of minutes during failover, violating the requirement to avoid DNS-cache delay.

763
MCQhard

A company stores petabytes of image files for a content delivery network. The images are accessed frequently for the first week, then rarely afterward. They must be retained for 5 years for compliance. The company wants to minimize storage costs while maintaining performance for frequently accessed data. Which storage solution and tier strategy should they recommend?

A.Azure Blob Storage with a lifecycle policy: Hot for 7 days, Cool for the remainder of 5 years
B.Azure Files with premium tier
C.Azure Data Lake Storage Gen2 with hot tier only
D.Azure Blob Storage with archive tier from day 1
AnswerA

This is correct because Azure Blob Storage is optimized for serving large volumes of static objects over HTTP/S to Azure CDN or Front Door, and its lifecycle management feature automates movement between access tiers based on blob age. Setting a rule for Hot for 7 days matches the period of heavy read traffic, after which transitioning to Cool for the remaining 5 years dramatically reduces storage cost while still providing sub-second latency for occasional access. The lifecycle policy evaluates each blob's last modification date and enforces the tier change without manual intervention, exactly fitting a cost-sensitive archive-with-fast-recent-access pattern.

Why this answer

Azure Blob Storage with a lifecycle policy is the correct solution because it automatically transitions blobs from the Hot tier (for frequent access during the first week) to the Cool tier (for rare access over the remaining 5 years), minimizing storage costs while maintaining low-latency performance for the initial high-access period. The Hot tier provides high throughput and low access costs for frequently read data, while the Cool tier offers lower storage costs for infrequently accessed data, meeting both performance and compliance retention requirements.

Exam trap

The trap here is that candidates often choose the Archive tier for long-term retention without considering the performance impact of frequent access during the first week, overlooking that Archive requires hours to rehydrate and incurs high read costs, making it unsuitable for the initial high-access period.

How to eliminate wrong answers

Option B is wrong because Azure Files with premium tier uses SSD-backed file shares designed for low-latency enterprise workloads (e.g., SQL Server, home directories), not for petabyte-scale image content delivery; it is cost-prohibitive for long-term retention and lacks native lifecycle tiering to reduce costs. Option C is wrong because Azure Data Lake Storage Gen2 with hot tier only provides no cost optimization for rarely accessed data after the first week, leading to unnecessarily high storage costs for 5 years of compliance retention. Option D is wrong because Azure Blob Storage with archive tier from day 1 would impose high retrieval costs and multi-hour rehydration latency for images that are frequently accessed during the first week, violating the performance requirement for the initial access period.

764
MCQhard

A multinational company runs a mission-critical application on Azure VMs in the West US region. The application uses Azure SQL Database (Business Critical tier) and Azure Cache for Redis. The company needs to ensure the application can fail over to a secondary region within 5 minutes during a regional outage. The design must minimize data loss. Which solution should you recommend?

A.Deploy VMs across Azure availability zones in West US, use Azure SQL Database geo-restore to East US, and deploy a second Azure Cache for Redis instance in East US.
B.Deploy VMs in an availability set in West US, use Azure Site Recovery to replicate to East US, and configure Azure SQL Database failover group with manual failover.
C.Deploy VMs in an Azure Site Recovery recovery plan to East US, use Azure SQL Database active geo-replication with auto-failover group, and deploy Azure Cache for Redis Standard tier in East US.
D.Deploy VMs in an Azure Site Recovery recovery plan to East US, use Azure SQL Database active geo-replication with auto-failover group, and use Azure Cache for Redis with geo-replication enabled.
AnswerD

Azure Site Recovery orchestrates VM failover to East US within minutes, while active geo-replication with auto-failover groups provides the SQL Database secondary and minimal data loss. Redis geo-replication completes the stack, meeting the five-minute regional failover constraint.

Why this answer

It ensures all components can fail over to East US within 5 minutes with minimal data loss. Azure Site Recovery (ASR) provides orchestrated VM replication with RTO typically under 5 minutes. Azure SQL Database active geo-replication with auto-failover groups offers RPO of 5 seconds and RTO of ~1 minute, meeting the 5-minute target and minimizing data loss.

Azure Cache for Redis geo-replication (Premium tier) replicates cache data asynchronously, providing a warm standby cache in East US to reduce data loss. Option A fails because availability zones do not protect against a regional outage and geo-restore has longer RTO. Option B uses availability sets (no regional protection) and manual failover for SQL (exceeds 5 minutes).

Option C uses Standard tier Redis which lacks geo-replication, leading to data loss.

Exam trap

The trap here is that candidates often assume any Azure Cache for Redis tier supports geo-replication, but only the Premium tier offers this feature, making option C a common distractor.

How to eliminate wrong answers

Option A is wrong because geo-restore for Azure SQL Database has an RTO of hours (not minutes) and does not support automated failover, and deploying a second Redis instance without geo-replication does not provide automatic data synchronization or failover. Option B is wrong because Azure SQL Database failover group with manual failover requires human intervention, which can exceed the 5-minute RTO, and availability sets only protect against rack-level failures within a single region, not regional outages. Option C is wrong because Azure Cache for Redis Standard tier does not support geo-replication (only Premium tier does), so cache data would be lost during failover, violating the minimize data loss requirement.

765
MCQhard

You are designing a governance strategy for an Azure environment that includes multiple subscriptions. The security team requires that all storage accounts must have HTTPS traffic only. Any non-compliant storage account must be automatically remediated. What is the most efficient solution?

A.Create an Azure Blueprint that includes a policy initiative
B.Assign a custom RBAC role that denies creation of storage accounts without HTTPS
C.Use Azure Policy with a DeployIfNotExists effect to enable HTTPS-only traffic
D.Configure Azure Monitor alerts to notify the security team
AnswerC

Azure Policy with the DeployIfNotExists effect evaluates every existing resource against the definition and automatically triggers a remediation task to deploy the required configuration — in this case, setting the 'supportsHttpsTrafficOnly' property to true. This effect uses a managed identity to apply the change, and it can be run on-demand via a remediation task or on a schedule, ensuring all non-compliant storage accounts are brought into compliance without manual intervention. This is the only option that provides automated, continuous enforcement and correction for resources already in the subscription.

Why this answer

Azure Policy with a DeployIfNotExists effect can automatically remediate non-compliant storage accounts by enabling the 'HTTPS traffic only' property. This approach ensures continuous compliance without manual intervention, meeting the security team's requirement for automatic remediation.

Exam trap

The trap here is that candidates often confuse Azure Policy's DeployIfNotExists effect with Azure Blueprints, assuming Blueprints can also remediate, but Blueprints only enforce initial compliance and do not provide ongoing automatic remediation for existing resources.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used to orchestrate the deployment of resource groups, policies, role assignments, and ARM templates, but they do not automatically remediate non-compliant resources after deployment; they only enforce initial compliance. Option B is wrong because a custom RBAC role that denies creation of storage accounts without HTTPS would only prevent new non-compliant accounts from being created, but it would not remediate existing non-compliant storage accounts. Option D is wrong because Azure Monitor alerts only notify the security team of non-compliance; they do not automatically remediate the issue, which is a core requirement of the question.

766
MCQhard

You are designing a network topology for a global e-commerce company that operates multiple web applications. The company has three main offices (New York, London, Tokyo) connected via ExpressRoute to Azure. Users access the applications through a public endpoint. The company requires that traffic be routed to the nearest healthy application instance based on geographic location, and that the solution provide automatic failover if an entire region goes down. Additionally, the company wants to protect against DDoS attacks at the network layer. You need to recommend a solution that meets these requirements while minimizing cost. What should you include in the design?

A.Deploy Azure Front Door with geographic routing and enable DDoS protection.
B.Deploy Azure Firewall in each region and use Public IP prefix for egress.
C.Deploy Azure Application Gateway v2 with WAF in each region and Azure DDoS Standard protection.
D.Deploy Azure Traffic Manager with geographic routing and Azure DDoS Standard protection.
AnswerA

Azure Front Door is the correct choice for a global e-commerce topology because it operates as a single anycast global endpoint, automatically routing users to the nearest region via its distributed edge network. It natively supports geographic routing to enforce data residency or direct customer traffic based on country/region, and it integrates with Azure WAF and Azure DDoS Standard, providing both L7 and L3/L4 protection at the edge. This combination gives you global load balancing, low-latency access, and comprehensive security without needing to manage per-region ingress gateways.

Why this answer

Azure Front Door with geographic routing directs users to the nearest healthy application instance based on geographic location, and it provides automatic failover if an entire region goes down by routing traffic to the next closest healthy region. Front Door also includes built-in DDoS protection at the network layer (Azure DDoS Basic) at no additional cost, which meets the DDoS requirement while minimizing cost. This combination satisfies all requirements without the need for separate, more expensive services.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager with Azure Front Door, assuming Traffic Manager's geographic routing and DNS-level failover are sufficient, but they overlook that Traffic Manager lacks built-in DDoS protection and application-layer features, and that Front Door provides a more cost-effective all-in-one solution for global load balancing with DDoS protection.

How to eliminate wrong answers

Option B is wrong because Azure Firewall is a stateful firewall for controlling outbound and inbound traffic, not a global load balancer with geographic routing, and it does not provide automatic failover across regions or DDoS protection at the network layer. Option C is wrong because Azure Application Gateway v2 is a regional load balancer that cannot route traffic based on geographic location across global regions, and while it supports WAF, it requires Azure DDoS Standard (which incurs additional cost) to protect against network-layer DDoS attacks. Option D is wrong because Azure Traffic Manager with geographic routing can route based on location and provide failover, but it does not include built-in DDoS protection; you would need to add Azure DDoS Standard separately, increasing cost, and Traffic Manager operates at the DNS level, not at the application layer, which can introduce latency and lacks features like SSL offloading and caching that Front Door provides.

767
MCQeasy

Your organization has 500 users in Microsoft Entra ID. You need to ensure that users can only access Microsoft 365 apps from compliant devices (compliant with Intune policies). Users are already enrolled in Intune. The compliance policies are defined. You need to configure the access control mechanism. What should you do?

A.Create a Conditional Access policy that blocks all access and then create exclusions for compliant devices.
B.Configure Intune compliance policies to automatically revoke access for non-compliant devices.
C.Create a Conditional Access policy that requires device to be marked as compliant.
D.Create a Conditional Access policy that requires MFA based on location.
AnswerC

This is the intended pattern because Conditional Access acts as the enforcement engine: setting the grant control 'Require device to be marked as compliant' forces Entra ID to check the device's compliance claim issued by Intune before issuing a token. If the device is non-compliant or unenrolled, access is denied, and the user may be redirected to remediation. This precisely matches the requirement that only compliant devices can access Microsoft 365 applications.

Why this answer

Conditional Access in Microsoft Entra ID is the mechanism that enforces access controls based on signals like device compliance. By creating a policy that requires the device to be marked as compliant, you ensure that only devices meeting Intune compliance policies can access Microsoft 365 apps. This directly addresses the requirement without blocking all access or relying on automatic revocation.

Exam trap

The trap here is that candidates confuse Intune compliance policies (which define rules) with the access control enforcement mechanism (Conditional Access), leading them to choose Option B, which incorrectly assumes compliance policies can directly revoke access without a Conditional Access policy.

How to eliminate wrong answers

Option A is wrong because blocking all access and then creating exclusions for compliant devices is an overly complex and error-prone approach; Conditional Access policies should grant access based on conditions, not block all and carve out exceptions. Option B is wrong because Intune compliance policies define the compliance criteria but do not enforce access control themselves; they rely on Conditional Access to block or allow access based on compliance status. Option D is wrong because requiring MFA based on location addresses authentication strength, not device compliance, and does not ensure that only compliant devices can access Microsoft 365 apps.

768
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They need to automatically block sign-ins from anonymous IP addresses (e.g., Tor) and force users from risky sign-ins to reset their password. They want to minimize administrative effort and use built-in features. Which Microsoft Entra ID feature should they enable?

A.Microsoft Entra ID Identity Protection risk policies (sign-in risk and user risk).
B.Conditional Access policies with locations and grant controls.
C.Microsoft Entra ID Privileged Identity Management (PIM).
D.Microsoft Entra ID Access Reviews.
AnswerA

Identity Protection includes built-in policies that automatically detect sign-in risks (including anonymous IP addresses) and user risks (e.g., leaked credentials). The sign-in risk policy can block the sign-in, and the user risk policy can require a password reset. This minimizes manual configuration.

Why this answer

Microsoft Entra ID Identity Protection provides built-in risk policies that automatically detect and block sign-ins from anonymous IP addresses (e.g., Tor) via the sign-in risk policy, and force password reset for users flagged with high user risk via the user risk policy. These policies operate without manual intervention, minimizing administrative effort while leveraging Premium P2 capabilities.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with Identity Protection risk policies, assuming that location-based blocking can replace dynamic risk detection, but Conditional Access lacks the built-in anonymous IP detection and automated password reset triggers that Identity Protection provides.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies with locations and grant controls can block IP ranges or require MFA, but they cannot natively detect anonymous IP addresses like Tor or automatically trigger password resets based on risk; they rely on static location definitions rather than dynamic risk signals. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and access reviews, not sign-in risk detection or password reset enforcement. Option D is wrong because Access Reviews are used for periodic attestation of group memberships or role assignments, not for real-time blocking of anonymous IPs or risk-based password resets.

769
MCQeasy

Your company is deploying a new application on Azure Kubernetes Service (AKS). You need to monitor the health and performance of the cluster, including container logs, metrics, and request rates. Which Azure service should you enable?

A.Azure Service Health
B.Azure Monitor for VMs
C.Azure Application Insights
D.Azure Monitor Container Insights
AnswerD

Microsoft Azure Monitor Container Insights is the purpose-built monitoring solution for Azure Kubernetes Service (AKS). It deploys a containerized Log Analytics agent to your cluster that scrapes node, pod, and container metrics (CPU, memory, disk, network), collects container stdout/stderr logs, and captures Kubernetes inventory and health status. This gives you a unified view of cluster infrastructure, plus integration with Azure Monitor alerts, workbooks, and Log Analytics queries for root-cause analysis—capabilities no other listed option provides.

Why this answer

Azure Monitor Container Insights is the correct service because it is specifically designed to monitor the health and performance of Azure Kubernetes Service (AKS) clusters. It collects container logs, metrics (such as CPU/memory usage), and request rates from the cluster via a containerized Log Analytics agent, providing visibility into the performance of workloads running on AKS.

Exam trap

The trap here is that candidates often confuse Azure Application Insights (which monitors application-level telemetry like requests and exceptions) with Container Insights (which monitors cluster-level health and container logs), leading them to choose C instead of D.

How to eliminate wrong answers

Option A is wrong because Azure Service Health provides a personalized dashboard of service issues, planned maintenance, and health advisories for Azure services, but it does not monitor the performance or logs of individual AKS clusters. Option B is wrong because Azure Monitor for VMs monitors the health and performance of virtual machines, not containerized workloads on AKS; it cannot collect container logs or request rates from Kubernetes pods. Option C is wrong because Azure Application Insights is an application performance management (APM) service for monitoring live web applications, not for collecting cluster-level metrics, container logs, or request rates from AKS infrastructure.

770
MCQhard

Your company has an Azure subscription with 100 virtual machines. You need to monitor the performance of these VMs and be alerted when the average CPU usage across a set of VMs exceeds 80% for 10 minutes. The set of VMs is defined by a tag (Environment=Production). Which Azure Monitor solution should you implement?

A.Use Azure Monitor VM Insights to visualize performance and set alerts per VM.
B.Create a metric alert rule with a dynamic threshold and scope it to a resource group containing Production VMs.
C.Create a metric alert rule with a static threshold of 80% for each Production VM individually.
D.Use a Log Analytics query to calculate average CPU and set a log alert.
AnswerD

A Log Analytics query aggregates CPU across the tag-scoped VMs and a log alert fires when the average exceeds 80% for 10 minutes. Metric alerts cannot natively average across a dynamic tag-defined VM set, so the query satisfies the grouping constraint.

Why this answer

The requirement is to alert when the average CPU usage across a set of VMs (tagged Environment=Production) exceeds 80% for 10 minutes. Metric alert rules (including dynamic thresholds) evaluate per resource, not across multiple resources. Option D uses a Log Analytics query to calculate the average CPU usage across all VMs with the specified tag and then creates a log alert based on that query, which correctly aggregates the metric.

Therefore, Option D is the correct solution.

Exam trap

The trap is that candidates often assume a metric alert rule scoped to a resource group with tag filtering can aggregate metrics across VMs. However, metric alerts evaluate each VM individually, not the average across the set. The correct approach is to use a Log Analytics query to compute the aggregate and trigger a log alert.

How to eliminate wrong answers

Option A is wrong because VM Insights provides per-VM performance visualization and alerts, but it does not natively support aggregating metrics across a set of VMs defined by a tag to trigger a single alert based on the average CPU usage. Option C is wrong because creating individual metric alert rules for each Production VM would require managing 100 separate rules, which is inefficient and does not aggregate the average CPU usage across the set; it would alert per VM, not based on the collective average. Option D is wrong because a Log Analytics query with a log alert would require sending performance data to Log Analytics, incurring additional ingestion costs and complexity, whereas a metric alert is simpler and more cost-effective for this scenario.

771
MCQeasy

A company stores log data in Azure Blob Storage. Logs are accessed frequently for the first 30 days, then rarely accessed but must be retained for 7 years for compliance. They want to minimize storage costs. Which storage tier and lifecycle management rule should they use?

A.Use the Cool tier for initial storage, and a lifecycle rule to move to Archive after 30 days.
B.Use the Hot tier for initial storage, and a lifecycle rule to move to the Cool tier after 30 days, then to Archive after 7 years.
C.Use the Hot tier for initial storage, and a lifecycle rule to move to Archive after 30 days.
D.Use the Archive tier for initial storage, and a lifecycle rule to move to Hot for the first 30 days.
AnswerC

Hot tier optimizes for frequent access during the first 30 days. Moving directly to Archive after 30 days minimizes storage cost during the long retention period, as Archive has the lowest storage cost for rarely accessed data.

Why this answer

The Hot tier is optimal for frequent access during the first 30 days, and a lifecycle rule moving directly to Archive after 30 days minimizes costs by immediately transitioning to the lowest-cost storage tier for long-term retention. The Archive tier is the most cost-effective for data that is rarely accessed and must be retained for 7 years, as it offers the lowest storage cost but higher retrieval latency and cost.

Exam trap

The trap here is that candidates may overcomplicate by adding an intermediate Cool tier (Option B) or incorrectly assume Archive can be used for initial storage (Option D), failing to recognize that direct transition to Archive after the hot period is the most cost-effective for long-term retention with minimal access.

How to eliminate wrong answers

Option A is wrong because using the Cool tier for initial storage is not cost-effective for frequently accessed logs; the Hot tier has lower access costs for frequent reads/writes, making it more economical for the first 30 days. Option B is wrong because moving to Cool after 30 days and then to Archive after 7 years incurs unnecessary transition costs and storage costs in Cool for 7 years, whereas direct transition to Archive after 30 days is cheaper for long-term retention. Option D is wrong because storing data initially in the Archive tier is impractical for frequent access; Archive has high retrieval latency (up to 15 hours) and high access costs, making it unsuitable for data accessed frequently in the first 30 days.

772
MCQmedium

A company must prevent non-compliant devices from accessing Exchange Online and SharePoint Online. Which design should you recommend?

A.Conditional Access policy requiring a compliant device.
B.Azure Firewall application rule.
C.Storage account network rule.
D.Resource lock on the Microsoft 365 tenant.
AnswerA

A Conditional Access policy that requires a compliant device works by evaluating the device's compliance state (reported by Intune or a mobile device management solution) as a grant control at the moment of Entra ID authentication. When a user attempts to reach Microsoft 365 apps such as Exchange Online or SharePoint Online, the policy checks that the device meets all compliance policies—like encryption, OS patch level, and jailbreak status—before issuing an access token. This is the correct approach because device compliance is an identity-driven signal that integrates directly with the Entra ID authentication and authorization pipeline, and it can be scoped to require this for all cloud app access.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) can enforce device compliance by integrating with Microsoft Intune. When a policy requires a compliant device, it checks the device's compliance status before granting access to Exchange Online and SharePoint Online, blocking non-compliant devices at the authentication layer. This is the correct design because it directly controls access to these cloud services based on device health.

Exam trap

The trap here is that candidates may confuse network-level controls (like Azure Firewall) with identity-driven access controls (like Conditional Access), assuming a firewall can filter SaaS traffic, but Azure Firewall cannot inspect or enforce device compliance for Microsoft 365 services.

How to eliminate wrong answers

Option B is wrong because Azure Firewall is a network-layer firewall for Azure virtual networks and cannot inspect or control access to SaaS applications like Exchange Online or SharePoint Online, which are accessed over the internet. Option C is wrong because Storage account network rules control access to Azure Blob, File, Queue, and Table storage, not to Microsoft 365 services like Exchange Online or SharePoint Online. Option D is wrong because a resource lock prevents accidental deletion or modification of an Azure resource but does not enforce any access control or device compliance requirements for Microsoft 365 tenants.

773
MCQeasy

A company plans to migrate a legacy web application to Azure. The application runs on multiple Windows virtual machines (VMs) in an availability set. The VMs must be exposed to the internet via a single endpoint that performs SSL termination and health checks. The load-balancing solution must preserve the original client IP address for logging purposes. Which Azure service should the company use?

A.Azure Load Balancer (Standard)
B.Azure Application Gateway v2
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway v2 is the appropriate choice because it is a regional layer-7 reverse proxy that terminates SSL/TLS at the gateway, offloading certificate management from the web servers. It supports cookie-based session affinity, URL-based routing, and a built-in web application firewall (WAF), while preserving the original client IP via the X-Forwarded-For request header. The v2 SKU also provides autoscaling, high availability, and a resilient static VIP, aligning well with a single-region legacy web application migration.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that supports SSL termination, health probes, and provides a single public endpoint. It preserves the original client IP address by inserting the X-Forwarded-For header in the HTTP request, which the backend VMs can read for logging. This meets all requirements: single internet-facing endpoint, SSL offload, health checks, and client IP preservation.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming that any load balancer can terminate SSL and preserve client IP, but only Layer 7 services can inspect HTTP headers and perform SSL offload natively.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer (Standard) operates at Layer 4 (TCP/UDP) and does not support SSL termination or HTTP-level health checks; it also preserves client IP only via Direct Server Return (DSR) mode, which is not suitable for SSL termination and adds complexity. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not perform SSL termination or health checks at the application layer; it only directs traffic based on DNS resolution and cannot preserve the original client IP in the HTTP headers. Option D is wrong because Azure Front Door is a global Layer 7 service that does support SSL termination and health checks, but it is designed for global distribution and CDN scenarios, not for a single regional endpoint; it also modifies the client IP by default (inserting X-Forwarded-For but also adding its own IP), which can complicate logging if only a single regional endpoint is needed.

774
MCQeasy

Your company uses Microsoft Entra ID for identity management. You need to ensure that only devices compliant with your company's security policies can access corporate resources. Which solution should you implement?

A.Conditional Access with device compliance policies from Microsoft Intune
B.Microsoft Purview Information Protection
C.Microsoft Sentinel
D.Microsoft Defender XDR
AnswerA

Conditional Access with device compliance policies from Microsoft Intune is the correct answer because Condition Access is the policy engine in Microsoft Entra ID that evaluates signals—including whether a device is compliant—before granting access. Intune compliance policies enforce technical requirements like OS version, disk encryption, and jailbreak detection, and report compliance status to Entra ID. The Conditional Access grant control 'Require device to be marked as compliant' then blocks non-compliant devices from accessing corporate resources. This is the standard Microsoft mechanism for enforcing device compliance at authentication time.

Why this answer

Conditional Access in Microsoft Entra ID allows you to enforce access controls based on conditions, including device compliance. By integrating with Microsoft Intune, you can define device compliance policies (e.g., requiring encryption, a minimum OS version, or anti-malware status) and then configure a Conditional Access policy to block or grant access only to devices that are marked as compliant. This directly ensures that only compliant devices can access corporate resources.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (which handles threat detection) with device compliance enforcement, not realizing that Conditional Access with Intune is the specific mechanism to gate access based on device health.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., via encryption and rights management), not on controlling device-level access based on compliance. Option C is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) and Security Orchestration Automation and Response (SOAR) solution for threat detection and incident response, not for enforcing device compliance access policies. Option D is wrong because Microsoft Defender XDR (Extended Detection and Response) provides cross-domain threat detection and response across endpoints, email, and identities, but it does not natively enforce device compliance-based access control; that is the role of Conditional Access with Intune.

775
MCQmedium

A company deploys a containerized microservices application on Azure Kubernetes Service (AKS). They need to expose the application to the internet with TLS termination and provide a single endpoint for multiple services. The solution must also include a Web Application Firewall (WAF). Which Azure service should they use as the ingress controller?

A.Azure Application Gateway with WAF
B.Azure Front Door with WAF
C.Azure Load Balancer with TLS termination
D.Azure Traffic Manager with health probes
AnswerA

Azure Application Gateway with WAF is correct because the Application Gateway Ingress Controller (AGIC) runs inside AKS and watches Kubernetes Ingress resources, translating them into routing rules on the gateway. This allows TLS termination and WAF inspection at a single public endpoint, with L7 HTTP/S routing directly to the appropriate microservices. Unlike L4 or DNS-level services, it understands application paths, hostnames, and headers, making it a true ingress controller for AKS.

Why this answer

Azure Application Gateway with WAF is the correct choice because it is a regional, layer-7 load balancer that can act as an ingress controller for AKS. It provides TLS termination at the gateway and integrates a Web Application Firewall (WAF) to protect against common web exploits. This allows a single public endpoint to route traffic to multiple microservices within the AKS cluster based on URL paths or host headers.

Exam trap

The trap here is that candidates often confuse Azure Front Door (global, edge-based) with Application Gateway (regional, cluster-facing), assuming both can serve as an AKS ingress controller, but only Application Gateway integrates natively with AKS via AGIC for internal cluster routing.

How to eliminate wrong answers

Option B is wrong because Azure Front Door is a global, multi-region load balancer and application delivery controller, not a regional ingress controller for AKS; it is designed for global HTTP(S) load balancing and WAF at the edge, not for terminating TLS and routing directly into a single AKS cluster's internal services. Option C is wrong because Azure Load Balancer operates at layer 4 (TCP/UDP) and does not support TLS termination or WAF; it cannot inspect HTTP headers or perform path-based routing. Option D is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that operates at layer 3/4 and does not provide TLS termination, WAF, or HTTP-level routing; it only directs traffic to endpoints based on DNS resolution.

776
MCQhard

You are designing a storage solution for a healthcare application that stores patient records. The solution must meet the following requirements: - Support for both structured and unstructured data. - Provide low-latency access to frequently accessed data. - Automatically move cold data to a lower-cost tier. - Encrypt data at rest using customer-managed keys. Which combination of Azure services should you recommend?

A.Azure Table Storage for structured data and Azure Blob Storage for unstructured data
B.Azure Files for unstructured data and Azure SQL Database for structured data
C.Azure Blob Storage for unstructured data and Azure Cosmos DB for structured data
D.Azure Blob Storage for unstructured data and Azure SQL Database for structured data
AnswerC

Azure Blob Storage provides multiple access tiers and lifecycle management policies, enabling automated movement of unstructured data (e.g., medical images, text reports) to cool or archive storage based on age, significantly reducing costs. Azure Cosmos DB offers single-digit millisecond read/write latency for structured healthcare data, with guaranteed throughput and global distribution, which is essential for electronic health records and real-time patient monitoring. Both services support customer-managed keys (CMK) for encryption at rest, meeting the healthcare industry's strict compliance and security requirements.

Why this answer

Azure Cosmos DB provides low-latency access to structured data with multi-region writes and automatic indexing, while Azure Blob Storage handles unstructured data like medical images. Both services support encryption at rest with customer-managed keys via Azure Key Vault, and Blob Storage offers lifecycle management policies to automatically move cold data to lower-cost tiers like Cool or Archive.

Exam trap

The trap here is that candidates often assume Azure SQL Database is the only option for structured data, overlooking Cosmos DB's superior low-latency and global distribution capabilities, and they forget that Blob Storage's lifecycle management is the key to automated cold data tiering.

How to eliminate wrong answers

Option A is wrong because Azure Table Storage is a NoSQL key-value store that lacks the low-latency guarantees and global distribution of Cosmos DB, and it does not natively support customer-managed keys for encryption at rest. Option B is wrong because Azure Files is a fully managed file share for SMB protocol, not optimized for unstructured data like images or documents, and Azure SQL Database does not automatically tier cold data to lower-cost storage. Option D is wrong because Azure SQL Database, while supporting customer-managed keys, does not automatically move cold data to a lower-cost tier; it requires manual scaling or use of elastic pools, and it is not designed for unstructured data.

777
Multi-Selectmedium

Which THREE considerations are important when designing a data archiving solution for Azure Storage to optimize costs?

Select 3 answers
A.Use the hot tier for all data to ensure high performance.
B.Consider early deletion penalties for data moved to archive tier.
C.Account for data retrieval (rehydration) costs when accessing archived data.
D.Choose the appropriate access tier (hot, cool, or archive) based on access frequency.
E.Use geo-redundant storage (GRS) for all archive data.
AnswersB, C, D

The archive access tier in Azure Blob Storage carries a 180-day minimum billing period; if you delete a blob or move it to a hotter tier before 180 days, you are charged an early deletion fee equal to the remaining days of storage. This penalty exists because Microsoft prices archive storage on the assumption of long-term commitment, and the fee can easily erase any savings from tiering data down. Therefore, any lifecycle policy that archives data must include a retention analysis to avoid unexpected charges when data is retired prematurely.

Why this answer

Azure Archive tier has a minimum storage duration of 180 days; deleting or moving data before that incurs an early deletion penalty equal to the cost of the remaining days. This is critical for cost optimization as it prevents unexpected charges from short-lived data.

Exam trap

The trap here is that candidates often overlook early deletion penalties and rehydration costs, focusing only on the low storage price of archive tier, leading to unexpected charges when data is deleted or accessed prematurely.

778
MCQeasy

You are a Solutions Architect for an e-commerce company that runs its online store on Azure. The application consists of: - Azure App Service (Windows) hosting the web frontend - Azure SQL Database (General Purpose, serverless) for product catalog and orders - Azure Cache for Redis for session state - Azure Blob Storage for product images The application is deployed in the East US region. The company wants to implement a disaster recovery (DR) plan that can fail over to a secondary region (West US) with minimal data loss. The requirements are: - RPO: 5 minutes for the database - RTO: 30 minutes for the entire application - The solution must be cost-effective and not require manual intervention during failover. Which of the following is the BEST course of action to meet these requirements?

A.Use Azure Backup for the SQL database with 5-minute backup frequency, deploy App Service in West US with staging slots, and use Azure Traffic Manager with priority routing.
B.Configure Azure SQL Database geo-replication with readable secondary, deploy App Service in West US with deployment slots, and use Azure Front Door with health probes. Cache for Redis is not critical and can be rebuilt.
C.Configure Azure SQL Database active geo-replication with auto-failover group, deploy App Service in West US with a separate App Service plan, enable geo-replication for Cache for Redis, and use RA-GRS for Blob Storage. Use Azure Traffic Manager with priority routing for the web app.
D.Deploy the entire application in an active-active configuration using Azure Front Door, with Azure SQL Database using failover groups and manual failover. Use Azure Backup for the database with 1-hour backup frequency.
AnswerC

Active geo-replication with an auto-failover group meets the RPO requirement by continuously replicating changes to a secondary database with a typical RPO of 5 seconds and automating failover on regional outage, which keeps RTO low. A separate App Service plan in West US, combined with Azure Traffic Manager priority routing, ensures that the web tier can fail over to the secondary region automatically when the primary is unhealthy. Enabling geo-replication for Cache for Redis preserves session or cached data across regions, while RA-GRS for Blob Storage provides a secondary read-only copy of static assets such as images and product catalogs, which can tolerate a slightly higher RPO without affecting transactional integrity.

Why this answer

It meets all requirements: Azure SQL Database active geo-replication with auto-failover groups provides an RPO of 5 seconds (well within the 5-minute requirement) and automated failover without manual intervention. Deploying App Service in West US with a separate App Service plan ensures capacity for failover, and geo-replication for Cache for Redis preserves session state to avoid data loss. RA-GRS for Blob Storage provides read access in the secondary region, and Azure Traffic Manager with priority routing enables automatic failover of the web frontend within the 30-minute RTO.

Exam trap

The trap here is that candidates often confuse Azure SQL Database geo-replication (manual failover) with auto-failover groups (automatic failover), leading them to select Option B which fails the 'no manual intervention' requirement.

How to eliminate wrong answers

Option A is wrong because Azure Backup with 5-minute frequency cannot achieve an RPO of 5 minutes for Azure SQL Database (backup frequency is limited to 12 hours for SQL DB), and using staging slots for DR is not designed for automatic failover—they require manual swap and do not provide geo-redundancy. Option B is wrong because Azure SQL Database geo-replication with readable secondary does not support auto-failover groups; failover must be initiated manually, violating the 'no manual intervention' requirement. Option D is wrong because it uses manual failover for the database (violating the no-manual-intervention requirement) and Azure Backup with 1-hour backup frequency exceeds the 5-minute RPO; active-active configuration with Azure Front Door is unnecessary and increases cost without meeting the stated RPO.

779
MCQhard

Your company uses Azure SQL Database and needs to archive data older than 7 years for compliance. The archived data must be stored in the most cost-effective manner, must be immutable, and must be deleted exactly after 10 years. What should you use?

A.Azure Archive Storage with lifecycle management to delete after 10 years
B.Azure Blob Storage with immutable storage and time-based retention policy
C.Azure SQL Database restore to a point in time with a retention period of 10 years
D.Azure SQL Database long-term retention (LTR) backups
AnswerB

Azure Blob Storage with immutable storage enforces a write-once-read-many (WORM) policy that blocks any writes or deletes until the retention period expires. A time-based retention policy can be set to exactly 10 years, ensuring data cannot be altered or removed during that period and is automatically eligible for deletion only after the policy lapses, satisfying both archival and compliance needs.

Why this answer

Azure Blob Storage with immutable storage and a time-based retention policy ensures that archived data cannot be modified or deleted until the specified retention period expires. This meets the compliance requirements for immutability and a 10-year deletion timeline, while blob storage tiers (e.g., cool or archive) can be used for cost-effective long-term storage.

Exam trap

The trap here is that candidates often confuse Azure Archive Storage's low cost with immutability, failing to realize that immutability requires a separate WORM policy, which Archive Storage does not inherently provide.

How to eliminate wrong answers

Option A is wrong because Azure Archive Storage alone does not provide immutability; it only offers low-cost storage with lifecycle management for deletion, but without a write-once-read-many (WORM) policy, data could be altered or deleted prematurely. Option C is wrong because Azure SQL Database point-in-time restore has a maximum retention period of 35 days, not 10 years, and does not provide immutability. Option D is wrong because Azure SQL Database long-term retention (LTR) backups are not immutable; they can be manually deleted before the retention period ends, and they are stored as backups, not as an immutable archive.

780
MCQhard

A company has a hub-spoke network topology in Azure. They have multiple spoke VNets connected to a hub VNet via peering. They need to ensure that all east-west traffic between spoke VNets goes through a network virtual appliance (NVA) in the hub for inspection. Additionally, all outbound internet traffic from spoke VMs must use a single public IP address. What should they configure?

A.Configure spoke VNets with a default route to the NVA IP, and deploy a NAT gateway in the hub for outbound traffic.
B.Configure a route table in each spoke with a route to the hub NVA for inter-spoke traffic, and use Azure Firewall in the hub for outbound internet traffic.
C.Enable 'Allow gateway transit' on the hub VNet and 'Use remote gateways' on the spoke VNets for the NVA.
D.Configure VNet peering with 'Allow forwarded traffic' enabled, add user-defined routes in each spoke pointing to the NVA IP for inter-spoke traffic, and use Azure Firewall in the hub for outbound internet with a default route in spokes.
AnswerD

This is the correct design because the hub NVA is placed as a next-hop for inter-spoke traffic via user-defined routes (UDRs) in each spoke route table, and enabling 'Allow forwarded traffic' on the peering lets the NVA accept and route packets between the connected VNets. For outbound internet access, Azure Firewall in the hub provides centralized egress, and a default route (0.0.0.0/0) in the spoke UDRs sends internet-bound traffic to the firewall's private IP. This combination cleanly separates east-west (NVA) and north-south (firewall) traffic while meeting the requirement for a single public IP and controlled routing.

Why this answer

It combines two critical configurations: user-defined routes (UDRs) in each spoke VNet force inter-spoke traffic through the NVA in the hub by specifying the NVA's IP as the next hop, and 'Allow forwarded traffic' on the VNet peering enables the hub NVA to forward packets between spokes. For outbound internet traffic, Azure Firewall in the hub provides a single public IP, and a default route (0.0.0.0/0) in the spoke UDRs directs all internet-bound traffic to the Azure Firewall's private IP, ensuring centralized inspection and egress.

Exam trap

The trap here is that candidates often forget to enable 'Allow forwarded traffic' on the VNet peering, assuming UDRs alone are sufficient for transitive routing through an NVA, or they confuse 'Allow gateway transit' with NVA forwarding, which is a common misstep in hub-spoke design questions.

How to eliminate wrong answers

Option A is wrong because a NAT gateway in the hub does not inspect traffic; it only provides source network address translation (SNAT) for outbound connections, failing the inspection requirement. Option B is wrong because while it correctly uses Azure Firewall for outbound traffic, it omits the critical 'Allow forwarded traffic' setting on the VNet peering, without which the hub NVA cannot forward packets between spoke VNets even with UDRs in place. Option C is wrong because 'Allow gateway transit' and 'Use remote gateways' are used for VPN/ExpressRoute gateway sharing, not for routing traffic through an NVA; these settings do not force inter-spoke traffic through the NVA.

781
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant external partners access to an internal application for a limited time (30 days). The access request must be approved by a manager from the partner's organization, and after 30 days the access must automatically expire. They also want to send email reminders 7 days before expiration. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Entitlement Management
D.Microsoft Entra ID B2B with Conditional Access
AnswerC

Microsoft Entra ID Entitlement Management is the correct choice because it is specifically built to govern access to applications, groups, and SharePoint sites through access packages. Administrators can create access packages that include a partner's required app, define an approval workflow, and set an expiration date for each assignment, at which point access is automatically removed with optional reminder emails before expiry. External users from connected organizations can request access through the Microsoft Entra myaccess portal, and access reviews ensure continued need, making this the only option among those listed that fully supports time-limited external access with approvals and lifecycle governance.

Why this answer

Microsoft Entra ID Entitlement Management enables organizations to manage access for external partners through access packages, which can include time-limited assignments, approval workflows (including manager approval from the partner's organization), and automatic expiration with email notifications. This directly meets the requirement for a 30-day access period with manager approval and 7-day reminder emails.

Exam trap

The trap here is that candidates often confuse PIM (which handles privileged role activation for internal admins) with Entitlement Management (which handles external partner access with full lifecycle governance), or assume B2B with Conditional Access alone can enforce time limits and reminders without the access package framework.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Identity Protection is a security tool for detecting and responding to identity risks (e.g., compromised credentials, sign-in anomalies), not for managing time-limited external access with approvals and expiration. Option B is wrong because Microsoft Entra ID Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and oversight for internal users, not for granting external partner access to applications with manager approval from the partner's organization. Option D is wrong because Microsoft Entra ID B2B with Conditional Access provides guest user invitations and access policies, but it lacks built-in capabilities for time-limited access packages, multi-stage approval workflows, and automatic expiration with email reminders; these require Entitlement Management.

782
MCQeasy

You are designing a solution to securely store secrets, keys, and certificates for a cloud application. Which Azure service should you use?

A.Azure App Configuration
B.Azure Key Vault
C.Azure Managed HSM
D.Azure Storage
AnswerB

Azure Key Vault is the purpose-built service for securely storing secrets, encryption keys, and certificates, with granular access via Azure RBAC or vault access policies. It supports versioning, soft-delete, purge protection, and near-real-time audit logs through Azure Monitor, enabling tracking of every read, modify, and deletion operation. It is the correct choice because it is designed specifically for secret management and natively integrates with services like App Service, AKS, Azure Functions, and Logic Apps.

Why this answer

Azure Key Vault is the correct service because it is specifically designed to securely store and manage secrets, encryption keys, and certificates. It provides centralized control with hardware security module (HSM) backed keys, access policies, and audit logging, meeting the core requirement for a cloud application's secure storage.

Exam trap

The trap here is that candidates often confuse Azure App Configuration (which can store secrets with encryption but lacks HSM and key management features) with Azure Key Vault, or they over-engineer by choosing Azure Managed HSM when the simpler Key Vault meets the requirement for standard secret, key, and certificate storage.

How to eliminate wrong answers

Option A is wrong because Azure App Configuration is optimized for managing application configuration settings and feature flags, not for storing secrets, keys, or certificates; it lacks native HSM support and key rotation capabilities. Option C is wrong because Azure Managed HSM is a dedicated, single-tenant HSM solution for customers who require FIPS 140-2 Level 3 validated key management, but it is overkill and more expensive for general secret storage, and it does not natively store secrets or certificates as Azure Key Vault does. Option D is wrong because Azure Storage is a general-purpose object storage service for blobs, files, queues, and tables; it does not provide built-in access policies, key rotation, or HSM-backed encryption for secrets, and storing secrets there would require manual encryption and expose them to broader access risks.

783
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to require multi-factor authentication (MFA) for all users accessing the Azure portal, but do not want MFA to be required for other applications like Office 365. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Security defaults
B.Microsoft Entra ID Conditional Access
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Privileged Identity Management (PIM)
AnswerB

Conditional Access lets an administrator create a policy that targets the 'Microsoft Azure Management' cloud app, which is the service principal behind the Azure portal, and applies the 'Require MFA' grant control to assigned users or groups. This scopes MFA enforcement to Azure portal sign-ins only, leaving other applications with their own separate access policies. It is the appropriate mechanism because it directly maps the exact resource (Azure portal) to the required control (MFA) while allowing granular exclusions and conditions.

Why this answer

Conditional Access in Microsoft Entra ID allows granular control over authentication requirements based on conditions such as application, user, location, or device state. By creating a Conditional Access policy targeting the Azure Portal application and requiring MFA, the company can enforce MFA specifically for Azure Portal access without affecting other applications like Office 365, which can be excluded from the policy.

Exam trap

The trap here is that candidates often confuse Security defaults (which enforces MFA broadly) with Conditional Access (which provides granular application-specific control), leading them to choose Security defaults when the question explicitly requires selective enforcement.

How to eliminate wrong answers

Option A is wrong because Security defaults enforces MFA for all users across all applications, including Office 365, which does not meet the requirement to restrict MFA only to the Azure portal. Option C is wrong because Identity Protection is a risk-based detection and remediation service that can trigger MFA based on user or sign-in risk, but it cannot be configured to require MFA for a specific application like the Azure portal while excluding others. Option D is wrong because Privileged Identity Management (PIM) provides just-in-time privileged access and approval workflows, not the ability to enforce MFA selectively per application.

784
MCQhard

Refer to the exhibit. You are implementing an Azure Policy to control VM SKU deployment. You assign this policy to a subscription. A developer attempts to deploy a virtual machine with SKU Standard_DS2_v2. What is the outcome?

A.The deployment is audited and logged.
B.The deployment is allowed.
C.The VM is deployed but flagged as non-compliant.
D.The deployment is denied.
AnswerD

The policy's condition (if the VM SKU is not equal to Standard_D2s_v3) evaluates to true for the attempted SKU, and the then block applies the Deny effect. Azure Policy returns a 403 Forbidden or similar conflict, and the deployment fails. This is the intended hard enforcement for restricting VM SKUs in the assigned scope.

Why this answer

The Azure Policy in the exhibit uses a 'deny' effect, which explicitly blocks any deployment that does not match the allowed VM SKUs. Since Standard_DS2_v2 is not in the allowed list, the policy engine evaluates the request during deployment and rejects it before any resource is created. This results in the deployment being denied entirely, not just audited or flagged.

Exam trap

The trap here is that candidates confuse the 'deny' effect with 'audit' or 'disabled', assuming the policy only logs non-compliance or allows deployment with a flag, when in fact 'deny' actively blocks the resource creation.

How to eliminate wrong answers

Option A is wrong because an 'audit' effect would log the non-compliant deployment without blocking it, but the policy uses 'deny', not 'audit'. Option B is wrong because the policy explicitly denies any SKU not in the allowed list, so the deployment is not allowed. Option C is wrong because the VM is never deployed; the 'deny' effect prevents resource creation, so there is no VM to flag as non-compliant.

785
MCQmedium

You are designing a disaster recovery solution for a SQL Server database hosted on an Azure VM. The recovery point objective (RPO) is 5 minutes, and the recovery time objective (RTO) is 1 hour. Which strategy should you recommend?

A.Use Azure SQL Managed Instance with failover groups.
B.Configure log shipping to a secondary VM in another region.
C.Use Azure Backup to back up the database every 5 minutes.
D.Replicate the VM using Azure Site Recovery with 5-minute replication.
AnswerA

Failover groups in Azure SQL Managed Instance provide automated, regional replication of databases with a configurable replication policy, ensuring an RPO of zero seconds (or near-zero) and RTO of under a minute for unplanned failovers. The service handles primary/secondary role transitions and redirects connections to the new primary, meeting the stated RPO and RTO requirements without needing to manage a secondary VM. As a PaaS offering, it also includes built-in high availability and eliminates the operational overhead of manual log shipping or backup/restore processes.

Why this answer

Azure SQL Managed Instance with failover groups provides automated, synchronous or asynchronous replication of the database to a secondary region, enabling a Recovery Point Objective (RPO) of 5 minutes and a Recovery Time Objective (RTO) of 1 hour. The failover group handles automatic or manual failover at the instance level, ensuring minimal data loss and rapid recovery without complex manual log shipping or backup restoration.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery's 5-minute replication frequency with meeting database-level RPO, but Site Recovery replicates disk blocks, not SQL Server transaction log consistency, so it cannot guarantee a 5-minute RPO for database transactions without additional configuration like log shipping or Always On availability groups.

How to eliminate wrong answers

Option B is wrong because log shipping to a secondary VM in another region typically has an RPO of 15 minutes or more (depending on log backup frequency) and requires manual failover steps, making it unable to consistently meet a 5-minute RPO and 1-hour RTO. Option C is wrong because Azure Backup for SQL Server on Azure VM has a minimum backup frequency of 15 minutes for transaction log backups, not 5 minutes, and restoring from backups takes longer than 1 hour due to restore time and point-in-time recovery overhead. Option D is wrong because Azure Site Recovery replicates the entire VM at the disk level, not the database transaction logs, and its 5-minute replication frequency applies to disk changes, not SQL Server transaction log consistency, leading to potential data corruption or longer recovery times for database-consistent failover.

786
MCQmedium

A logistics company runs a customer-facing web application on 20 Azure VMs behind an Azure Standard Load Balancer. The company requires a 99.99% availability SLA for the VMs. The VMs are currently all deployed in a single availability set within one Azure region. What should you recommend to meet the SLA requirement with minimal architectural changes?

A.Deploy the VMs across multiple regions and use Azure Traffic Manager for load balancing.
B.Deploy the VMs across three availability zones in the same region.
C.Keep the VMs in the availability set but add a second availability set in the same region.
D.Move the VMs to Azure Virtual Machine Scale Sets with a single placement group.
AnswerB

Availability zones provide a higher SLA (99.99%) for VMs because they are physically separate datacenters within a region, protecting against datacenter-level failures. Deploying the existing VMs across three zones in the same region meets the SLA with minimal changes to the overall architecture, as the load balancer can be zone-redundant.

Why this answer

Availability zones are physically separate datacenters within an Azure region, each with independent power, cooling, and networking. Deploying VMs across three zones provides a 99.99% SLA, higher than the 99.95% offered by availability sets. This approach requires minimal changes because the existing load balancer can be made zone-redundant, and no cross-region data replication is needed.

Exam trap

The trap here is assuming that adding more availability sets or using a single placement group scale set automatically improves the SLA, when only availability zones provide the higher 99.99% SLA.

787
MCQeasy

A company has Azure virtual networks (VNets) in three different Azure regions (West US, East US, and West Europe). They also have an on-premises data center connected to the East US region via ExpressRoute. They need to connect all VNets to each other and to the on-premises network. The solution must support transitive routing between all sites and provide centralized management of connectivity and routing policies. Which Azure service should they use?

A.VNet peering
B.Azure Virtual WAN
C.VPN Gateway
D.ExpressRoute Direct
AnswerB

Azure Virtual WAN is the correct architectural solution because it creates regional hubs connected in an any-to-any mesh, and each hub contains a fully managed virtual router with built-in VPN/ExpressRoute gateways. It provides transitive routing between VNets attached to different hubs as well as between VNets and on-premises sites, using a single, centrally managed route table and route propagation via BGP. This eliminates the need to build a full mesh of VNet peerings and gives centralized monitoring, routing, and security policy management across all regions.

Why this answer

Azure Virtual WAN is correct because it provides a hub-and-spoke architecture with built-in transitive routing between all VNets and on-premises sites. It supports automatic connectivity through Virtual Hub routers, which use BGP to propagate routes across all spokes and branches, meeting the requirement for centralized management of connectivity and routing policies.

Exam trap

The trap here is that candidates often assume VNet peering can be chained to achieve transitive routing, but Azure explicitly blocks transitive routing through peered VNets unless a network virtual appliance or Azure Virtual WAN is used.

How to eliminate wrong answers

Option A is wrong because VNet peering does not support transitive routing; peered VNets cannot route traffic through each other to reach a third VNet or on-premises network without additional user-defined routes and network virtual appliances. Option C is wrong because a VPN Gateway only provides site-to-site or point-to-site connectivity to a single VNet and does not inherently enable transitive routing between multiple VNets or centralized policy management across regions. Option D is wrong because ExpressRoute Direct is a physical port offering for dedicated private connections to Azure, not a service that provides transitive routing or centralized connectivity management between multiple VNets and on-premises networks.

788
MCQeasy

You need to design a solution to store configuration data for a cloud-native application. The configuration must be centrally managed, versioned, and accessible to multiple services without hard-coding values. Which Azure service should you use?

A.Azure App Configuration
B.Azure Cosmos DB
C.Azure Blob Storage
D.Azure Key Vault
AnswerA

Azure App Configuration is the correct choice because it is a purpose-built managed service for centrally storing and managing application configuration settings such as key-value pairs, hierarchical labels, feature flags, and dynamic refresh. It supports versioning, rollback, and composition with services like Azure Kubernetes Service, so workload configuration can be updated without redeploying. Unlike a general NoSQL store, it provides a simple configuration model and SDK integration to watch for changes and apply them at runtime.

Why this answer

Azure App Configuration is the correct choice because it is a fully managed service specifically designed for central management of application configuration and feature flags. It supports versioning of configuration key-values, provides instant access to multiple services via SDKs or REST API, and eliminates the need to hard-code values by allowing dynamic updates without redeployment.

Exam trap

The trap here is that candidates often confuse Azure Key Vault (for secrets) with Azure App Configuration (for non-secret configuration), or assume a general-purpose database like Cosmos DB can serve as a configuration store, overlooking the specialized versioning and dynamic refresh capabilities of App Configuration.

How to eliminate wrong answers

Option B (Azure Cosmos DB) is wrong because it is a NoSQL database for storing transactional or operational data, not a configuration store; it lacks built-in versioning for configuration and adds unnecessary complexity and cost. Option C (Azure Blob Storage) is wrong because it is an object storage service for unstructured data like files and backups, not designed for fine-grained, versioned configuration key-values with low-latency access from multiple services. Option D (Azure Key Vault) is wrong because it is a secrets management service for storing sensitive items like passwords and certificates, not for general configuration data; it does not support versioning of configuration values in a way that is easily consumable by application code.

789
MCQmedium

A company runs an application on Azure VMs that must be backed up according to regulatory compliance: daily backups retained for 30 days, weekly backups retained for 12 months, and yearly backups retained for 7 years. The backups must be stored in a secondary region for disaster recovery. They want to use Azure Backup for VMs. Which backup policy and storage configuration should they implement?

A.Configure a backup policy in Azure Backup for VMs with daily, weekly, and yearly retention rules, and enable cross-region restore by using a Recovery Services Vault with geo-redundant storage.
B.Enable backup with Azure Backup using the default policy and select Geo-Redundant Storage (GRS) for the Recovery Services Vault.
C.Use Azure Site Recovery to replicate VMs to the secondary region and configure retention policies in the replication settings.
D.Perform file-level backups using Azure Backup and store them in a separate storage account with read-access geo-redundant storage (RA-GRS).
AnswerA

This is the correct approach because Azure Backup for VMs allows you to create a custom backup policy in a Recovery Services Vault, specifying multiple retention rules for daily, weekly, and yearly recovery points. The vault must be configured with geo-redundant storage (GRS), and you must enable the cross-region restore feature on the vault, which then permits restoring VM backups to the paired secondary Azure region for disaster avoidance. This combination meets the requirement for scheduled backups with long-term retention and off-region recoverability.

Why this answer

Azure Backup for VMs allows you to create a custom backup policy with daily, weekly, and yearly retention points, meeting the regulatory requirements. By enabling cross-region restore (CRR) on a Recovery Services Vault configured with geo-redundant storage (GRS), backups are automatically replicated to a paired secondary region, providing disaster recovery without additional infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with Azure Backup (long-term retention), or assume the default policy can be customized to include yearly retention without realizing it must be explicitly configured.

How to eliminate wrong answers

Option B is wrong because the default backup policy in Azure Backup does not include yearly retention rules, so it cannot meet the 7-year yearly retention requirement. Option C is wrong because Azure Site Recovery is designed for replication and failover, not for long-term backup retention; it does not support granular retention policies like daily, weekly, and yearly backups. Option D is wrong because file-level backups do not capture the full VM state (including OS and application consistency), and RA-GRS storage alone does not provide the integrated backup policy with retention rules required for compliance.

790
Multi-Selectmedium

A company is designing a highly available architecture for a web application on Azure VMs. The solution must protect against both planned and unplanned downtime and provide automatic failover. Which TWO Azure services should the company use together? (Choose two.)

Select 2 answers
A.Azure Availability Zones
B.Azure Site Recovery
C.Azure Traffic Manager
D.Azure Load Balancer
E.Azure Application Gateway
AnswersA, D

Azure Availability Zones are physically separate datacenters within the same Azure region, each with independent power, cooling, and networking. By placing VM replicas across multiple zones, you ensure that a failure of one entire datacenter does not affect all instances, achieving intra-region high availability. This is the foundational building block for many HA architectures and carries a 99.99% VM SLA when two or more instances are deployed across zones.

Why this answer

Azure Availability Zones (A) protect against datacenter-level failures by distributing VMs across physically separate zones within a region, each with independent power, cooling, and networking. Azure Load Balancer (D) provides automatic failover by distributing incoming traffic across healthy VMs in a backend pool, using health probes to detect and route away from failed instances. Together, they ensure the application remains available during both planned maintenance and unplanned outages, with the Load Balancer handling traffic redirection and Availability Zones providing infrastructure redundancy.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (a disaster recovery service with RTOs of minutes to hours) with high-availability solutions that provide automatic failover within seconds, leading them to select Site Recovery instead of Availability Zones.

791
MCQhard

Contoso is a global e-commerce company that runs its platform on Azure Kubernetes Service (AKS) with Istio service mesh. The application uses Azure Cosmos DB (API for MongoDB) with multi-region writes enabled. The platform also uses Azure Cache for Redis Enterprise for session caching. The business requires a Recovery Time Objective (RTO) of 30 seconds and a Recovery Point Objective (RPO) of 0 for all tiers. You need to design a disaster recovery solution that meets these requirements with high availability. What should you recommend?

A.Deploy AKS in two regions with Azure Traffic Manager. Use Azure Cosmos DB with multi-region writes. Use Azure Cache for Redis Enterprise with active geo-replication.
B.Deploy AKS in two regions with Azure Front Door. Use Azure Cosmos DB with a single write region and auto-failover. Use Azure Cache for Redis Standard with geo-replication.
C.Deploy AKS in two regions with Azure Front Door. Use Azure Cosmos DB with multi-region writes. Use Azure Cache for Redis Enterprise with active geo-replication.
D.Use Azure SQL Database with auto-failover groups for the database tier. Deploy AKS in two regions with Azure Front Door. Use Azure Cache for Redis Enterprise with active geo-replication.
AnswerC

By using Azure Cosmos DB multi-region writes, every write is acknowledged in all configured regions, guaranteeing zero data loss (RPO) and enabling immediate failover. Azure Front Door sits in front of AKS clusters in two regions, performing health-probe-based endpoint selection and traffic redirection within seconds, which supports the strict 30-second RTO. Azure Cache for Redis Enterprise with active geo-replication creates active-active caches that allow simultaneous reads and writes in both regions without data loss. This combination provides a truly active-active data plane and global HTTP routing, making it the only architecture that fully satisfies all requirements.

Why this answer

It meets the RTO of 30 seconds and RPO of 0 by using Azure Front Door for global load balancing with health probes, Azure Cosmos DB with multi-region writes for zero data loss (RPO=0) and instant failover, and Azure Cache for Redis Enterprise with active geo-replication to provide a writable cache in both regions with sub-30-second failover. This combination ensures that all tiers can fail over independently and instantly without data loss.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager (DNS-based, slow failover) with Azure Front Door (Anycast-based, fast failover), and they may overlook that Azure Cache for Redis Standard geo-replication is read-only in the secondary region, while Enterprise active geo-replication supports writes in both regions for true active-active disaster recovery.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager relies on DNS-based routing, which can take minutes to propagate and fail over, exceeding the 30-second RTO. Option B is wrong because Azure Cosmos DB with a single write region and auto-failover introduces a failover delay (typically 1-2 minutes) and potential data loss during the failover window, violating the RPO of 0; additionally, Azure Cache for Redis Standard with geo-replication is read-only in the secondary region, preventing active writes and causing cache misses. Option D is wrong because it uses Azure SQL Database with auto-failover groups, which does not match the application's stated use of Azure Cosmos DB (API for MongoDB) and introduces a different database technology that may not support the same multi-region write semantics or RPO=0 requirements.

792
MCQeasy

A company uses Microsoft Entra ID. They want to require users to use multi-factor authentication when accessing the Azure portal from any device. They do not want to require MFA for other applications. Which Microsoft Entra ID feature should they configure?

A.Conditional Access policy targeting Azure Portal
B.Per-user MFA (legacy)
C.Security defaults
D.Identity Protection
AnswerA

A Conditional Access policy that targets the Azure Portal is the correct solution because you can select the 'Microsoft Azure Management' cloud app (the enterprise application that represents the Azure portal and API management) and require MFA as a grant control. This policy is evaluated by the Conditional Access engine at sign-in and applies only to the selected app, leaving MFA behavior for other applications unaffected. You can further scope it by users, groups, locations, or device state to meet the company's exact requirement.

Why this answer

Conditional Access policies allow granular control over authentication requirements based on conditions such as application, user, location, or device state. By creating a policy that targets the 'Microsoft Azure Management' cloud app and requires multi-factor authentication, you can enforce MFA specifically for the Azure portal without affecting other applications. This provides the precise control requested, unlike broader or legacy methods.

Exam trap

The trap here is that candidates often confuse Security defaults (which is a blanket MFA enforcement for all apps) with the ability to scope MFA to a single application, leading them to choose Security defaults instead of the more precise Conditional Access policy.

How to eliminate wrong answers

Option B (Per-user MFA) is wrong because it enables MFA for all applications and sign-ins for the assigned user, not just the Azure portal, and is a legacy feature that lacks the conditional targeting required. Option C (Security defaults) is wrong because it enforces MFA for all users and all applications, including every cloud app, which contradicts the requirement to not require MFA for other applications. Option D (Identity Protection) is wrong because it is a risk-based detection and remediation service that can trigger MFA based on sign-in risk, but it does not allow you to target a specific application like the Azure portal; it works in conjunction with Conditional Access but is not the feature to configure for this requirement.

793
Multi-Selecteasy

Which TWO are valid methods to authenticate users in a Microsoft Entra ID hybrid identity solution? (Select TWO.)

Select 3 answers
A.Cloud-only authentication
B.Password hash synchronization
C.Federation with Active Directory Federation Services (ADFS)
D.Pass-through Authentication
E.Seamless Single Sign-On
AnswersB, C, D

Synchronizes password hashes to cloud for authentication.

Why this answer

Password hash synchronization (B), Federation with Active Directory Federation Services (ADFS) (C), and Pass-through Authentication (D) are all valid authentication methods in a Microsoft Entra ID hybrid identity solution. Cloud-only authentication (A) is not hybrid, and Seamless Single Sign-On (E) is a supplementary feature rather than a standalone authentication method.

Exam trap

The trap here is that candidates often confuse Seamless Single Sign-On (SSO) as an authentication method, when it is actually a feature that works on top of password hash sync or pass-through authentication to provide automatic sign-in, not a standalone authentication method.

794
MCQhard

A company runs a mission-critical SQL Server database on an Azure virtual machine using SQL Server Standard Edition. They need a disaster recovery solution that replicates the database to a secondary Azure region with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 1 hour. The solution must support non-disruptive disaster recovery drills. The company cannot modify the SQL Server configuration or use Always On features due to licensing constraints. Which Azure service should they use?

A.Azure Site Recovery
B.SQL Server log shipping to a VM in the secondary region
C.Azure Backup with cross-region restore
D.Azure SQL Database geo-replication
AnswerA

Azure Site Recovery is the only listed option that provides full IaaS disaster recovery by continuously replicating the entire VM (disk-level) to the secondary region, with app-consistent recovery points every 15 minutes. It supports non-disruptive test failovers that run in parallel with production, satisfying the DR drill requirement without downtime, and a coordinated failover can restore the mission-critical SQL Server VM well within the 1-hour RTO.

Why this answer

Azure Site Recovery (ASR) replicates the entire VM (including the SQL Server database) to a secondary Azure region, meeting the RPO of 15 minutes and RTO of 1 hour. It supports non-disruptive disaster recovery drills by allowing test failovers in an isolated network without affecting the production environment. ASR does not require any changes to SQL Server configuration or licensing, as it operates at the hypervisor level using continuous replication.

Exam trap

The trap here is that candidates often choose Azure Backup (Option C) thinking it provides cross-region restore with low RPO, but they overlook that Backup's cross-region restore is designed for long-term retention and compliance, not for sub-hour RPOs, and it does not support non-disruptive drills.

How to eliminate wrong answers

Option B is wrong because SQL Server log shipping requires modifying the SQL Server configuration (setting up backup, copy, and restore jobs) and uses Always On features that are not available in Standard Edition without additional licensing; it also does not support non-disruptive drills without breaking the log chain. Option C is wrong because Azure Backup with cross-region restore provides only point-in-time snapshots with a typical RPO of 24 hours (or longer for cross-region), far exceeding the 15-minute requirement, and does not support non-disruptive drills. Option D is wrong because Azure SQL Database geo-replication is a PaaS feature that cannot be used with a SQL Server running on an Azure VM (IaaS); it requires migrating to Azure SQL Database, which is not the scenario described.

795
MCQmedium

Your company plans to deploy a new application to Azure. The application will be used by external partners. You need to design an identity solution that allows partners to authenticate using their own corporate credentials while ensuring that the application can enforce conditional access policies based on partner device compliance. What should you include in the design?

A.Federate your Microsoft Entra tenant with each partner's on-premises Active Directory.
B.Create guest user accounts in your Microsoft Entra tenant and assign them application roles.
C.Configure Microsoft Entra B2C and federate with partner identity providers.
D.Configure Microsoft Entra B2B collaboration and enable conditional access policies for guest users.
AnswerD

Configuring Microsoft Entra B2B collaboration lets partners access the application using their own corporate identities, avoiding separate username/passwords. When you also enable Conditional Access policies that target guest users, you can require device compliance as an access condition, so only partner devices that are compliant with your (or their) Intune policies are granted access. This is the only option that combines external identity federation with the enforcement of device compliance for external users.

Why this answer

Microsoft Entra B2B collaboration allows you to invite external partners as guest users who can authenticate with their own corporate credentials. You can then enforce conditional access policies, including device compliance checks, on these guest users by targeting the policy to the 'Guest' user type or specific external users.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2C (for customers) with Microsoft Entra B2B (for partners), leading them to choose Option C, which cannot enforce conditional access policies based on partner device compliance.

How to eliminate wrong answers

Option A is wrong because federating your Entra tenant with each partner's on-premises Active Directory would require you to manage federation trusts for every partner, and it does not inherently enable conditional access policies based on partner device compliance; device compliance is typically evaluated against your own tenant's policies, not the partner's. Option B is wrong because creating guest user accounts and assigning application roles alone does not enable conditional access policies based on partner device compliance; guest users can authenticate, but without B2B collaboration settings, you cannot enforce device-based conditional access on their external devices. Option C is wrong because Microsoft Entra B2C is designed for customer-facing identity management with self-service sign-up, not for external partner access where partners use their own corporate credentials; B2C does not natively support conditional access policies based on device compliance for guest users.

Page 10

Page 11 of 11

All pages