Courseiva

Microsoft Azure Solutions Architect Expert AZ-305 (AZ-305) — Questions 151–225

795 questions total · 11pages · All types, answers revealed

Page 2

Page 3 of 11

Page 4
151
Multi-Selectmedium

A company is designing a data storage solution for its IoT devices that generate telemetry data. The data is ingested at high velocity (millions of events per second) and must be stored for real-time dashboards and historical analysis. The solution must also support complex event processing and alerting. Which two Azure services should the company use together? (Choose two.)

Select 2 answers
A.Azure IoT Hub
B.Azure Event Hubs
C.Azure Stream Analytics
D.Azure Synapse Analytics
E.Azure Data Lake Storage Gen2
AnswersB, C

Azure Event Hubs is the correct choice because it is a fully managed, partitioned event-streaming platform engineered for high-throughput telemetry ingestion from millions of IoT devices, supporting millions of events per second and automatic data retention for replay. It decouples producers (devices) from consumers, exposes Kafka-compatible APIs, and enables Stream Analytics, functions, or custom consumers to process the stream, making it the foundational buffer before durable storage.

Why this answer

Azure Event Hubs is the correct choice because it is a high-throughput data ingestion service designed to handle millions of events per second from IoT devices, providing low-latency, durable event capture for real-time dashboards and historical analysis. Azure Stream Analytics is the correct companion service because it natively integrates with Event Hubs to perform complex event processing (CEP), such as pattern matching, aggregation, and alerting, on the streaming telemetry data in real time.

Exam trap

The trap here is that candidates often confuse Azure IoT Hub with Event Hubs, assuming IoT Hub is the default for all IoT data ingestion, but IoT Hub is for device management and lower-throughput scenarios, while Event Hubs is the correct choice for high-velocity, multi-million-events-per-second telemetry ingestion.

152
MCQeasy

Your company has a large Azure environment with thousands of resources. You need to design a solution to track resource ownership and ensure that resources are cleaned up when projects end. You want to use a tag-based approach where each resource has an 'Owner' and 'Project' tag. Additionally, you need to generate a weekly report of resources that are not tagged or have been orphaned (no recent activity). What should you include in the design?

A.Use Azure Policy to audit missing tags and create a custom dashboard in Azure Monitor.
B.Use Azure Monitor alerts with a metric alert for unmodified resources.
C.Use Azure Automation runbook to inventory resources and store in a SQL database, then use Power BI to report.
D.Use Azure Resource Graph queries in an Azure Logic App scheduled to run weekly, and send the report via email.
AnswerD

This is the correct approach because Azure Resource Graph (ARG) provides a centralized, KQL-queryable inventory of all resource types and properties, including tags and sometimes a lastModified timestamp, which lets you filter for resources that appear orphaned based on staleness. A Logic App with a Recurrence trigger can invoke the 'Run Azure Resource Graph query' connector action weekly, handle pagination via the skip token for thousands of resources, and send the formatted results through an Office 365 Outlook or SMTP email action. This serverless composition avoids standing infrastructure, directly addresses the schedule-and-email requirement, and scales well beyond the resource count in the scenario.

Why this answer

Azure Resource Graph (ARG) provides fast, queryable access to resource properties across subscriptions, enabling efficient identification of untagged or orphaned resources. Scheduling an Azure Logic App to run ARG queries weekly and email the report meets the requirements for automation and delivery without additional infrastructure. This approach is cost-effective and scales well for thousands of resources.

Exam trap

The trap here is that candidates overcomplicate the solution by choosing a database and Power BI (Option C) or misapplying Azure Monitor alerts (Option B), when Azure Resource Graph with Logic Apps provides a simpler, serverless, and fully managed solution for scheduled resource inventory and reporting.

How to eliminate wrong answers

Option A is wrong because Azure Policy can audit missing tags but cannot detect orphaned resources (no recent activity); a custom dashboard in Azure Monitor visualizes metrics but does not generate scheduled reports. Option B is wrong because Azure Monitor metric alerts are designed for performance metrics (e.g., CPU usage), not for tracking resource modification timestamps or tag compliance; they cannot identify untagged or orphaned resources. Option C is wrong because using an Azure Automation runbook to inventory resources into a SQL database and then Power BI adds unnecessary complexity, cost, and maintenance overhead; Azure Resource Graph queries are simpler and natively support cross-subscription inventory without a database.

153
MCQeasy

A software company runs 50 small Azure SQL databases for different clients. Each database has low average usage but unpredictable spikes. The company wants to minimize cost while providing resources for peak loads and easily adding new databases without manual sizing. Which Azure data service should they use?

A.Azure SQL Database single databases
B.Azure SQL Database elastic pool
C.Azure SQL Managed Instance
D.SQL Server on Azure Virtual Machines
AnswerB

Azure SQL Database elastic pools distribute a shared pool of eDTUs or vCores across many databases, allowing each database to burst beyond its guaranteed minimum without a dedicated allocation. This statistical multiplexing is ideal for 50 small databases with variable, low average utilization because you pay only for the pooled resources actually needed, not the sum of individual peak demands. By configuring per-database min and max limits, you protect individual tenants while maximizing overall cost efficiency.

Why this answer

Azure SQL Database elastic pool is ideal for multiple databases with low average usage and unpredictable spikes because it allows them to share a fixed set of resources (eDTUs or vCores). This pooling model minimizes cost by only paying for the aggregate peak usage across all databases, not each database's individual peak, and automatically handles resource allocation without manual sizing for new databases.

Exam trap

The trap here is that candidates often choose single databases (Option A) thinking they can scale individually for spikes, but they overlook the cost inefficiency of provisioning each database for its peak load versus sharing resources in an elastic pool.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database single databases would require each database to be sized for its own peak load, leading to over-provisioning and higher costs for 50 low-usage databases with spikes. Option C is wrong because Azure SQL Managed Instance is a fully managed instance of SQL Server with fixed resources, designed for lift-and-shift migrations, not for cost-efficient multi-tenant scenarios with variable loads. Option D is wrong because SQL Server on Azure Virtual Machines requires manual VM sizing, patching, and management, increasing operational overhead and cost, and does not provide the automatic resource sharing needed for unpredictable spikes.

154
MCQmedium

A healthcare organization needs to store patient records that must be immutable and auditable for compliance purposes. The records should be stored in a cost-effective manner with the ability to set retention policies. Which Azure storage solution should they implement?

A.Azure NetApp Files
B.Azure SQL Database
C.Azure Blob Storage with immutable storage
D.Azure Files
AnswerC

Azure Blob Storage with immutable storage — available as a container-level policy or legal hold — enforces a Write Once, Read Many (WORM) model at the object layer. Once a time-based retention interval is locked, blobs cannot be overwritten or deleted by any user, including subscription administrator, until the interval expires; legal hold makes such protection indefinite. This behavior is Microsoft’s recommended path for retaining regulated health records like EHR/PHI because it meets HIPAA data integrity and retention compliance via auditable, policy-controlled protection.

Why this answer

Azure Blob Storage with immutable storage (WORM policy) is the correct solution because it provides time-based retention policies and legal hold capabilities that make data non-erasable and non-modifiable, meeting compliance requirements for patient records. It is cost-effective for large volumes of data and integrates with Azure Policy for audit logging, making it ideal for healthcare compliance scenarios like HIPAA.

Exam trap

The trap here is that candidates often confuse Azure Files or Azure NetApp Files with immutable storage because they support snapshots, but snapshots can be deleted or overwritten, whereas Blob Storage immutable policies enforce true WORM compliance that cannot be bypassed.

How to eliminate wrong answers

Option A is wrong because Azure NetApp Files is a high-performance file share for NFS/SMB workloads, not designed for immutable storage or compliance retention policies. Option B is wrong because Azure SQL Database supports row-level security and auditing but does not offer native immutable storage capabilities; data can be modified or deleted unless using complex triggers or backups. Option D is wrong because Azure Files provides SMB file shares with snapshots but lacks built-in WORM (Write Once, Read Many) immutability and retention policy enforcement required for compliance.

155
MCQeasy

A company wants to implement a backup strategy for their Azure virtual machines. They need to retain backups for 7 years for compliance and ensure backups are encrypted at rest. Which solution should you recommend?

A.Azure Disk Snapshot with a lifecycle management policy.
B.Azure Backup with a vault configured for 7-year retention and encryption at rest.
C.Azure Files Backup to a Recovery Services vault.
D.Azure Site Recovery with custom retention policies.
AnswerB

Azure Backup with a Recovery Services vault is the correct service for long-term VM backup, supporting retention up to 10 years (or 7 years easily) with flexible weekly/monthly/yearly retention policies. Backups are application-consistent using VSS on Windows and file-system-consistent on Linux, with encryption at rest using platform-managed keys and secure network access via private endpoints. The vault stores recovery points across regions if you enable cross-region restore, providing the durability and compliance needed for keeping backups for 7 years.

Why this answer

Azure Backup is the correct solution because it provides long-term retention (up to 99 years) and supports encryption at rest using platform-managed keys (PMK) or customer-managed keys (CMK). It meets the 7-year compliance requirement and ensures backups are encrypted by default using Azure Storage Service Encryption (SSE).

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with Azure Backup (long-term backup), or assume that disk snapshots with lifecycle management can achieve 7-year retention, but snapshots have a maximum retention of 5 years and lack the integrated encryption and compliance features of Azure Backup.

How to eliminate wrong answers

Option A is wrong because Azure Disk Snapshots do not support retention policies beyond the snapshot lifecycle management (max 5 years) and are not inherently encrypted at rest with a managed backup service; they rely on the underlying disk encryption. Option C is wrong because Azure Files Backup is designed for file shares, not Azure virtual machines, and does not provide VM-consistent backup or 7-year retention for VMs. Option D is wrong because Azure Site Recovery is a disaster recovery solution focused on replication and failover, not long-term backup retention; its custom retention policies are limited to crash-consistent recovery points and do not support 7-year archival.

156
MCQhard

You are designing a monitoring solution for a critical application running on Azure Kubernetes Service (AKS). The application generates custom metrics that need to be queried in real-time for dashboards. You also need to retain logs for one year for compliance. Which combination of services should you use?

A.Azure Monitor Metrics and Azure Monitor Logs
B.Prometheus and Azure Monitor Logs
C.Azure Data Explorer and Azure Blob Storage
D.Application Insights and Azure Storage
AnswerA

Azure Monitor Metrics provides lightweight, high-granularity time-series data with sub-minute ingestion for real-time dashboards and alert rules, while Azure Monitor Logs stores verbose diagnostic and resource logs for years, enabling powerful KQL queries and trend analysis. Together they deliver both immediate operational visibility and deep historical investigation without any additional tooling, making them the natural native pair for AKS monitoring.

Why this answer

Azure Monitor Metrics is the correct choice for real-time querying of custom metrics because it stores numeric time-series data with sub-minute granularity and supports near real-time alerting and dashboarding via Azure Dashboards or Grafana. Azure Monitor Logs (Log Analytics) is required for retaining logs for one year, as it offers configurable retention up to 730 days (2 years) and supports KQL queries for compliance and audit needs. Together, they provide a unified monitoring solution for AKS that meets both real-time metric querying and long-term log retention requirements.

Exam trap

The trap here is that candidates often confuse Prometheus as the only way to collect custom metrics in AKS, but Azure Monitor Metrics natively supports custom metrics via the Azure Monitor agent and does not require a separate Prometheus deployment for real-time dashboards.

How to eliminate wrong answers

Option B is wrong because Prometheus is a third-party monitoring tool that, while commonly used with AKS, does not natively integrate with Azure Monitor Logs for log retention; you would need Azure Monitor for logs, making this combination redundant and less integrated. Option C is wrong because Azure Data Explorer is designed for big data analytics and interactive queries on large datasets, not for real-time metric dashboards, and Azure Blob Storage is a cold storage option that does not support real-time querying or native dashboarding. Option D is wrong because Application Insights is primarily for application performance monitoring (APM) and traces, not for storing custom metrics from AKS in a real-time queryable format, and Azure Storage (Blob) is not a log analytics platform and lacks the querying capabilities needed for compliance retention.

157
MCQmedium

A startup is building a social media analytics platform that processes streaming data. They need a data store for time-series events with high write throughput and fast timestamp-based range queries. Which Azure data store is most suitable for this workload?

A.Azure Cosmos DB with SQL API
B.Azure SQL Database with columnstore index
C.Azure Table Storage
D.Azure Data Lake Storage Gen2
AnswerC

Azure Table Storage is a schema-less key-value store where data is addressed by PartitionKey and RowKey, making it a natural fit for IoT-style time-series data. Using a partition key such as device ID and a row key such as inverted timestamp allows efficient range scans for a given device over a time window, while inserts are cheap and highly parallel across partitions. This design delivers low latency at very low cost without the operational complexity of a SQL-based service, which is why it is the correct recommendation.

Why this answer

Azure Table Storage is a NoSQL key-value store that supports high-volume, low-latency writes and efficient range queries on the PartitionKey and RowKey, which can be structured as a timestamp for time-series data. Its schema-less design and ability to scale to massive throughput without sharding overhead make it ideal for streaming event ingestion and timestamp-based retrieval.

Exam trap

The trap here is that candidates often choose Cosmos DB for its flexibility and global distribution, but for a simple, high-throughput time-series workload with timestamp-based queries, Azure Table Storage is the most cost-effective and performant choice, as Cosmos DB adds unnecessary complexity and cost.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB with SQL API, while supporting time-series patterns, introduces higher latency and cost for simple key-value workloads compared to Table Storage, and its throughput is provisioned per container, requiring careful RU management that adds complexity for high-write streaming. Option B is wrong because Azure SQL Database with columnstore index is optimized for analytical queries on large datasets, not for high-write throughput of individual streaming events; its transactional overhead and indexing costs make it unsuitable for real-time ingestion. Option D is wrong because Azure Data Lake Storage Gen2 is a hierarchical file system designed for big data analytics and batch processing, not for low-latency point writes or timestamp-based range queries on individual events.

158
MCQmedium

A company runs a critical OLTP application on Azure SQL Database in the West US region. They need to ensure business continuity if a regional outage occurs. The solution must have a recovery point objective (RPO) of 5 seconds and a recovery time objective (RTO) of less than 1 hour. They also want to use the secondary region for read-only query offloading. Which Azure SQL Database feature should they enable?

A.Active geo-replication with automatic failover group
B.Geo-restore
C.Azure Site Recovery
D.Read scale-out with manual regional failover
AnswerA

Active geo-replication continuously pushes transactions to a readable secondary in a paired region, achieving a recovery point objective (RPO) of about 5 seconds and an RTO under one hour. When paired with an auto-failover group, outage detection and promotion of the secondary are automated, so the critical OLTP workload can resume without manual intervention and the secondary can also serve read-only queries during normal operation. This combination directly satisfies both the low data-loss and fast-recovery requirements.

Why this answer

Active geo-replication with automatic failover groups is the correct choice because it provides continuous asynchronous data replication to a secondary Azure SQL Database in a paired region, achieving an RPO of 5 seconds and an RTO of under 1 hour. The automatic failover group enables coordinated failover of multiple databases and allows the secondary region to be used for read-only query offloading by connecting with ApplicationIntent=ReadOnly.

Exam trap

The trap here is that candidates confuse geo-restore (backup-based) with active geo-replication (continuous replication), or assume read scale-out can span regions, when in fact it only works within the same Azure region.

How to eliminate wrong answers

Option B (Geo-restore) is wrong because it restores a database from geo-replicated backups with an RPO of 1 hour and an RTO of 12+ hours, failing the 5-second RPO and 1-hour RTO requirements. Option C (Azure Site Recovery) is wrong because it is designed for IaaS VM replication, not for PaaS Azure SQL Database, and cannot meet the 5-second RPO or provide read-only query offloading. Option D (Read scale-out with manual regional failover) is wrong because read scale-out only offloads read-only queries using a readable secondary replica within the same region, not in a secondary region, and manual failover does not meet the automated RTO of under 1 hour.

159
MCQeasy

A company wants to run a containerized application on Azure without managing virtual machines. They need automatic scaling, load balancing, and rolling updates. Which Azure compute service should they choose?

A.Azure Virtual Machine Scale Sets
B.Azure Kubernetes Service (AKS)
C.Azure App Service
D.Azure Container Instances
AnswerB

Azure Kubernetes Service (AKS) is a fully managed container orchestration platform that abstracts the Kubernetes control plane—including etcd and the API server—so you never have to manage those components. It provides managed node pools, cluster autoscaler, seamless integration with Azure Load Balancer and Application Gateway, and declarative rolling updates through Kubernetes Deployments and ReplicaSets. AKS handles scheduling, self-healing, service discovery, and secret management natively, making it the appropriate choice when you need robust, production-grade orchestration for containerized applications without managing the underlying orchestration infrastructure.

Why this answer

Azure Kubernetes Service (AKS) is the correct choice because it provides a fully managed Kubernetes orchestration platform that handles containerized applications with automatic scaling (via Horizontal Pod Autoscaler), built-in load balancing (via Azure Load Balancer integration), and rolling updates (via Kubernetes deployment strategies). This meets the requirement of running containers without managing VMs, as AKS abstracts the underlying node management.

Exam trap

The trap here is that candidates often confuse Azure Container Instances (ACI) as a full orchestration solution, but ACI lacks the automatic scaling, load balancing, and rolling update capabilities that AKS provides for multi-container applications.

How to eliminate wrong answers

Option A is wrong because Azure Virtual Machine Scale Sets require you to manage VMs and the container runtime, and they do not natively support container orchestration features like rolling updates or service discovery. Option C is wrong because Azure App Service is a Platform-as-a-Service (PaaS) for web apps and APIs, not designed for containerized applications with full orchestration; it lacks native Kubernetes features like pod-level scaling and rolling update strategies. Option D is wrong because Azure Container Instances (ACI) is a serverless container service that does not provide built-in orchestration for automatic scaling, load balancing across multiple containers, or rolling updates; it is intended for simple, single-container scenarios.

160
MCQmedium

A company is designing private access to a PaaS database from workloads in a VNet. The database should not be reachable over its public endpoint. What should be recommended?

A.A public IP address with NSG rules
B.A route table to the internet gateway
C.Private Endpoint with public network access disabled
D.Azure CDN endpoint
AnswerC

Create a private endpoint in the workloads' VNet, which provisions a private IP address from the chosen subnet and maps it to the PaaS database via Azure Private Link, allowing connections over the Microsoft backbone. Then disable public network access on the PaaS resource so the only valid path is through the private endpoint, eliminating internet exposure entirely. This is the intended architecture when workloads must reach a PaaS database without traversing the public internet.

Why this answer

Private Endpoint with public network access disabled is the correct recommendation because it assigns a private IP address from the VNet to the PaaS database, making it accessible only over the private network. This eliminates exposure to the public internet by disabling the public endpoint, aligning with the requirement that the database should not be reachable over its public endpoint.

Exam trap

The trap here is that candidates may confuse Private Endpoint with Service Endpoint, but Service Endpoint does not remove the public endpoint and still allows internet-based access if the firewall permits it, whereas Private Endpoint with public access disabled fully isolates the resource.

How to eliminate wrong answers

Option A is wrong because a public IP address with NSG rules still exposes the database to the internet, and NSGs only filter traffic at the subnet/NIC level, not prevent public endpoint access. Option B is wrong because a route table to the internet gateway directs traffic to the internet, which does not provide private access and would actually route traffic away from the private endpoint. Option D is wrong because an Azure CDN endpoint is a content delivery network for caching static content at edge locations, not a mechanism for private network access to a PaaS database.

161
Multi-Selectmedium

Which TWO of the following are true about Microsoft Entra ID Governance features?

Select 2 answers
A.Conditional Access policies govern access based on location and device.
B.Access reviews allow administrators to periodically review and attest to access rights.
C.Privileged Identity Management (PIM) provides just-in-time access for all users.
D.Identity Protection automatically blocks all risky sign-ins.
E.Entitlement management enables automation of access request workflows.
AnswersB, E

Access reviews in Microsoft Entra ID are a governance control that enables administrators, or delegated reviewers, to conduct recurring certifications of group memberships, application assignments, and privileged roles. These reviews generate attestation evidence for compliance audits, and, based on the reviewer's decision, automatically remove stale or inappropriate access when configured with auto-apply. That periodic, human-in-the-loop attestation is exactly the access-lifecycle governance the question is asking about.

Why this answer

Microsoft Entra ID Access Reviews enable administrators to periodically review and attest to the access rights of users, groups, or applications, ensuring that only authorized users retain access. This is a core governance feature that helps organizations meet compliance and security requirements by automating the certification process.

Exam trap

The trap here is confusing security features (Conditional Access, Identity Protection) with governance features (Access Reviews, Entitlement Management), leading candidates to select options that enforce access rather than manage its lifecycle.

162
MCQmedium

A company uses Microsoft Entra ID. They need to monitor sign-in logs for anomalous activity (e.g., sign-ins from unfamiliar locations) and automatically take action such as requiring MFA or blocking sign-in. Which Microsoft Entra ID feature should they configure?

A.Identity Protection
B.Conditional Access
C.Access Reviews
D.Privileged Identity Management
AnswerA

Identity Protection is the correct choice because it continuously evaluates user sign-ins against dozens of risk signals—such as impossible travel, anonymous IP addresses, unfamiliar properties, and leaked credentials—using machine learning models that produce a per-sign-in risk level. It not only flags anomalous activity in real time but also exposes risk history in Entra ID reports, and it can natively trigger automated remediation when paired with a Conditional Access policy (e.g., block sign-in or require MFA). Its purpose is precisely to detect and respond to risky sign-ins rather than to enforce static policies or manage permissions.

Why this answer

Identity Protection is the correct feature because it is specifically designed to detect anomalous sign-in activities, such as sign-ins from unfamiliar locations or anonymous IP addresses, and can automatically trigger risk-based remediation actions like requiring MFA or blocking sign-ins. It leverages machine learning models and real-time risk detections to assess sign-in risks and apply policies accordingly, directly meeting the requirement for monitoring and automated response.

Exam trap

The trap here is that candidates often confuse Conditional Access as the detection mechanism, but it is only the enforcement layer; Identity Protection is the service that performs the actual anomaly detection and risk assessment.

How to eliminate wrong answers

Option B (Conditional Access) is wrong because it is a policy engine that enforces access controls based on conditions (e.g., location, device state), but it does not itself detect anomalous activity; it relies on risk signals from Identity Protection to trigger actions. Option C (Access Reviews) is wrong because it is used for periodic attestation of group memberships or application access, not for real-time monitoring or automated response to sign-in anomalies. Option D (Privileged Identity Management) is wrong because it focuses on just-in-time privileged role activation and approval workflows, not on detecting or responding to anomalous sign-in behavior.

163
MCQhard

Your organization uses Microsoft Entra ID with P2 licensing. You need to implement a strategy to automatically detect and remediate risky sign-ins without requiring user interaction for low-risk events. What should you configure?

A.Identity Protection sign-in risk policy set to allow access and log for low risk, and require MFA for medium and above
B.Conditional Access policy with session control requiring MFA for all sign-ins
C.Identity Protection user risk policy set to block high risk
D.Identity Protection sign-in risk policy set to allow access with MFA for medium and above
AnswerA

The Identity Protection sign-in risk policy evaluates real-time risk signals for each authentication event, such as anonymous IP addresses, impossible travel, or atypical directory access. Configuring it to allow access and log for low risk automatically remediates low-risk sign-ins by letting them proceed while generating an audit log for later review, while setting the medium-and-above action to require MFA forces stronger authentication only when risk warrants it. This precisely matches a risk-based remediation approach without disrupting ordinary sign-ins.

Why this answer

The Identity Protection sign-in risk policy allows you to automatically respond to sign-in risk levels. By configuring it to 'allow access' and 'log' for low risk, you meet the requirement of no user interaction for low-risk events, while requiring MFA for medium and above ensures remediation for higher-risk sign-ins without manual intervention.

Exam trap

The trap here is confusing sign-in risk policies (which evaluate individual sign-in events) with user risk policies (which evaluate overall user compromise), leading candidates to select Option C, which addresses user risk rather than the sign-in risk requirement.

How to eliminate wrong answers

Option B is wrong because a Conditional Access policy requiring MFA for all sign-ins does not differentiate by risk level, forcing user interaction even for low-risk events, which contradicts the requirement to avoid user interaction for low risk. Option C is wrong because the Identity Protection user risk policy targets user account compromise (e.g., leaked credentials), not sign-in risk; it blocks high-risk users but does not address the sign-in risk detection and remediation for low-risk events. Option D is wrong because it requires MFA for medium and above but does not explicitly allow and log low-risk sign-ins without user interaction; the 'allow access with MFA' for medium and above still triggers MFA for medium risk, but the policy lacks the 'log' action for low risk, potentially blocking or requiring interaction for low-risk events depending on defaults.

164
Multi-Selectmedium

Which TWO options are valid methods to secure access to Azure Cosmos DB?

Select 2 answers
A.X.509 certificate-based authentication
B.Azure Storage account keys
C.Azure RBAC roles
D.Primary and secondary keys
E.Shared access signatures (SAS)
AnswersC, D

Azure RBAC roles are a valid method to secure access to Cosmos DB. For the control plane, built-in roles like DocumentDB Account Contributor let you manage the Cosmos DB account, while for the data plane, roles such as Cosmos DB Built-in Data Reader and Data Contributor allow Azure AD identities to read or write data without using account keys. This provides fine-grained, identity-based access to databases and containers, making RBAC a supported alternative to key-based authentication.

Why this answer

Azure RBAC roles (Option C) provide fine-grained, role-based access control to Azure Cosmos DB, allowing you to assign permissions to users, groups, or service principals for operations like read, write, or delete on specific resources. Primary and secondary keys (Option D) are the default authentication method, enabling full access to the Cosmos DB account for data plane operations, and are commonly used for application connections.

Exam trap

The trap here is that candidates often confuse Azure Cosmos DB authentication with Azure Storage authentication, mistakenly selecting SAS tokens or storage account keys, which are valid for Azure Storage but not for Cosmos DB.

165
MCQeasy

A company deploys a web application on multiple Azure VMs. They need to distribute incoming HTTP traffic across the VMs, offload SSL/TLS termination, and maintain session persistence (sticky sessions) so that all requests from a user session go to the same backend VM. Which Azure load balancing solution should they use?

A.Azure Application Gateway
B.Azure Load Balancer
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is a dedicated layer-7 (HTTP/HTTPS) load balancer that offers SSL offloading by terminating client SSL connections and re-encrypting traffic to backends if needed. It provides cookie-based session affinity, which ensures a user's requests are consistently routed to the same backend VM—a critical requirement for stateful web applications. Additionally, it supports URL path-based routing and an integrated Web Application Firewall, making it the correct choice for a web application deployed on multiple VMs within a single Azure region.

Why this answer

Azure Application Gateway is a Layer 7 load balancer that can route HTTP/HTTPS traffic, offload SSL/TLS termination, and support session persistence using cookie-based affinity. This makes it the correct choice for distributing incoming HTTP traffic across multiple VMs while maintaining sticky sessions and handling SSL termination at the gateway.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), forgetting that SSL termination and cookie-based sticky sessions require Layer 7 capabilities, not just Layer 4 load balancing.

How to eliminate wrong answers

Option B is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL/TLS termination or HTTP-level session persistence; it only supports source IP affinity, which is not cookie-based sticky sessions. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not handle SSL termination or session persistence; it directs traffic at the DNS level, not at the application layer. Option D is wrong because Azure Front Door is a global Layer 7 load balancer and CDN that can offload SSL and provide session affinity, but it is designed for global distribution across regions, not for distributing traffic within a single region to multiple VMs; using it for regional load balancing would introduce unnecessary latency and complexity.

166
MCQhard

You run the above PowerShell script to upload a blob to Azure Storage. The script fails with an error: 'The specified container does not exist.' What should you do first to resolve the issue?

A.Create the container using New-AzStorageContainer.
B.Use a different connection string with a SAS token.
C.Grant the storage account key access to the user.
D.Change the -StandardBlobTier parameter to Cool.
AnswerA

The script fails because the target container is not present in the storage account. Azure Blob Storage enforces a strict hierarchy: every blob must reside inside an existing container. The Set-AzStorageBlobContent cmdlet (or equivalent upload command) returns a 404 ContainerNotFound error when the container is missing. Running New-AzStorageContainer with the same storage context and container name creates the required namespace, allowing the upload to succeed.

Why this answer

The error 'The specified container does not exist' indicates that the target container has not been created in the Azure Storage account. The PowerShell script uses the `Set-AzStorageBlobContent` cmdlet, which requires an existing container as the destination. Therefore, the first corrective action is to create the container using `New-AzStorageContainer` before uploading the blob.

Exam trap

The trap here is that candidates may confuse authentication/authorization issues (SAS tokens, key access) with the fundamental prerequisite of container existence, leading them to select options that address permissions rather than the missing resource.

How to eliminate wrong answers

Option B is wrong because using a different connection string with a SAS token does not create the missing container; it only changes authentication, and the container still does not exist. Option C is wrong because granting storage account key access to the user addresses permissions, not the absence of the container; the container must exist regardless of access level. Option D is wrong because changing the -StandardBlobTier parameter to Cool affects the blob's access tier, not the existence of the container; the container must be present before any blob can be uploaded.

167
MCQmedium

Your company has a Microsoft Entra ID tenant with 50,000 users. You need to design a solution to ensure that users can reset their own passwords without help desk intervention, while preventing password reuse for the last 10 passwords. Which feature should you enable?

A.Microsoft Entra ID Protection
B.Microsoft Entra Connect
C.Privileged Identity Management (PIM)
D.Self-Service Password Reset (SSPR)
AnswerD

Self-Service Password Reset (SSPR) is the correct Entra ID capability that lets end users reset or change their own passwords after verifying authentication methods such as phone, email, or security questions. Administrators can configure SSPR registration requirements, and by combining SSPR with Entra ID Password Protection, the tenant can enforce password reuse restrictions—for example, specifying that a new password cannot match a remembered set of prior passwords. This directly satisfies the company's need for users to reset their own passwords while enforcing anti-reuse policy.

Why this answer

Self-Service Password Reset (SSPR) is the correct feature because it allows users to reset their own passwords without help desk intervention. Additionally, SSPR can be configured with password protection policies that enforce password history, preventing reuse of the last 10 passwords. This directly meets both requirements stated in the question.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Protection (which handles risk-based policies) with SSPR, or they mistakenly think PIM is involved because it deals with passwords, but PIM is strictly for privileged role management, not end-user password resets.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection is a security tool that detects and responds to identity-based risks (e.g., leaked credentials, sign-in anomalies), but it does not provide self-service password reset capabilities or enforce password history policies. Option B is wrong because Microsoft Entra Connect is used for hybrid identity synchronization between on-premises Active Directory and Azure AD, not for password reset or reuse prevention. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time access and role activation for privileged roles, not general user password reset or password history enforcement.

168
Multi-Selectmedium

Which TWO actions should you take to implement a least-privilege identity strategy for Azure resources?

Select 2 answers
A.Use managed identities for Azure resources instead of service principals with secrets
B.Assign the Contributor role at the subscription scope to allow flexibility
C.Use storage account keys for access to blob data
D.Enable Privileged Identity Management (PIM) for just-in-time role assignments
E.Use a single service principal for all applications
AnswersA, D

Managed identities for Azure resources eliminate the need to store, rotate, or protect service principal secrets because Azure automatically binds the identity to the resource and rotates credentials. You can assign a granular RBAC role, such as Storage Blob Data Reader at a specific resource scope, so the identity cannot exceed its intended permissions. This directly supports least privilege by removing long-lived credential management and enforcing scoped access without human intervention.

Why this answer

Managed identities for Azure resources eliminate the need to manage credentials by automatically rotating them and binding them to a resource lifecycle. This removes the risk of secret leakage or mismanagement that exists with service principal secrets, directly supporting a least-privilege identity strategy by ensuring identities are scoped and ephemeral.

Exam trap

The trap here is that candidates often confuse 'least privilege' with 'convenience' and select broad roles like Contributor at subscription scope, thinking it provides flexibility, when in reality it grants excessive permissions that violate the core principle.

169
Drag & Dropmedium

Drag and drop the steps to set up Azure Private Link for an Azure SQL Database into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for setting up Azure Private Link for an Azure SQL Database is: first create the private endpoint in the virtual network, then approve the private link connection from the Azure SQL Database side, next configure DNS (typically using a private DNS zone) to resolve the database's FQDN to the private endpoint IP, test connectivity from within the virtual network, and finally disable public access to the database to enforce private connectivity. This order ensures each step builds on the previous one, avoiding connectivity issues or premature security restrictions.

170
MCQhard

A company runs a critical SAP HANA database on an Azure large instance. They need a disaster recovery solution that provides automatic failover to a secondary region with an RPO of 15 minutes and RTO of 30 minutes. The solution must not require manual intervention to start replication. What should they use?

A.SAP HANA System Replication with HANA Pacemaker
B.Azure Site Recovery with replication policy for SAP HANA
C.Azure NetApp Files with cross-region replication
D.Azure Backup for SAP HANA
AnswerA

SAP HANA System Replication replicates the database at the log and data level from a primary to a secondary node, while the HANA Pacemaker cluster provides cluster orchestration, heartbeat monitoring, and STONITH fencing to automatically promote the secondary when the primary fails. This combination yields near-zero RPO with synchronous replication and automatic RTO in minutes, which is exactly what critical SAP HANA workloads need without manual intervention.

Why this answer

SAP HANA System Replication with HANA Pacemaker is the correct choice because it provides automatic, synchronous or asynchronous replication of SAP HANA data to a secondary region, meeting the RPO of 15 minutes and RTO of 30 minutes. HANA Pacemaker handles automatic failover without manual intervention, ensuring the database is promoted to primary in the disaster recovery region within the required timeframes. This solution is specifically designed for SAP HANA on Azure large instances, offering native integration and support for the required recovery objectives.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery's VM replication with application-consistent replication, but it cannot meet the sub-minute RPO or automatic failover requirements for a critical SAP HANA database without risking data loss or corruption.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery replicates VMs at the hypervisor level and does not understand SAP HANA database consistency, so it cannot guarantee an RPO of 15 minutes or automatic failover without data corruption. Option C is wrong because Azure NetApp Files cross-region replication operates at the file system level and does not provide application-consistent replication for SAP HANA, nor does it support automatic failover with the required RTO. Option D is wrong because Azure Backup for SAP HANA is a backup solution, not a replication or disaster recovery solution, and cannot achieve an RPO of 15 minutes or automatic failover to a secondary region.

171
MCQeasy

A company deploys a web application across multiple Azure VMs in a single region. They want to distribute incoming HTTP traffic evenly across the VMs, offload SSL encryption, and provide a fixed public IP address for clients. Which Azure load balancing solution should they use?

A.Azure Application Gateway
B.Azure Load Balancer
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is a regional, layer 7 (HTTP/HTTPS) load balancer that terminates client SSL/TLS connections at the gateway, eliminating backend SSL overhead and enabling centralized certificate management. It exposes a single, fixed public VIP for all incoming web traffic, supports cookie-based session affinity, URL-path-based routing, and WebSocket forwarding, making it the natural choice for an HTTP workload spread across multiple VMs in one Azure region. Unlike layer 4 devices, it inspects HTTP headers and can redirect traffic based on host names or paths, so it fully satisfies the requirement for SSL offloading and a stable public IP for the web application.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that supports HTTP/HTTPS traffic, SSL termination, and cookie-based session affinity. It can distribute incoming HTTP traffic evenly across VMs, offload SSL encryption to reduce backend processing, and provide a fixed public IP address (VIP) for client access. This aligns with all three requirements: load balancing, SSL offload, and a static public IP.

Exam trap

The trap here is confusing Layer 4 (Azure Load Balancer) with Layer 7 (Application Gateway) capabilities, leading candidates to pick Azure Load Balancer because it is the default choice for distributing traffic across VMs, but it cannot offload SSL or handle HTTP-specific features like session affinity.

How to eliminate wrong answers

Option B (Azure Load Balancer) is wrong because it operates at Layer 4 (TCP/UDP) and cannot perform SSL termination or inspect HTTP traffic; it only forwards packets without understanding application-layer protocols. Option C (Azure Traffic Manager) is wrong because it is a DNS-based traffic router that distributes traffic across regions, not within a single region, and it does not provide a fixed public IP for clients (it uses DNS names) nor offloads SSL. Option D (Azure Front Door) is wrong because it is a global Layer 7 service designed for multi-region scenarios with advanced WAF and acceleration features; it does not provide a fixed public IP for clients (it uses a dynamic anycast IP) and is overkill for a single-region deployment.

172
MCQeasy

A company plans to migrate an on-premises application with strict low-latency requirements to Azure. The application must communicate with an Azure SQL Database. Which of the following is the best design to minimize latency?

A.Deploy the application in one region and Azure SQL Database in a different region, using Azure Traffic Manager.
B.Deploy the application on-premises and use a Point-to-Site VPN to connect to Azure SQL Database.
C.Deploy the application and Azure SQL Database in the same Azure region, and connect via Azure Private Link.
D.Deploy the application on-premises and use ExpressRoute to connect to Azure SQL Database.
AnswerC

Deploying the application and Azure SQL Database in the same Azure region minimizes physical distance between compute and data, drastically reducing network round-trip time. Azure Private Link creates a private endpoint with a NIC in the application's virtual network, so all SQL traffic flows over the Microsoft backbone and never traverses the public internet. This combination delivers the lowest possible latency and a secure, isolated connectivity path, meeting the performance and migration requirements in a best-practice architecture.

Why this answer

The best design because deploying both the application and Azure SQL Database in the same Azure region minimizes network distance and latency. Using Azure Private Link creates a private endpoint for the SQL Database within the application's virtual network, eliminating internet routing and reducing latency further by keeping traffic entirely within the Microsoft backbone network.

Exam trap

The trap here is that candidates often overestimate ExpressRoute's ability to eliminate latency, forgetting that physical distance from on-premises to Azure still adds delay, while co-locating both application and database in the same region with Private Link provides the lowest possible latency.

How to eliminate wrong answers

Option A is wrong because deploying the application and database in different regions introduces cross-region network latency, and Azure Traffic Manager only handles DNS-level load balancing, not direct low-latency connectivity. Option B is wrong because a Point-to-Site VPN over the internet adds significant latency due to encryption overhead and variable internet routing, failing to meet strict low-latency requirements. Option D is wrong because ExpressRoute provides a dedicated private connection from on-premises to Azure, but the application remains on-premises, so the network round-trip from on-premises to the Azure region still introduces higher latency compared to keeping both resources in the same Azure region.

173
MCQmedium

Refer to the exhibit. You are reviewing a backup policy for an Azure VM. The policy is defined using the Azure Backup REST API. What is the maximum number of recovery points that can be retained according to this policy?

A.24
B.17
C.29
D.12
AnswerA

12 weekly (every Mon, Wed, Fri for 12 weeks) + 12 monthly (first Sunday each month for 12 months) = 24 recovery points.

Why this answer

The weekly retention keeps 12 weekly points (count=12, durationType=Weeks). The monthly retention keeps 12 monthly points (count=12, durationType=Months). Instant RP retention adds up to 5 days, but those are additional recovery points not counted in the long-term retention.

So total long-term recovery points = 12 (weekly) + 12 (monthly) = 24. Option A is correct.

174
MCQeasy

Your company has multiple Azure subscriptions and needs a single pane of glass to monitor the health and performance of all resources across subscriptions. Which Azure service should you use?

A.Microsoft Sentinel
B.Azure Service Health
C.Azure Monitor
D.Azure Advisor
AnswerC

Azure Monitor is the central monitoring platform in Azure that collects, analyzes, and responds to telemetry from secure resources, applications, and even on-premises systems. It acquires platform metrics, custom logs, and diagnostics data via Azure Diagnostics extensions and Log Analytics agent, enabling comprehensive visibility into resource health, performance, and dependencies across all subscriptions in a tenant. Azure Monitor supports powerful querying with KQL, creating alert rules, and visualizing dashboards, making it the exact service for a requirement spanning multiple subscriptions. It is the correct answer because it is purpose-built for unified resource observability.

Why this answer

Azure Monitor is the correct choice because it provides a unified, single-pane-of-glass experience for collecting, analyzing, and acting on telemetry from all Azure resources across multiple subscriptions. It aggregates metrics, logs, and alerts from various sources, enabling cross-subscription monitoring of health and performance without requiring separate tools.

Exam trap

The trap here is confusing Azure Monitor's broad monitoring capabilities with specialized services like Sentinel (security) or Service Health (Azure infrastructure status), leading candidates to pick a tool that addresses only a subset of the requirement.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) tool focused on security detection, investigation, and response, not general resource health and performance monitoring. Option B is wrong because Azure Service Health provides personalized alerts and guidance for Azure service issues and planned maintenance, but it does not monitor the health and performance of your own deployed resources. Option D is wrong because Azure Advisor is a personalized cloud consultant that offers best-practice recommendations for cost, security, reliability, and performance, but it does not provide real-time monitoring or a dashboard for resource health and performance.

175
MCQmedium

A company is designing a disaster recovery solution for a critical application that runs on Azure VMs in a single region. The RTO is 4 hours, and the RPO is 1 hour. The application uses Azure SQL Database. The company wants to minimize the cost of the disaster recovery solution while meeting the RTO and RPO. You need to recommend a solution. What should you recommend?

A.Use Azure SQL Database active geo-replication for the database and Azure Backup for VMs.
B.Use Azure Backup to back up VMs and Azure SQL Database to a secondary region.
C.Use Azure Traffic Manager to distribute traffic to VMs in multiple regions and Azure SQL Database failover groups.
D.Use Azure Site Recovery to replicate VMs to a secondary region and Azure SQL Database geo-replication for the database.
AnswerD

Azure Site Recovery continuously replicates managed disks of Azure VMs to the paired region with an RPO typically measured in seconds to a few minutes, and it supports automated, testable failover, so the compute tier comfortably meets the 1-hour RPO. Azure SQL Database geo-replication (or failover groups) asynchronously replays committed transactions to a secondary database, providing an RPO of seconds and enabling simple failover for the data tier. This combination covers both compute and data with continuous replication rather than backup or traffic routing, making it the correct DR architecture.

Why this answer

Azure Site Recovery provides orchestrated replication and failover for Azure VMs, meeting the 4-hour RTO with automated recovery plans. Azure SQL Database active geo-replication (or failover groups) enables continuous data synchronization with an RPO of 1 hour. This combination minimizes cost by using only the necessary replication services without over-provisioning resources.

Exam trap

The trap here is that candidates often confuse Azure Backup (long-term backup) with Azure Site Recovery (disaster recovery replication), leading them to choose a backup-only solution that cannot meet the RTO/RPO for rapid failover.

How to eliminate wrong answers

Option A is wrong because Azure Backup for VMs is designed for long-term retention and point-in-time restore, not for rapid failover to a secondary region; its RTO typically exceeds 4 hours for full VM recovery. Option B is wrong because Azure Backup for Azure SQL Database backs up to a secondary region as a backup copy, not as a continuously synchronized replica, so it cannot achieve a 1-hour RPO for disaster recovery failover. Option C is wrong because Azure Traffic Manager handles DNS-level traffic distribution but does not replicate VMs or databases; it requires pre-existing multi-region deployments, which contradicts the single-region design and would increase costs unnecessarily.

176
Multi-Selecthard

A company wants to ensure that their Azure Storage account containing blobs is protected against accidental deletion or corruption. The solution must enable recovery of previous versions up to 30 days. Which TWO features should they enable? (Choose TWO.)

Select 2 answers
A.Blob versioning
B.Blob soft delete
C.Change feed
D.Azure Backup for Azure Blobs
E.Point-in-time restore for Azure Files
AnswersA, B

Blob versioning automatically captures the state of a blob each time it is modified, preserving an accessible copy of every previous version in the same storage account. If the current blob is accidentally overwritten or corrupted, you can promote a prior version to restore the blob without relying on a separate backup service.

Why this answer

Blob versioning automatically maintains previous versions of a blob when it is modified or deleted, enabling recovery of any version from the last 30 days if combined with a lifecycle management policy to retain versions for that period. Blob soft delete protects against accidental deletion by preserving deleted blobs in a soft-deleted state for a specified retention period (up to 30 days), allowing restoration within that window. Together, they provide comprehensive protection against both accidental deletion and corruption.

Exam trap

The trap here is that candidates often confuse Azure Backup for Azure Blobs (a separate backup service) with native blob protection features like versioning and soft delete, or they mistakenly think Change feed provides recovery capabilities when it only logs changes.

177
MCQhard

Refer to the exhibit. An administrator configured Azure Site Recovery replication for a VM using the policy shown. The VM workload is a critical database that requires application-consistent snapshots every 30 minutes to meet compliance. What is the issue with the current configuration?

A.The application-consistent snapshot frequency is 60 minutes, which is too high (should be 30 minutes).
B.The recovery point retention is set too low (1440 minutes).
C.The target region eastus2 is not a valid paired region for the source.
D.The storage account type is Standard_LRS; it should be Premium_LRS.
AnswerA

The Azure Site Recovery replication policy is configured for application-consistent snapshots every 60 minutes. This directly contradicts the compliance requirement for the critical database workload, which mandates application-consistent snapshots every 30 minutes. The policy's application-consistent snapshot frequency setting must be reduced to 30 minutes to meet the specified compliance constraint.

Why this answer

The current policy sets the application-consistent snapshot frequency to 60 minutes, but the compliance requirement demands a snapshot every 30 minutes. Application-consistent snapshots are taken by the Azure Site Recovery mobility service using VSS (Volume Shadow Copy Service) on Windows, and the frequency is configured in the replication policy. Since the requirement is 30 minutes, the policy must be adjusted to match that interval.

Exam trap

The trap here is that candidates may confuse crash-consistent snapshots (which can be as frequent as every few seconds) with application-consistent snapshots, or assume that retention or storage type is the root cause, when the actual constraint is the snapshot frequency mismatch.

How to eliminate wrong answers

Option B is wrong because the recovery point retention of 1440 minutes (24 hours) is a typical and acceptable value for critical workloads; there is no indication that it is too low. Option C is wrong because eastus2 is a valid paired region for eastus (the source region is not specified, but eastus2 is commonly paired with eastus in Azure's regional pairs). Option D is wrong because the storage account type (Standard_LRS vs Premium_LRS) affects performance and cost, not the ability to meet the 30-minute snapshot compliance requirement; the issue is purely about snapshot frequency, not storage tier.

178
MCQhard

Refer to the exhibit. You are assigned an Azure policy that restricts resource group locations to eastus, westus, and centralus. A user attempts to create a resource group in 'eastus2' and receives a denial. The user argues that there are existing resources in 'eastus2' and that the policy should allow it. What is the best course of action to allow the resource group creation while maintaining compliance?

A.Instruct the user to create the resource group in an allowed location and then deploy resources to 'eastus2'
B.Add 'eastus2' to the list of allowed locations in the policy parameters
C.Create an Azure Policy exemption for the user's subscription
D.Disable the policy assignment for that subscription
AnswerA

The Azure Policy assignment targets the resource group resource type (Microsoft.Resources/subscriptions/resourceGroups), denying creation only when the group's location is not in the allowed list. Resource groups are logical containers, not regional boundaries; individual resources can be deployed to any region supported by the subscription, including eastus2. Instructing the user to create the resource group in an allowed location and then deploy to eastus2 satisfies the policy while preserving the intended geo-compliance controls.

Why this answer

Azure Policy evaluates resource group location at creation time, not the location of individual resources within it. A resource group is a logical container that can hold resources in any region, regardless of the resource group's own location. By creating the resource group in an allowed location (eastus, westus, or centralus), the user satisfies the policy constraint while still being able to deploy resources to 'eastus2' within that resource group.

Exam trap

The trap here is that candidates mistakenly believe a resource group's location restricts where its resources can be deployed, when in fact Azure resource groups can contain resources from any region regardless of the resource group's own location.

How to eliminate wrong answers

Option B is wrong because it modifies the policy to allow 'eastus2' globally, which weakens the compliance boundary and may violate organizational requirements. Option C is wrong because an exemption would bypass the policy entirely for the subscription, which is an over-engineered solution that reduces security posture and auditability. Option D is wrong because disabling the policy assignment removes all location restrictions for the subscription, which is a drastic measure that abandons compliance goals entirely.

179
MCQmedium

A company has 10 branch offices, each with Windows file servers. They want to centralize file storage in Azure and allow each branch office to cache files locally for fast access. The solution must support cloud tiering so that only frequently accessed files are kept locally. Which Azure service should they implement?

A.Azure File Sync
B.Azure Files
C.Azure Blob Storage with Azure File Sync
D.Azure NetApp Files
AnswerA

Azure File Sync is the only solution that provides continuous, multi-site synchronization between on-premises Windows file servers and Azure Files. Its cloud tiering feature keeps only the most frequently accessed files on each branch server's local disk while transparently offloading the rest to Azure, allowing each office to retain a fast, cache-like working set without requiring a full copy. This gives you a single cloud namespace with local caching and hierarchical sync across all branch offices.

Why this answer

Azure File Sync is the correct choice because it enables centralizing file shares in Azure Files while providing local caching on Windows file servers at each branch office. It supports cloud tiering, which automatically keeps only frequently accessed files locally and moves cold data to the cloud, meeting the requirement for fast local access and efficient storage.

Exam trap

The trap here is that candidates often confuse Azure Files (a standalone cloud file share) with Azure File Sync (the hybrid caching and sync service), or incorrectly assume Azure Blob Storage can be used with File Sync, when in fact File Sync only integrates with Azure Files.

How to eliminate wrong answers

Option B (Azure Files) is wrong because it provides cloud-based file shares without native local caching or cloud tiering; it requires Azure File Sync to achieve those capabilities. Option C (Azure Blob Storage with Azure File Sync) is wrong because Azure File Sync works exclusively with Azure Files, not Azure Blob Storage; Blob Storage is designed for unstructured data and does not support the SMB protocol or file-level caching needed for branch office file servers. Option D (Azure NetApp Files) is wrong because it is a high-performance, enterprise-grade NFS/SMB file service for specialized workloads like HPC, not designed for distributed branch office caching with cloud tiering, and it lacks the integrated sync and tiering features of Azure File Sync.

180
MCQeasy

A multinational company uses Microsoft Entra ID. The company has regional IT teams that need to manage users and groups within their respective regions. Each region has a distinct set of users in specific organizational units. The company wants to assign the User Administrator role to regional IT staff, but limit their scope to only the users in their region. Which Microsoft Entra ID feature should they use?

A.Administrative Units
B.Dynamic Groups
C.Microsoft Entra ID B2B
D.Microsoft Entra ID Identity Protection
AnswerA

Administrative Units are the correct approach because they partition a tenant's users, groups, and devices into explicit management boundaries. An administrator can assign a built-in or custom role such as User Administrator or Helpdesk Administrator scoped to a specific Administrative Unit, so regional IT staff see and manage only the objects in their local unit. This gives the desired delegated administration while preventing tenant-wide access.

Why this answer

Administrative Units in Microsoft Entra ID allow you to delegate administrative roles, such as User Administrator, to a specific subset of users and groups defined by organizational boundaries (e.g., region). By creating an Administrative Unit for each region and adding the regional users and groups to it, you can assign the User Administrator role scoped to that unit, ensuring regional IT staff can only manage their own region's identities.

Exam trap

The trap here is that candidates often confuse Administrative Units with Dynamic Groups, thinking that group-based membership scoping is equivalent to role-based administrative scoping, but Dynamic Groups only control group membership, not administrative permissions.

How to eliminate wrong answers

Option B is wrong because Dynamic Groups automatically manage group membership based on user attributes (e.g., department), but they do not provide role-based access control scoping; they cannot restrict administrative permissions to a subset of users. Option C is wrong because Microsoft Entra ID B2B is designed for external collaboration with guest users from partner organizations, not for delegating administrative control over internal users within the same tenant. Option D is wrong because Microsoft Entra ID Identity Protection is a security feature that detects and responds to identity risks (e.g., compromised credentials), and it does not offer any capability to scope administrative roles to specific users or regions.

181
MCQeasy

A company needs to store large amounts of unstructured data such as images and videos for a content management system. The data must be accessible via HTTPS and support tiered storage for cost optimization. Which Azure service should they use?

A.Azure Cosmos DB
B.Azure Blob Storage
C.Azure Data Lake Storage
D.Azure Files
AnswerB

Azure Blob Storage is Microsoft's object storage solution, purpose-built for storing massive amounts of unstructured data—anything from text and binary streams to images, logs, and application backups. It exposes a flat namespace via REST over HTTPS, supports data tiering to hot/cool/archive for cost optimization, and provides life-cycle management, soft-delete, and replication options that meet enterprise durability and disaster-recovery requirements. Because the requirement explicitly calls for large-scale unstructured data and HTTPS access, Blob Storage is the direct, default Azure service for that scenario.

Why this answer

Azure Blob Storage is the correct choice because it is designed for storing large amounts of unstructured data (such as images and videos) and provides HTTPS access. It also offers tiered storage (hot, cool, cold, and archive tiers) to optimize costs based on data access patterns, making it ideal for a content management system.

Exam trap

The trap here is that candidates often confuse Azure Data Lake Storage (which is built on Blob Storage) as a separate service for unstructured data, but it is specifically optimized for analytics workloads, not general-purpose content management with tiered storage.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL document database designed for structured or semi-structured data with low-latency queries, not for storing large unstructured blobs like images and videos. Option C is wrong because Azure Data Lake Storage is built on Blob Storage but is optimized for big data analytics workloads (e.g., Hadoop/Spark) and hierarchical namespaces, not for general-purpose content management with tiered storage. Option D is wrong because Azure Files provides SMB and NFS file shares for shared file access, not HTTPS-based blob storage, and its tiering is limited to transaction-optimized, hot, and cool tiers, lacking the full archive tier for deep cost optimization.

182
MCQeasy

You need to ensure that only authorized users can access the Azure portal. What should you use?

A.Conditional Access policies
B.Azure RBAC
C.Privileged Identity Management (PIM)
D.Azure AD Identity Protection
AnswerA

Conditional Access policies are Azure AD policies that evaluate multiple signals—such as user and group membership, device compliance, location, and sign-in risk—before allowing access to the Azure portal. They can enforce multi-factor authentication, block access from high-risk geographies, or require hybrid-joined devices, thereby making the authorization decision at the authentication layer. This is the correct mechanism for ensuring only authorized users can access the portal, because it does not rely on resource-level permissions but on the user's identity and sign-in context.

Why this answer

Conditional Access policies are the correct choice because they enforce access control decisions at the Azure AD authentication layer, allowing you to require specific conditions (e.g., MFA, compliant device, trusted IP) before a user can sign in to the Azure portal. This directly ensures that only authorized users—those meeting the defined conditions—can access the portal, regardless of their role assignments. Azure RBAC controls what actions a user can perform after authentication, not whether they can sign in at all.

Exam trap

The trap here is confusing authorization (what you can do after signing in, handled by RBAC) with authentication and access control (who can sign in, handled by Conditional Access), leading candidates to incorrectly choose Azure RBAC or PIM.

How to eliminate wrong answers

Option B is wrong because Azure RBAC (Role-Based Access Control) manages permissions for Azure resources after authentication, such as who can create VMs or read storage accounts, but it does not control the initial sign-in process to the Azure portal. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time activation and approval workflows for privileged roles, but it does not block unauthorized users from accessing the portal; it only manages role assignments and activation. Option D is wrong because Azure AD Identity Protection detects and responds to identity risks (e.g., leaked credentials, sign-ins from anonymous IPs) but does not directly enforce access control policies to block unauthorized users from the portal; it feeds risk signals into Conditional Access for enforcement.

183
MCQmedium

A company runs a critical application on Azure Virtual Machines in a single availability set. They want to protect against an entire Azure region failure. They need a recovery time objective (RTO) of 30 minutes and a recovery point objective (RPO) of 15 minutes. Which solution should they use?

A.Azure Backup for VMs with geo-redundant backup storage.
B.Azure Site Recovery to another region.
C.Deploy VMs in an availability zone within the same region.
D.Use Azure managed disks with geo-replication (LRS to GRS).
AnswerB

Azure Site Recovery replicates VMs continuously to a secondary region. It can achieve RPO as low as 15 seconds (with app-consistent snapshots) and RTO of minutes (30 minutes is typical). It supports planned and unplanned failover.

Why this answer

Azure Site Recovery (ASR) provides orchestrated replication, failover, and failback of Azure VMs to a secondary region, enabling a recovery time objective (RTO) of 30 minutes and a recovery point objective (RPO) of 15 minutes as required. ASR replicates VM disks continuously to the target region, and in a regional failure, you can initiate a planned or unplanned failover to bring up the application within the specified RTO/RPO. This is the only option that offers both cross-region disaster recovery and the granular recovery objectives stated.

Exam trap

The trap here is that candidates often confuse Azure Backup (which provides long-term retention with geo-redundancy) with Azure Site Recovery (which provides near-synchronous replication and automated failover), leading them to select Option A despite its inability to meet the strict RTO/RPO requirements.

How to eliminate wrong answers

Option A is wrong because Azure Backup with geo-redundant storage (GRS) is designed for long-term backup and restore, not for rapid failover; its typical RTO is hours or days, not 30 minutes, and it does not support orchestrated cross-region failover. Option C is wrong because deploying VMs in an availability zone within the same region protects against datacenter failures, not an entire Azure region failure, and thus does not meet the requirement for cross-region disaster recovery. Option D is wrong because Azure managed disks with geo-replication (LRS to GRS) is not a supported feature—managed disks use locally redundant storage (LRS) by default and cannot be directly geo-replicated; the misconception is that GRS applies to disks, but it applies only to storage accounts, and even then it does not provide the orchestrated failover or RTO/RPO guarantees of Azure Site Recovery.

184
MCQmedium

Refer to the exhibit. You have an Azure Storage account with hierarchical namespace enabled. You create this JSON policy to assign to a container. Users report that they can access the container from any IP, not just the specified range. What is the most likely reason?

A.Hierarchical namespace disables IP-based restrictions
B.Anonymous access is enabled on the container
C.IP address conditions are not supported in RBAC for Azure Storage data plane operations
D.The resource scope is incorrect; RBAC cannot be assigned at the container level
AnswerC

Azure RBAC condition expressions, part of ABAC (attribute-based access control), support a limited set of attributes for a given action. For Azure Storage data-plane operations, the supported condition attributes include container names, blob paths, tags, and request metadata—but the client's IP address is not among them. Therefore, any attempt to add an IP-address condition to an RBAC role assignment for a storage scope will not be evaluated, and the policy cannot restrict traffic by IP. The recommended mechanism for IP filtering is the storage account firewall, which operates independently of RBAC.

Why this answer

RBAC roles for Azure Storage data plane operations do not support IP address conditions in role assignments. IP address conditions are only supported for Azure Resource Manager (control plane) RBAC roles, not for data plane operations like accessing blob or container data. Since the policy uses RBAC with an IP condition, the condition is ignored, and access is allowed from any IP.

Exam trap

The trap here is that candidates confuse RBAC conditions with Azure Storage firewall rules, assuming that IP conditions can be applied directly in RBAC role assignments for data plane operations, when in fact IP restrictions must be configured separately via the storage account's networking blade.

How to eliminate wrong answers

Option A is wrong because hierarchical namespace (Azure Data Lake Storage Gen2) does not disable IP-based restrictions; IP-based network rules can still be applied via Azure Storage firewall and virtual network settings, but not via RBAC conditions. Option B is wrong because anonymous access being enabled would allow unauthenticated access, but the question states users are authenticated and reporting that IP restrictions are not enforced, which points to a RBAC condition issue, not anonymous access. Option D is wrong because RBAC can be assigned at the container level for data plane operations; the scope is valid, but the IP condition within the RBAC assignment is unsupported.

185
MCQhard

You are a cloud architect at a healthcare company. They have an existing application running on Azure VMs in a single region. The application uses SQL Server on a VM for its database. The company is migrating to Azure SQL Managed Instance for better manageability and compliance. The database is 2 TB and requires point-in-time restore (PITR) capability with a retention period of 35 days. The workload is critical with an RPO of 5 minutes and an RTO of 2 hours. The company wants to minimize costs while meeting these requirements. Which of the following should you recommend?

A.Use Azure SQL Managed Instance with automated backups configured for 35-day retention and a backup storage redundancy of Locally Redundant Storage (LRS)
B.Use Azure SQL Managed Instance with active geo-replication to a secondary region
C.Use Azure SQL Managed Instance with long-term retention (LTR) backups
D.Use Azure SQL Database with the Hyperscale service tier
AnswerA

Automated backups in Azure SQL Managed Instance are enabled by default and retain full, differential, and transaction log backups to support point-in-time restore (PITR) within the configured retention period. You can set the retention to exactly 35 days, the maximum for Managed Instance, and choose Locally Redundant Storage (LRS) to minimize backup storage cost while still meeting the recovery requirement. LRS is cost-effective because it replicates only within the same data center, which is sufficient for PITR when no geo-redundancy requirement exists.

Why this answer

Azure SQL Managed Instance's automated backups with a 35-day retention period and LRS storage meet the PITR requirement while minimizing cost. LRS is the cheapest redundancy option and sufficient for PITR within a single region, as the RPO of 5 minutes is satisfied by the default transaction log backup frequency (every 5-10 minutes). The RTO of 2 hours is achievable by restoring from these backups, and no cross-region replication is needed since the workload is single-region.

Exam trap

The trap here is that candidates often confuse PITR retention with long-term retention (LTR) or assume geo-replication is required for any critical workload, but the question's RPO/RTO and single-region focus make automated backups with LRS the most cost-effective choice.

How to eliminate wrong answers

Option B is wrong because active geo-replication is designed for disaster recovery across regions, which is not required here; it adds unnecessary cost and complexity for a single-region workload with a 2-hour RTO that can be met by local backups. Option C is wrong because long-term retention (LTR) backups are for archival retention beyond 35 days (e.g., years), not for meeting the 35-day PITR requirement; automated backups already cover this period at lower cost. Option D is wrong because Azure SQL Database Hyperscale is a different service tier with a different architecture (e.g., page servers, log-based replication) and does not support SQL Managed Instance features like full instance-level compatibility, which is needed for the migration from SQL Server on a VM.

186
MCQeasy

A company stores backup data for Azure VMs in a Recovery Services vault. They need to ensure that the backup data is protected from accidental deletion and remains available even if the entire Azure region fails. What should you configure?

A.Assign Azure RBAC roles to limit access to the vault.
B.Enable soft delete in the vault and use geo-redundant storage (GRS).
C.Enable immutable storage for the vault.
D.Enable locally redundant storage (LRS) for the vault.
AnswerB

Soft delete for a Recovery Services vault retains accidentally deleted backup data for an additional 14 days after deletion, allowing it to be recovered before permanent purge; this directly protects against accidental or malicious deletion of backup items. Geo-redundant storage (GRS) copies backup data to a paired Azure region, so even if the primary region's datacenter fails, the backup data remains available for restore from the secondary region. Together, these two controls address both deletion protection and cross-region disaster recovery.

Why this answer

Enabling soft delete protects backup data from accidental deletion by retaining deleted data for a default retention period of 14 days, allowing recovery. Using geo-redundant storage (GRS) replicates vault data to a paired secondary Azure region, ensuring availability even if the entire primary region fails. Together, these features meet both protection and regional failover requirements.

Exam trap

The trap here is that candidates often confuse immutable storage (a Blob Storage feature) with backup vault protection, or think RBAC alone prevents deletion, overlooking that soft delete and GRS are the specific Azure Backup mechanisms for deletion protection and regional resilience.

How to eliminate wrong answers

Option A is wrong because Azure RBAC roles control access permissions but do not protect against accidental deletion by authorized users or provide geo-redundancy for regional failures. Option C is wrong because immutable storage for a Recovery Services vault is not a supported feature; immutable storage applies to Azure Blob Storage, not backup vaults. Option D is wrong because locally redundant storage (LRS) replicates data only within a single datacenter, which does not protect against a full region failure.

187
Multi-Selecteasy

Your organization is implementing a security strategy for Azure resources. You need to enforce consistent security policies across all subscriptions and ensure compliance with regulatory standards. Which TWO services should you use?

Select 2 answers
A.Azure RBAC
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Azure Blueprints
E.Azure Policy
AnswersB, E

Microsoft Defender for Cloud continuously assesses Azure resources against regulatory benchmarks such as ISO 27001 and PCI DSS, surfacing compliance posture across every subscription through its regulatory compliance dashboard. This satisfies the stem's requirement for consistent policy enforcement and demonstrated regulatory compliance, complementing Azure Policy's preventive controls with detection and recommendations.

Why this answer

Microsoft Defender for Cloud (B) is correct because it provides continuous security assessment and regulatory compliance dashboards against standards such as ISO 27001, PCI DSS, and NIST, letting you measure and enforce compliance across subscriptions. Azure Policy (E) is correct because it enforces organizational standards and assesses compliance at scale by evaluating resource properties against policy definitions and applying deny, audit, or deployIfNotExists effects across all subscriptions. Together they cover both policy enforcement and regulatory compliance monitoring.

Azure RBAC (A) only controls who can perform actions on resources and does not enforce configuration or regulatory standards. Microsoft Sentinel (C) is a SIEM/SOAR solution for threat detection and incident response, not policy or compliance enforcement. Azure Blueprints (D) orchestrates deployments of artifacts including policies, but it is a deployment/governance packaging tool rather than the service that itself enforces and reports compliance across subscriptions.

188
MCQeasy

Refer to the exhibit. A KQL query is run against Azure Storage logs. The result shows a high number of 404 errors for 'GetBlob' operations. What is the most likely cause?

A.The client does not have permission to access the blobs
B.The storage account is throttling requests
C.The blobs being requested do not exist
D.The client is using an incorrect authentication method
AnswerC

A 404 response for a blob operation in Azure Storage corresponds to the BlobNotFound error code, meaning the specified blob does not exist at that path or has been deleted. Because the query returned this code rather than 403 or 429, authentication and rate limits were satisfied. The only remaining conclusion is that the requested blob (or its container) is missing, perhaps due to an incorrect name, a different container, or lifecycle policy deletion.

Why this answer

A 404 (Not Found) error for 'GetBlob' operations in Azure Storage logs specifically indicates that the requested blob resource does not exist at the specified URI. This is distinct from authorization failures (which return 403) or throttling (which returns 503). The high number of 404 errors suggests the client is attempting to retrieve blobs that have been deleted, never created, or are referenced with an incorrect path.

Exam trap

The trap here is that candidates confuse 404 (Not Found) with 403 (Forbidden), assuming that a missing blob is caused by a permissions problem, but Azure strictly differentiates these status codes based on whether the resource exists versus whether access is denied.

How to eliminate wrong answers

Option A is wrong because permission issues (e.g., missing RBAC role or SAS token) result in a 403 (Forbidden) error, not 404. Option B is wrong because throttling by the storage account returns a 503 (Server Busy) or 429 (Too Many Requests) status code, not 404. Option D is wrong because an incorrect authentication method (e.g., using an invalid key or expired SAS) also leads to a 403 (Forbidden) error, as the request is authenticated but not authorized, or a 401 (Unauthorized) if the authentication header is missing or malformed.

189
MCQhard

Your organization is migrating an on-premises application to Azure. The application consists of a load-balanced web tier and a backend SQL Server database. The web tier requires session persistence (sticky sessions) and SSL offload. You need to design a solution that meets these requirements with minimal operational overhead. Which Azure service should you use for the web tier load balancing?

A.Azure Traffic Manager
B.Azure Application Gateway
C.Azure Front Door
D.Azure Load Balancer
AnswerB

Azure Application Gateway is a regional, Layer 7 reverse proxy explicitly built for HTTP/HTTPS workloads, making it the correct choice for an on-premises migration that needs session affinity and SSL termination. Its cookie-based session affinity preserves client sessions to the same backend server, and its SSL offload capability decrypts HTTPS traffic at the gateway so backend VMs avoid CPU-intensive encryption work. These features map directly to the requirements, and the gateway operates within a single region, aligning with the migration scale.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that natively supports HTTP-based session persistence (sticky sessions) via cookie affinity and SSL termination (offload) at the gateway. This meets both requirements while minimizing operational overhead, as it handles SSL certificates and session affinity without requiring changes to the web tier.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support SSL offload and sticky sessions, but only Layer 7 services can inspect HTTP traffic for these features.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager is a DNS-level traffic router that operates at Layer 3/4 and cannot perform SSL offload or maintain session persistence based on HTTP cookies. Option C is wrong because Azure Front Door is a global Layer 7 load balancer and CDN that supports SSL offload and session affinity, but it is designed for global distribution with edge caching and WAF, introducing unnecessary complexity and cost for a single-region web tier requiring minimal overhead. Option D is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot inspect HTTP headers for session persistence or terminate SSL, making it unsuitable for sticky sessions and SSL offload.

190
MCQmedium

A company is migrating on-premises Windows applications that require LDAP, NTLM, or Kerberos authentication to Azure VMs. They want to provide domain services for these applications without deploying and managing domain controllers. Which Azure service should they use?

A.Microsoft Entra ID
B.Microsoft Entra ID Domain Services
C.Active Directory on Azure VMs
D.Microsoft Entra ID B2C
AnswerB

Microsoft Entra ID Domain Services (AAD DS) provides a fully managed Windows Server Active Directory-compatible domain controller that is synchronized from Entra ID. It natively supports LDAP, including secure LDAP (LDAPS), and NTLM/Kerberos authentication, making it the intended choice for lifting and shifting on-premises apps that need an AD-joined infrastructure. Microsoft handles patching, availability, and domain controller replication, eliminating the administration burden.

Why this answer

Microsoft Entra ID Domain Services (formerly Azure AD DS) provides managed domain services such as LDAP, NTLM, and Kerberos authentication without requiring you to deploy, patch, or manage domain controllers. It integrates with your existing Microsoft Entra tenant and supports group policy, domain join, and legacy authentication protocols needed by the on-premises Windows applications being migrated to Azure VMs.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID (a modern identity provider) with Microsoft Entra ID Domain Services (which provides legacy protocol support), leading them to incorrectly select Entra ID for LDAP/NTLM/Kerberos needs.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is a cloud-based identity and access management service that uses modern protocols like OAuth 2.0, OpenID Connect, and SAML, and does not natively support LDAP, NTLM, or Kerberos authentication required by legacy Windows applications. Option C is wrong because deploying Active Directory on Azure VMs would require you to manually manage domain controllers, which contradicts the requirement to avoid deploying and managing domain controllers. Option D is wrong because Microsoft Entra ID B2C is designed for customer-facing identity management with social and local account sign-ins, not for providing domain services like LDAP or Kerberos for enterprise applications.

191
Multi-Selecteasy

Which TWO features of Microsoft Entra ID help protect against credential compromise? (Choose two.)

Select 2 answers
A.Microsoft Entra Conditional Access
B.Microsoft Entra Identity Protection
C.Microsoft Entra Password Protection
D.Microsoft Entra Smart Lockout
E.Microsoft Entra access reviews
AnswersC, D

Microsoft Entra Password Protection actively blocks users from selecting weak or easily guessed passwords by maintaining a global banned password list (e.g., 'Password123', 'P@ssw0rd') and allowing tenant administrators to add custom banned words and patterns. It is applied at the point of password creation or change, preventing the credential from ever being set to a vulnerable value. This directly hardens the password against dictionary and guessing attacks, making it a correct answer.

Why this answer

Microsoft Entra Password Protection automatically blocks weak passwords and common password variations (e.g., 'Password123!') by comparing them against a global banned password list and an optional custom banned password list. This directly prevents users from setting easily guessable credentials, reducing the risk of credential compromise.

Exam trap

The trap here is that candidates often confuse detection/remediation features (Identity Protection) or policy enforcement (Conditional Access) with direct credential protection mechanisms, leading them to select options that manage risk after compromise rather than preventing weak passwords or brute-force attacks.

192
MCQhard

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a lifecycle workflow that automatically disables user accounts when employees leave the organization, and then deletes them after 30 days. What should you use?

A.Microsoft Entra Domain Services
B.Microsoft Entra ID Governance
C.Microsoft Intune
D.Microsoft Entra Connect Health
AnswerB

Microsoft Entra ID Governance contains Lifecycle Workflows, a feature that automates joiner, mover, and leaver scenarios by orchestrating tasks like sending notifications, assigning access, and disabling accounts. These workflows can be triggered by HR-driven provisioning, schedules, or on-demand execution, and they provide centralized logging and audit trails. This exactly addresses the company's need to automate lifecycle processes for 10,000 users, making it the correct choice.

Why this answer

Microsoft Entra ID Governance includes lifecycle workflows that automate the process of disabling and deleting user accounts based on triggers such as employee departure. This feature allows you to configure a workflow that disables the account immediately and then schedules deletion after a specified period, such as 30 days, without requiring custom scripting or manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Governance with Microsoft Entra Domain Services, mistakenly thinking that domain services include user lifecycle management, when in fact Entra ID Governance is the correct service for automated identity lifecycle tasks.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Domain Services provides managed domain services like LDAP and Kerberos, not lifecycle automation for user accounts. Option C is wrong because Microsoft Intune focuses on mobile device management (MDM) and mobile application management (MAM), not on automating user account lifecycle in Entra ID. Option D is wrong because Microsoft Entra Connect Health monitors the health of on-premises identity infrastructure and sync, not user account lifecycle workflows.

193
Multi-Selecthard

Which THREE components are required to implement a disaster recovery solution for Azure SQL Database using failover groups? (Choose three.)

Select 3 answers
A.A failover group that includes both servers
B.A secondary Azure SQL Database server in another region
C.Zone-redundant configuration on the primary database
D.A primary Azure SQL Database server in one region
E.Active geo-replication configured on the primary database
AnswersA, B, D

A failover group is the coordination element: it binds a primary and secondary logical server into a single unit and owns the geo-replication relationships between their databases. It also exposes a writable listener endpoint and, optionally, a read-only endpoint, which means client applications can fail over without changing connection strings. Without this object, you would have no unified policy or endpoint to orchestrate regional failover.

Why this answer

A failover group is the core orchestration component that manages the replication and automatic or manual failover of multiple databases between a primary and secondary Azure SQL Database server. It requires both a primary server in one region and a secondary server in another region to be included in the group, enabling a coordinated disaster recovery plan with a defined failover policy.

Exam trap

The trap here is that candidates often confuse active geo-replication with failover groups, thinking both are required, when in fact failover groups subsume the replication functionality and provide a simpler management model with automatic failover capabilities.

194
MCQmedium

A company runs a multi-tier application on Azure VMs. The application has front-end and back-end VMs that must be started in a specific order during failover (front-end first, then back-end). The company uses Azure Site Recovery to replicate to a secondary region. After failover, they also need to run custom PowerShell scripts to update DNS records. Which Azure Site Recovery feature should they configure?

A.Recovery plan with manual steps
B.Recovery plan with automation runbooks and order groups
C.Failover with network mapping
D.Test failover with isolation
AnswerB

Recovery plans support order groups, so the web tier, application tier, and database tier can be assigned to separate groups that start strictly in the specified sequence. Automation runbooks can be attached as pre-action or post-action steps for each group, which lets you run custom scripts to reconfigure connections, update DNS, or mount storage right after each dependency is available. This combined capability not only satisfies the stated startup-order and script requirements but also makes failover predictable and fully automated.

Why this answer

Azure Site Recovery recovery plans support order groups to enforce the startup sequence of VMs (front-end first, then back-end) and can include automation runbooks to execute custom PowerShell scripts, such as updating DNS records after failover. This provides a structured, automated failover workflow that meets both the sequencing and scripting requirements.

Exam trap

The trap here is that candidates may confuse recovery plans with simple failover options, overlooking that recovery plans uniquely combine order groups and runbook automation to address both sequencing and custom scripting requirements in a single feature.

How to eliminate wrong answers

Option A is wrong because manual steps in a recovery plan require human intervention during failover, which contradicts the need to automatically run PowerShell scripts for DNS updates and does not inherently enforce VM startup order without additional configuration. Option C is wrong because network mapping defines how VMs connect to the target network after failover but does not control VM startup sequencing or execute custom scripts. Option D is wrong because test failover with isolation is used to validate failover in an isolated network without impacting production, but it does not provide mechanisms for startup order or script execution.

195
MCQmedium

A company uses Microsoft Entra ID B2B collaboration for external partners. They want to enforce that external users must use multi-factor authentication (MFA) and access company resources only from devices that are compliant with Intune policies. Additionally, they need to require a session timeout of 1 hour. Which combination of Microsoft Entra ID features should they use?

A.Configure cross-tenant access settings to trust MFA and device compliance from external organizations, and then create a Conditional Access policy that requires MFA, compliant device, and a session sign-in frequency of 1 hour.
B.Create a Conditional Access policy for external users that requires MFA and compliant device, and set session controls for sign-in frequency. Trusting MFA from external tenants is automatic.
C.Use Microsoft Entra ID Identity Protection to detect risky sessions for external users and require MFA only when risk is high. This will also enforce device compliance automatically.
D.Configure Microsoft Entra ID Privileged Identity Management (PIM) for external users to activate MFA and require compliant device. PIM is for role activation, not for external user access policies.
AnswerA

Cross-tenant access settings in Microsoft Entra ID let you explicitly trust MFA, compliant device, and hybrid Azure AD joined device claims that external organizations assert about their own users. After configuring that inbound trust for the partner tenant, you must create a Conditional Access policy that targets external users and grants access only when MFA is satisfied, a compliant device is reported, and the session sign-in frequency does not exceed one hour. This two-step approach is mandatory because the trust settings establish which claims are honored, while the Conditional Access policy defines the conditions and session controls that are actually enforced at the resource tenant.

Why this answer

Cross-tenant access settings in Microsoft Entra ID allow you to trust MFA and device compliance claims from external organizations, which is necessary when external users bring their own devices. Then, a Conditional Access policy targeting external users can enforce MFA, require compliant device, and set a session sign-in frequency of 1 hour using session controls. This combination ensures that the company's security requirements are met without relying on the external tenant's policies.

Exam trap

The trap here is that candidates assume MFA and device compliance from external users are automatically trusted or can be enforced solely through Conditional Access, forgetting that cross-tenant trust settings must be explicitly configured to accept those claims from the external organization.

How to eliminate wrong answers

Option B is wrong because trusting MFA from external tenants is not automatic; it must be explicitly configured in cross-tenant access settings, otherwise the Conditional Access policy cannot rely on MFA claims from the external user's home tenant. Option C is wrong because Identity Protection detects risk but does not enforce device compliance automatically; it can require MFA based on risk level but cannot mandate compliant device or session timeout. Option D is wrong because Privileged Identity Management (PIM) is designed for just-in-time role activation, not for enforcing MFA, device compliance, or session controls for external user access to resources.

196
MCQhard

A company has multiple Azure virtual networks (VNets) spread across three Azure regions (West US, East US, and West Europe). They also have an on-premises network connected to East US via ExpressRoute. They need to connect all VNets to each other and to the on-premises network. They require centralized management of routing and the ability to enforce security policies such as forcing all internet-bound traffic from any VNet to pass through a central firewall in East US. Which Azure solution should they implement?

A.VNet peering between all VNets and use route tables for forced tunneling.
B.Azure Virtual WAN with a secured hub in East US.
C.ExpressRoute Global Reach with VNet peering to connect all VNets.
D.VPN gateways with BGP to connect all VNets.
AnswerB

Azure Virtual WAN provides a scalable hub-and-spoke architecture with centralized routing. A secured hub can include a firewall to enforce forced tunneling and security policies. All VNets and on-premises connect to the hub(s), simplifying management.

Why this answer

Azure Virtual WAN with a secured hub in East US provides a centralized hub-and-spoke architecture that connects all VNets and the on-premises network via ExpressRoute. The secured hub includes Azure Firewall, enabling forced tunneling of all internet-bound traffic from any VNet through the central firewall in East US, while Virtual WAN automatically manages routing between all spokes and the on-premises network.

Exam trap

The trap here is that candidates often assume VNet peering with route tables (Option A) is sufficient for centralized security, but they overlook the operational complexity and lack of built-in forced tunneling enforcement across multiple regions, which Virtual WAN's secured hub solves natively.

How to eliminate wrong answers

Option A is wrong because VNet peering alone creates a full mesh that lacks centralized routing management and cannot enforce forced tunneling through a single firewall without complex route table configurations that become unmanageable across multiple regions. Option C is wrong because ExpressRoute Global Reach only connects on-premises networks to Azure and does not provide inter-VNet connectivity or centralized security policy enforcement; VNet peering would still be needed but without centralized routing. Option D is wrong because VPN gateways with BGP can connect VNets but require a full mesh of VPN tunnels and do not natively support forced tunneling of all internet traffic through a central firewall without additional complex routing and gateway configurations.

197
MCQeasy

Your company is implementing a new Azure subscription for a project that requires strict separation of duties. The security team requires that all resource creation must be approved by a central IT team. Additionally, any resource that does not comply with company tagging standards should be automatically reported. You need to design a solution that meets these requirements using Azure Policy and Azure Role-Based Access Control (RBAC). What should you do?

A.Use Azure Policy with 'Audit' effect to report non-compliant resources. Use Azure RBAC to assign Owner role to IT team.
B.Use Azure Policy with 'Append' effect to automatically add required tags at creation. Use Azure Monitor alerts for non-compliance.
C.Create an Azure Policy with 'DeployIfNotExists' to deploy a tagging template. Use Azure RBAC to assign Contributor role to IT team.
D.Create a custom RBAC role that allows only the IT team to add a specific 'Approved' tag. Use Azure Policy with 'Deny' effect to block resources without that tag. Use a separate 'Audit' policy for other tagging standards.
AnswerD

This solution enforces approval at the point of creation by combining a custom RBAC role that grants the IT team exclusive permission to write the 'Approved' tag (via Microsoft.Resources/tags/write) with an Azure Policy using the Deny effect that blocks any resource lacking that tag. When a deployment attempts to create a resource without the approved tag, the Deny policy causes the deployment to fail, making the approval a mandatory part of the provisioning process. A separate Audit policy then monitors other tagging standards, providing compliance visibility without blocking deployments, while the Deny policy enforces the critical approval requirement.

Why this answer

It uses a custom RBAC role to restrict the ability to add an 'Approved' tag to the IT team, combined with a Deny policy that blocks creation of any resource lacking that tag, ensuring all resource creation requires IT approval. The separate Audit policy automatically reports resources that fail to meet other company tagging standards, fulfilling both the approval and compliance reporting requirements without manual intervention.

Exam trap

The trap here is that candidates often think a simple RBAC role assignment (like Owner or Contributor) combined with an Audit policy is sufficient, but they overlook the need for a Deny policy to actively block unapproved resource creation, which is essential for strict separation of duties.

How to eliminate wrong answers

Option A is wrong because assigning the Owner role to the IT team grants them full control over all resources, including the ability to bypass approval and modify permissions, which violates strict separation of duties. Option B is wrong because the Append effect automatically adds required tags at creation but does not enforce approval; Azure Monitor alerts can report non-compliance but do not block unapproved creation or enforce tagging standards at the policy level. Option C is wrong because DeployIfNotExists deploys a tagging template to remediate non-compliant resources but does not prevent creation of unapproved resources; assigning Contributor role to the IT team allows them to create resources without requiring approval, breaking separation of duties.

198
MCQmedium

Refer to the exhibit. You are an Azure administrator reviewing a custom Azure Policy definition. What does this policy do?

A.Denies the creation of virtual machines with the SKUs Standard_D2s_v3 or Standard_D4s_v3.
B.Denies the creation of resource groups that contain virtual machines with the specified SKUs.
C.Allows only virtual machines with the SKUs Standard_D2s_v3 or Standard_D4s_v3 to be created in a specific region.
D.Audits virtual machines to check if they have the SKUs Standard_D2s_v3 or Standard_D4s_v3.
AnswerA

This policy definition uses the `Microsoft.Compute/virtualMachines/sku.name` property in its `if` condition, checking whether the SKU name matches either `Standard_D2s_v3` or `Standard_D4s_v3`. When a VM creation or update request contains one of these SKUs, the `Deny` effect is triggered and the deployment is blocked before any resource is provisioned. This is the correct interpretation because the policy targets the VM resource type directly, not the resource group or a specific region.

Why this answer

The policy definition uses the 'deny' effect, which blocks any request that matches the specified condition. The condition checks if the virtual machine SKU is either 'Standard_D2s_v3' or 'Standard_D4s_v3' using the 'in' operator on the 'Microsoft.Compute/virtualMachines/sku.name' alias. Therefore, any attempt to create a VM with these SKUs will be denied, making Option A correct.

Exam trap

The trap here is that candidates confuse the 'deny' effect with 'audit' or 'DeployIfNotExists', or misinterpret the condition as allowing only those SKUs instead of denying them, leading them to select Option C or D.

How to eliminate wrong answers

Option B is wrong because the policy targets the 'Microsoft.Compute/virtualMachines' resource type, not 'Microsoft.Resources/resourceGroups', and the condition evaluates the VM SKU, not the resource group's contents. Option C is wrong because the policy uses a 'deny' effect, not 'allow' or 'DeployIfNotExists', and it does not include any location-based condition (e.g., 'location' alias) to restrict creation to a specific region. Option D is wrong because the policy uses the 'deny' effect, not 'audit' or 'AuditIfNotExists', so it actively blocks creation rather than merely auditing existing VMs.

199
MCQmedium

You are designing a connectivity solution for a hybrid network. The company has an on-premises network connected to an Azure virtual network via ExpressRoute. They also have a site-to-site VPN to the same Azure virtual network as a backup. When the ExpressRoute connection fails, traffic should automatically fail over to the VPN. How should you configure the routes to ensure automatic failover?

A.Configure Azure Traffic Manager with a priority routing method to direct traffic to ExpressRoute first.
B.Ensure the ExpressRoute connection has a lower BGP metric than the VPN connection; Azure automatically prefers lower metric.
C.Set the BGP metrics (local preference) on the ExpressRoute connection to be higher than the VPN connection.
D.Configure Azure Route Server to propagate routes with a lower metric for the VPN connection.
AnswerB

ExpressRoute and VPN gateway BGP peering allow Azure to choose between the two paths by comparing BGP attributes; a lower BGP metric (such as MED) on the ExpressRoute connection makes it the preferred route because Azure selects the path with the lowest metric. When the ExpressRoute circuit fails, its route is withdrawn and the VPN route with the higher metric becomes the only available path, enabling automatic failover. This is the standard, supported coexistence design for resilient hybrid networking, and no additional traffic-management or routing services are required.

Why this answer

B is correct because when both ExpressRoute and VPN connections use BGP to advertise routes to Azure, Azure automatically selects the route with the lowest BGP metric (MED). By configuring the ExpressRoute connection with a lower BGP metric than the VPN connection, Azure will prefer the ExpressRoute path under normal conditions. If the ExpressRoute fails, its routes are withdrawn, and Azure falls back to the VPN routes, providing automatic failover.

Exam trap

The trap here is confusing BGP metrics (MED) with local preference; local preference is used for outbound path selection within an AS, while MED influences inbound path selection from a neighbor AS, and Azure uses MED for route preference in hybrid connectivity.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager operates at the DNS level and cannot influence routing within a hybrid network; it directs user traffic to endpoints based on DNS resolution, not IP-level path selection for existing connections. Option C is wrong because setting a higher BGP local preference on the ExpressRoute connection would make it less preferred (Azure prefers higher local preference), which would cause the VPN to be used as the primary path, not the backup. Option D is wrong because Azure Route Server is used to exchange routes between virtual network gateways and network virtual appliances (NVAs), not to set metrics for failover between ExpressRoute and VPN; lowering the metric for the VPN connection would make it preferred over ExpressRoute, defeating the failover purpose.

200
MCQhard

A company runs large-scale analytics workloads using Apache Hadoop and Spark. They need a cloud storage solution that is fully compatible with the Hadoop Distributed File System (HDFS) and provides unlimited storage with high throughput for parallel processing. They also want to take advantage of tiered storage to reduce costs for older data. Which Azure data service should they use?

A.Azure Blob Storage
B.Azure Data Lake Storage Gen2
C.Azure Files
D.Azure Disk Storage
AnswerB

Azure Data Lake Storage Gen2 is the correct choice because it merges Blob Storage's durable object storage with a hierarchical namespace and native HDFS support via the ABFS driver. It provides unlimited storage, POSIX-like permissions, atomic directory renames, and high throughput, enabling Spark and Hadoop jobs to run at scale without a dedicated HDFS cluster. Lifecycle tiering further reduces costs while retaining analytics performance.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with Azure Blob Storage, providing full HDFS compatibility. This allows Apache Hadoop and Spark workloads to use the `wasbs://` or `abfss://` driver for unlimited storage and high throughput parallel processing, while also supporting tiered storage (hot, cool, archive) to reduce costs for older data.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage (which is object storage without a hierarchical namespace) with ADLS Gen2, assuming both are equally HDFS-compatible, but only ADLS Gen2 provides the required HDFS semantics and the `abfss://` driver for native Hadoop/Spark integration.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage lacks a hierarchical namespace by default, making it incompatible with HDFS semantics (e.g., atomic directory operations) required by Hadoop/Spark; it also does not support the `abfss://` driver natively. Option C is wrong because Azure Files uses the SMB protocol and is designed for file shares, not for HDFS-compatible distributed storage; it cannot handle the massive throughput and parallel processing demands of large-scale analytics. Option D is wrong because Azure Disk Storage provides block-level storage attached to VMs, which is limited in capacity, not natively HDFS-compatible, and does not offer tiered storage for cost optimization of older data.

201
MCQhard

You executed the above Azure CLI commands. The remote VNet (yourVNet) has address space 10.1.0.0/16. What is the result?

A.The peering command fails because the remote VNet does not exist.
B.A VNet with one subnet is created, and no peering is established.
C.A VNet with two subnets is created, and a VNet peering is established.
D.Only the first subnet is created, and the peering is established.
AnswerC

The sequence of Azure CLI commands creates the VNet, adds a second subnet, and then creates a VNet peering from the local to the remote VNet. Both subnets are created before peering, and the peering resource is successfully provisioned, allowing resources in the two VNets to communicate.

Why this answer

The Azure CLI commands create a VNet named 'myVNet' with two subnets ('subnet1' and 'subnet2') using the 'az network vnet create' command, which supports multiple subnet configurations in a single call. The subsequent 'az network vnet peering create' command establishes a VNet peering from 'myVNet' to the remote VNet 'yourVNet' (address space 10.1.0.0/16). Since both VNets exist and the commands are syntactically correct, the result is a VNet with two subnets and a successful peering.

Exam trap

The trap here is that candidates may think the 'az network vnet create' command only creates a single subnet or that the peering command will fail due to missing parameters, but the CLI defaults allow both subnets and peering to succeed without explicit flags.

How to eliminate wrong answers

Option A is wrong because the remote VNet 'yourVNet' is assumed to exist (the question states it has address space 10.1.0.0/16), and the peering command would only fail if the remote VNet did not exist, but no error is indicated. Option B is wrong because the 'az network vnet create' command with '--subnets subnet1 subnet2' creates two subnets, not one, and the peering command is executed successfully. Option D is wrong because the '--subnets' parameter in 'az network vnet create' creates both specified subnets, not just the first, and the peering is established after the VNet creation.

202
MCQeasy

You are designing a solution to grant external partners access to specific Azure resources. The partners must authenticate using their own corporate credentials. You need to manage their access centrally. Which Microsoft Entra ID feature should you use?

A.Microsoft Entra ID Domain Services
B.Microsoft Entra ID B2C
C.Microsoft Entra ID B2B collaboration
D.Microsoft Entra ID Connect
AnswerC

Microsoft Entra ID B2B collaboration is the correct choice because it allows external partners to use their own corporate identities (from any Azure AD tenant, Microsoft account, or even Google/SAML/WS-Fed identity provider) to access your applications and resources. You invite the partner's users or enable self-service sign-up; they are represented as guest users in your Entra ID tenant, while their authentication is handled by their home organization. This preserves the partner's identity lifecycle and enables fine-grained conditional access policies, multi-factor authentication, and governance controls like access reviews, making it the standard for partner access scenarios.

Why this answer

Microsoft Entra ID B2B collaboration is the correct choice because it allows external partners to authenticate using their own corporate credentials (via their home tenant or identity provider) while enabling centralized management of their access to Azure resources. B2B collaboration supports features like cross-tenant synchronization, conditional access policies, and entitlement management, making it ideal for granting granular, centrally managed access to external users without requiring them to create new accounts.

Exam trap

The trap here is confusing B2B collaboration (for external partners with existing corporate identities) with B2C (for customer-facing applications with social or local accounts), as both involve external users but serve fundamentally different scenarios.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Domain Services provides managed domain services (e.g., LDAP, Kerberos, NTLM) for legacy applications, not for granting external partner access with their own credentials. Option B is wrong because Microsoft Entra ID B2C is designed for customer-facing identity management (e.g., social logins, self-service sign-up) for applications, not for business-to-business partner access to Azure resources. Option D is wrong because Microsoft Entra ID Connect is used for synchronizing on-premises Active Directory identities to the cloud, not for managing external partner access.

203
MCQhard

A multinational corporation needs to store and analyze petabytes of historical data for regulatory reporting. The data is rarely accessed but must be available for queries within 5 minutes. Which Azure storage solution should they choose to minimize cost?

A.Azure SQL Database
B.Azure Data Lake Storage Gen2
C.Azure Files
D.Azure Cosmos DB
AnswerB

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct foundation for petabyte-scale analytics because it combines Blob Storage's massive, low-cost capacity with a hierarchical namespace for folder-level permissions and efficient file management. It is engineered for high-throughput parallel scanning, and features like query acceleration allow filtering and aggregating large datasets without spinning up dedicated compute. Its native integration with Azure Synapse, Databricks, and HDInsight makes it the analytics data lake standard.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with Azure Blob Storage's massive scalability, enabling petabyte-scale storage at low cost. It supports fast queries via tools like Azure Synapse or PolyBase, meeting the 5-minute query SLA for cold data, while its tiered storage (e.g., Cool or Archive access tiers) minimizes cost for rarely accessed historical data.

Exam trap

The trap here is that candidates often choose Azure SQL Database or Cosmos DB for 'query performance' without considering the massive cost and architectural mismatch for petabyte-scale cold data, or they pick Azure Files thinking 'file storage' implies analytical capability, ignoring its lack of native query engines and higher cost per GB.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database is a relational OLTP service optimized for transactional workloads with structured data, not designed for petabyte-scale historical data storage and analysis, and its cost would be prohibitive for cold data. Option C is wrong because Azure Files provides SMB/NFS file shares for shared access, lacks native analytical query capabilities, and is not cost-effective for petabyte-scale archival storage. Option D is wrong because Azure Cosmos DB is a NoSQL database for low-latency, globally distributed real-time applications, not suited for petabyte-scale historical data analysis, and its provisioned throughput model would be excessively expensive for rarely accessed data.

204
MCQmedium

An organization wants to enforce MFA only when sign-in risk is medium or high. Which Microsoft Entra capability should be used?

A.Azure RBAC deny assignments only
B.Conditional Access with Identity Protection risk signals
C.Access reviews only
D.Administrative units only
AnswerB

Conditional Access policies can directly reference Identity Protection sign-in risk levels (low, medium, high) and evaluate them during the authentication event. Configuring a policy to require MFA when sign-in risk is medium or high achieves the exact requirement, while optionally adding a block action for high risk. This is the built-in Azure AD mechanism for dynamic, risk-based step-up authentication.

Why this answer

Conditional Access policies can integrate with Microsoft Entra Identity Protection risk signals to enforce MFA based on the calculated sign-in risk level (low, medium, high). When the risk is medium or high, the policy triggers MFA, meeting the requirement precisely. This is the only Microsoft Entra capability that directly uses risk-based conditional enforcement.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which controls resource access) with Conditional Access (which controls authentication and session conditions), leading them to pick a permission-based option instead of the risk-based policy engine.

How to eliminate wrong answers

Option A is wrong because Azure RBAC deny assignments control access to Azure resources via role-based permissions and cannot evaluate sign-in risk or enforce MFA. Option C is wrong because Access reviews are used for periodic attestation of group memberships or application access, not for real-time risk-based MFA enforcement. Option D is wrong because Administrative units are used to delegate administrative scope within a tenant, not to enforce authentication policies based on risk.

205
MCQhard

Your company is designing a data lake solution for IoT telemetry data. The data is ingested continuously and must be stored cost-effectively while allowing occasional interactive queries. The data has a lifespan of 90 days for hot access and 3 years for archived access. Which Azure storage tiering strategy minimizes costs?

A.Use Azure Blob Storage with only Hot tier for 90 days, then delete
B.Use Azure Blob Storage with lifecycle management: Hot for 90 days, then Cool, then Archive after 3 years
C.Use Azure Blob Storage with Cool tier for all data
D.Use Azure Files with lifecycle management to Archive after 90 days
AnswerB

This approach uses Azure Blob Storage lifecycle management policies to automatically transition blobs from Hot to Cool after 90 days of frequent access, then to Archive after 3 years, aligning with the retention period. The Archive tier offers the lowest storage cost for rarely accessed historical data while preserving it for future analytics, and the automated transitions reduce operational overhead and optimize cost without compromising data availability.

Why this answer

Azure Blob Storage lifecycle management can automatically transition data from Hot to Cool to Archive tiers based on age, minimizing costs for IoT telemetry that needs 90 days of hot access and 3 years of archival. The Hot tier provides low-latency access for interactive queries, Cool offers lower storage cost for infrequent access, and Archive provides the lowest cost for long-term retention. This tiering strategy aligns with the data's lifespan and access patterns, reducing overall storage expenses compared to keeping all data in a single tier.

Exam trap

The trap here is that candidates may assume Cool tier is sufficient for all data to save costs, but they overlook the need for hot access during the first 90 days and the even lower Archive tier for long-term retention, leading to higher overall costs.

How to eliminate wrong answers

Option A is wrong because deleting data after 90 days ignores the 3-year archival requirement, and storing all data in Hot tier for 90 days is more expensive than using Cool or Archive tiers for older data. Option C is wrong because using Cool tier for all data incurs higher costs for the first 90 days of hot access and does not provide the lowest-cost Archive tier for the 3-year retention period. Option D is wrong because Azure Files is not optimized for data lake scenarios with large-scale IoT telemetry ingestion; it uses SMB/NFS protocols and lacks the native tiering and lifecycle management capabilities of Blob Storage, plus archiving after 90 days does not meet the 3-year retention need.

206
MCQhard

Your Azure environment includes multiple subscriptions that are managed by different teams. You need to ensure that all resources are compliant with your company's security policies, and any non-compliant resources must be automatically remediated or reported. Which solution should you implement?

A.Azure Policy with remediation tasks
B.Azure Blueprints
C.Azure RBAC
D.Microsoft Defender for Cloud
AnswerA

Azure Policy with remediation tasks is correct because DeployIfNotExists and Modify effects can automatically correct non-compliant resources when the policy is assigned. A managed identity is assigned to the policy definition, and remediation tasks run on existing resources, while new resources are fixed during creation. This provides continuous, automated enforcement across your subscriptions, making it the only option that actively remediates configuration drift, not just reports it.

Why this answer

Azure Policy with remediation tasks is the correct solution because it allows you to define and enforce security policies across multiple subscriptions, and automatically remediate non-compliant resources using managed identities and DeployIfNotExists or Modify policy effects. This ensures continuous compliance without manual intervention, meeting the requirement for both automatic remediation and reporting.

Exam trap

The trap here is that candidates often confuse Azure Policy (for governance and remediation) with Azure Blueprints (for environment setup) or Microsoft Defender for Cloud (for security monitoring), but only Azure Policy with remediation tasks provides the automatic, continuous enforcement and remediation required for compliance.

How to eliminate wrong answers

Option B (Azure Blueprints) is wrong because it is primarily a packaging and orchestration tool for deploying consistent environments (including policies, RBAC, and resource groups), but it does not provide automatic remediation of non-compliant resources after deployment; it is a one-time or versioned deployment artifact, not a continuous compliance enforcement mechanism. Option C (Azure RBAC) is wrong because it controls who can access and manage resources (authorization), not what resources are compliant with security policies; it cannot detect or remediate non-compliant configurations. Option D (Microsoft Defender for Cloud) is wrong because it provides security posture management, threat detection, and recommendations, but it does not automatically remediate non-compliant resources by itself; it can integrate with Azure Policy for remediation, but the core enforcement and remediation engine is Azure Policy, not Defender for Cloud.

207
MCQeasy

A company wants to monitor sign-in failures for their Microsoft Entra ID-integrated applications. They need a dashboard in Azure Monitor showing sign-in failures by application and user location. Which data source should they stream to a Log Analytics workspace?

A.Microsoft Entra ID Audit logs
B.Microsoft Entra ID Sign-in logs
C.Microsoft Entra ID Provisioning logs
D.Office 365 Activity logs
AnswerB

Microsoft Entra ID Sign-in logs are the authoritative telemetry for authentication against the directory, containing both successful and failed sign-in attempts for interactive and non-interactive sessions. Each entry includes the user principal name, application, client IP, device, location, and a specific sign-in error code (e.g., 50126 for invalid password), along with conditional access and MFA status. Because they persist and expose the exact failure reason, they are the correct data source for monitoring sign-in failures across Entra ID-integrated applications.

Why this answer

Microsoft Entra ID Sign-in logs contain detailed information about every sign-in attempt, including success or failure status, application name, user location (IP address), and failure reasons. Streaming these logs to a Log Analytics workspace enables you to build custom dashboards in Azure Monitor that visualize sign-in failures by application and user location. Audit logs track configuration changes, not authentication events; Provisioning logs cover user/group synchronization; and Office 365 Activity logs focus on workload-specific actions, not general sign-in failures.

Exam trap

The trap here is that candidates often confuse Audit logs with Sign-in logs, assuming Audit logs capture all security events, but Audit logs specifically exclude authentication attempts and location data.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Audit logs record changes made to the directory (e.g., user creation, policy updates) and do not contain sign-in failure events or user location data. Option C is wrong because Microsoft Entra ID Provisioning logs track synchronization activities between Entra ID and third-party applications (e.g., ServiceNow, SAP) and do not capture sign-in failures. Option D is wrong because Office 365 Activity logs capture user actions within Exchange Online, SharePoint Online, and other Office 365 workloads, but they do not include sign-in failure details for all Entra ID-integrated applications or user location data.

208
Matchingmedium

Match each Azure governance tool to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Enforce rules and compliance for resources

Define repeatable set of Azure resources and policies

Hierarchical structure for managing access and policies

Query and explore Azure resources across subscriptions

Monitor, allocate, and optimize cloud costs

Why these pairings

Azure Policy enforces rules; Azure Blueprints provides repeatable templates; Management Groups organize subscriptions; RBAC controls access. Confusions often arise between policy enforcement and access control, or between blueprints and management groups.

209
Multi-Selectmedium

Your organization is planning to migrate a large number of on-premises file servers to Azure. The data includes millions of small files. You need to select a storage solution that supports SMB protocol and can handle high file counts. Which TWO Azure services meet these requirements?

Select 2 answers
A.Azure Stack Edge
B.Azure Blob Storage with NFS 3.0
C.Azure Files
D.Azure NetApp Files
E.Azure Disk Storage
AnswersC, D

Azure Files provides fully managed, cloud-native SMB (and NFS) file shares that are accessible over the internet or via private endpoints, with integration into Azure Active Directory for identity-based access control. It can scale to store millions of files across standard and premium tiers, making it a straightforward and cost-effective choice for migrating on-premises file servers without rearchitecting applications. Performance is suitable for most workloads, and the service handles patching, availability, and durability automatically, so it requires the least operational overhead among the options.

Why this answer

Azure Files provides fully managed SMB file shares in the cloud, supporting the SMB protocol natively and capable of handling high file counts (up to 100 million files per share with large shares enabled). This makes it a direct match for migrating on-premises file servers with millions of small files.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with NFS 3.0 as an SMB-compatible solution, but NFS and SMB are distinct protocols, and the question explicitly requires SMB support.

210
Multi-Selecthard

Which THREE of the following are best practices for securing an Azure Kubernetes Service (AKS) cluster? (Choose three.)

Select 3 answers
A.Enable Azure Policy for Kubernetes to enforce security policies.
B.Enable Azure AD integration for cluster authentication.
C.Use managed identities for pods to access Azure resources securely.
D.Allow all pod-to-pod communication within the cluster without network policies.
E.Disable Kubernetes RBAC and use only Azure RBAC for simplicity.
AnswersA, B, C

Azure Policy for Kubernetes extends Gatekeeper to audit and deny non-compliant workloads at admission time, enforcing pod security standards, resource limits and allowed registries directly inside the cluster. This satisfies the stem's requirement to secure AKS by preventing insecure configurations from being deployed, rather than merely detecting them afterwards.

Why this answer

Option A is correct because Azure Policy for Kubernetes (via the Azure Policy add-on) enforces governance and security controls at scale, such as restricting privileged containers, hostPath mounts, and allowed registries, and it reports compliance for AKS clusters. Option B is correct because integrating Azure AD (Microsoft Entra ID) with AKS enables centralized, identity-based authentication using Azure AD credentials and supports Kubernetes RBAC authorization, eliminating static local admin accounts. Option C is correct because managed identities (or workload identity) let pods obtain Azure AD tokens without storing credentials, enabling secure, secretless access to Azure resources like Key Vault and Storage.

Option D is not a best practice: allowing unrestricted pod-to-pod traffic removes segmentation and increases lateral movement risk; network policies (Calico or Azure NPM) should restrict traffic. Option E is incorrect because disabling Kubernetes RBAC removes fine-grained, namespace-scoped authorization; Azure RBAC alone does not replace Kubernetes RBAC for in-cluster permissions, and both should be used together.

211
MCQmedium

A media company is designing a storage solution for its large video files (average 50 GB each) that are edited by multiple users simultaneously. The solution must support SMB protocol for compatibility with existing editing software and provide low-latency access. The files must be stored in a highly available configuration across multiple availability zones in a single region. Which Azure storage solution should the company recommend?

A.Azure Files Premium tier with zone-redundant storage (ZRS)
B.Azure Blob Storage Premium tier with geo-redundant storage (GRS)
C.Azure Disk Storage with shared disks
D.Azure NetApp Files Premium tier with cross-zone replication
AnswerA

Azure Files Premium tier provides fully managed SMB and NFS file shares backed by SSD storage, delivering the low-latency I/O required for media workloads. Zone-redundant storage (ZRS) synchronously replicates data across three Azure availability zones within a region, ensuring high availability and resilience to zone failures without the cost of geo-replication. This combination offers native file sharing, strong performance, and simple integration, making it the most appropriate choice for a media company's scalable, low-latency storage.

Why this answer

Azure Files Premium tier supports SMB protocol natively, which is required for compatibility with existing editing software. Zone-redundant storage (ZRS) replicates data synchronously across three availability zones within a single region, providing high availability and low-latency access for simultaneous editing of large video files.

Exam trap

The trap here is that candidates may confuse Azure Blob Storage (which is object storage, not file storage) with Azure Files, or assume that geo-redundant storage (GRS) is required for high availability, when zone-redundant storage (ZRS) within a single region is sufficient and provides lower latency for real-time editing workloads.

How to eliminate wrong answers

Option B is wrong because Azure Blob Storage Premium tier does not support the SMB protocol; it uses REST APIs or NFS (preview), not SMB, and geo-redundant storage (GRS) adds asynchronous cross-region replication that increases latency and is unnecessary for single-region high availability. Option C is wrong because Azure Disk Storage with shared disks supports SMB but is designed for single-VM attached disks or shared block storage for clustered VMs, not for file-level sharing across multiple users; it lacks native SMB file-sharing semantics and is not optimized for concurrent user editing of large files. Option D is wrong because Azure NetApp Files Premium tier supports SMB and cross-zone replication, but cross-zone replication is asynchronous, which can introduce latency and potential data inconsistency for real-time editing; Azure NetApp Files is also more expensive and complex to manage compared to Azure Files for this use case.

212
Multi-Selectmedium

Which TWO data storage solutions in Azure provide built-in, automatic geo-redundancy for disaster recovery across paired regions?

Select 2 answers
A.Azure SQL Database (active geo-replication)
B.Azure Cosmos DB (default)
C.Azure Blob Storage (with GRS or RA-GRS)
D.Azure Data Lake Storage Gen2
E.Azure Files (standard tier)
AnswersA, C

Azure SQL Database active geo-replication is a built-in feature that continuously replicates committed transactions from a primary database to a readable secondary in a paired Azure region. This is a native capability of the platform, not an add-on or explicit custom configuration. It supports manual failover and provides a clear disaster recovery path with minimal administrative overhead, making it a correct answer.

Why this answer

Azure SQL Database's active geo-replication automatically creates a readable secondary database in a paired Azure region, enabling synchronous or asynchronous replication for disaster recovery. Azure Blob Storage with GRS or RA-GRS replicates data to a paired secondary region automatically, ensuring durability even during a regional outage. Both services provide built-in geo-redundancy without manual configuration beyond selecting the replication option.

Exam trap

The trap here is that candidates assume all Azure storage services have built-in geo-redundancy by default, but only specific services (like SQL Database with active geo-replication and Blob Storage with GRS/RA-GRS) offer it automatically without additional configuration.

213
MCQeasy

Your company plans to use Microsoft Sentinel as a SIEM solution. You need to ensure that security events from all Azure subscriptions are collected in a single workspace. What should you configure?

A.Create a Log Analytics workspace per subscription and use cross-workspace queries
B.Use Azure Policy to enforce Log Analytics workspace configuration across subscriptions
C.Deploy Microsoft Sentinel in each subscription and connect them via Azure Lighthouse
D.Enable Microsoft Sentinel on a single Log Analytics workspace and configure diagnostic settings for all subscriptions to send logs to that workspace
AnswerD

Enabling Microsoft Sentinel on a single Log Analytics workspace makes that workspace the system-of-record for security telemetry, and configuring Azure diagnostic settings on each subscription (and resource) to stream logs — including Activity Logs and resource-specific logs — into that same workspace ensures all data converges in one location. This provides a centralized SIEM with unified incident management, hunting, and correlation, which is the exact architecture Sentinel requires for a single-tenant security operations center.

Why this answer

Microsoft Sentinel requires a single Log Analytics workspace to act as the SIEM repository. By enabling Sentinel on that workspace and configuring diagnostic settings on all Azure subscriptions to stream their security logs (e.g., Activity logs, NSG flow logs, Windows Event logs) to that same workspace, you centralize all security events in one location. This ensures unified detection, investigation, and response across the entire enterprise without needing multiple Sentinel instances.

Exam trap

The trap here is that candidates often confuse Azure Policy's ability to enforce log collection with the need to also enable Sentinel on a single workspace, or they mistakenly think cross-workspace queries or multiple Sentinel instances can achieve the same centralized correlation, which violates Sentinel's architecture requirement for a single data repository.

How to eliminate wrong answers

Option A is wrong because creating a separate Log Analytics workspace per subscription and using cross-workspace queries does not consolidate events into a single workspace; it only allows querying across workspaces, which breaks Sentinel's single-pane-of-glass requirement for correlation and incident management. Option B is wrong because Azure Policy can enforce that resources send logs to a specific Log Analytics workspace, but it cannot enable Microsoft Sentinel itself or guarantee that all security events from all subscriptions are collected in one workspace without also configuring diagnostic settings. Option C is wrong because deploying Microsoft Sentinel in each subscription creates isolated SIEM instances that cannot share incidents, analytics rules, or workbooks; Azure Lighthouse provides cross-subscription management but does not merge data into a single Sentinel workspace.

214
MCQmedium

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. You need to ensure that all Azure subscriptions are covered by a single continuous export configuration that sends security alerts to a Log Analytics workspace. What should you do?

A.Use Azure Policy to deploy continuous export settings to all subscriptions.
B.Configure continuous export at the management group level.
C.Create an Azure Automation runbook to export settings to all subscriptions.
D.Configure continuous export in each subscription individually.
AnswerB

Configuring continuous export at the management group level is the correct single configuration point. In Microsoft Defender for Cloud, you can define the export settings (target Log Analytics workspace or Event Hub, and the data types such as alerts and recommendations) at a management group scope, and those settings are inherited by every subscription under that group. This ensures a consistent, centrally managed configuration without needing to touch individual subscriptions, and any new subscription added to the group automatically receives the same export settings.

Why this answer

Continuous export can be configured at the subscription level or management group scope. By configuring it at the management group level, all subscriptions under that management group inherit the export settings. This provides a single configuration point.

215
MCQmedium

Your organization is implementing a hybrid identity solution with Microsoft Entra ID. Users in an on-premises Active Directory domain need to access cloud applications. You need to ensure that password changes on-premises are synchronized to Entra ID within 30 seconds. Which configuration should you use?

A.Pass-through Authentication (PTA)
B.Federation with Active Directory Federation Services (AD FS)
C.Microsoft Entra Cloud Sync
D.Microsoft Entra Connect Sync with password hash synchronization
AnswerC

Microsoft Entra Cloud Sync uses a lightweight provisioning agent installed on-premises to connect directly to Entra ID, and its default delta synchronization cycle runs roughly every 30 seconds for user, group, and password hash changes. Because it supports password hash synchronization and synchronizes attributes in near-real time, it satisfies the requirement for changes to appear in the cloud quickly. Cloud Sync is therefore the correct choice when a 30-second sync window is required without running the full Microsoft Entra Connect sync engine.

Why this answer

Microsoft Entra Cloud Sync (Option C) is the correct choice because it is designed for near-real-time synchronization of identity changes, including password writes, with a target latency of under 30 seconds. It uses the lightweight Microsoft Entra Connect provisioning agent and the SCIM (System for Cross-domain Identity Management) protocol to sync changes from on-premises Active Directory to Entra ID, meeting the strict 30-second requirement for password change propagation.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect Sync (Option D) with Microsoft Entra Cloud Sync (Option C), assuming both offer the same synchronization speed, but Connect Sync uses a scheduled batch process (default 2-minute interval) that cannot meet the 30-second requirement, while Cloud Sync is designed for near-real-time sync.

How to eliminate wrong answers

Option A is wrong because Pass-Through Authentication (PTA) validates passwords directly against on-premises AD without synchronizing password hashes to Entra ID, so it does not propagate password changes to the cloud. Option B is wrong because Federation with AD FS relies on on-premises authentication and does not synchronize password changes to Entra ID; it only redirects authentication requests. Option D is wrong because Microsoft Entra Connect Sync with password hash synchronization typically runs on a schedule (default every 2 minutes) and cannot guarantee synchronization within 30 seconds; it is designed for batch sync, not near-real-time propagation.

216
MCQmedium

Your organization runs a critical application on Azure VMs that must be highly available within a region. The application is stateful and requires shared storage. You need to design a solution that can automatically recover from a VM failure with minimal downtime. What should you include in the design?

A.Deploy a single VM with premium storage and Azure Backup for recovery.
B.Deploy the VMs in different Availability Zones and use Azure NetApp Files for storage.
C.Use Azure Site Recovery to replicate the VM to a secondary region.
D.Deploy the VMs in an availability set and use Azure Shared Disks for the stateful data.
AnswerD

Availability set protects from rack-level failures, and shared disks enable automatic failover.

Why this answer

An availability set distributes VMs across fault domains and update domains within a datacenter, providing redundancy for VM failures. Azure Shared Disks enable multiple VMs to attach and access the same managed disk, fulfilling the shared storage requirement for stateful applications. Option A is incorrect because a single VM with Azure Backup does not provide automatic failover; backup is for data recovery, not high availability.

Option B is incorrect because Azure NetApp Files is a shared storage service, but deploying VMs in different Availability Zones introduces cross-zone latency and is not necessary for intra-region HA; an availability set is more suitable for stateful apps requiring shared disks. Option C is incorrect because Azure Site Recovery replicates to a secondary region for disaster recovery, not for automatic recovery within a region.

217
Multi-Selectmedium

Which TWO actions should you take to ensure business continuity for an Azure App Service web app that uses Azure SQL Database? (Choose two.)

Select 2 answers
A.Configure Azure SQL Database failover groups with automatic failover.
B.Enable auto-healing in the App Service and modify the application code to handle retries.
C.Deploy the App Service app in two regions using separate App Service plans and use Azure Traffic Manager for global traffic distribution.
D.Use Azure Front Door with a single App Service instance.
E.Configure Azure Backup for the App Service and enable geo-restore.
AnswersA, C

Failover groups with automatic failover replicate Azure SQL Database to a paired secondary region and provide a listener endpoint, so the database recovers without manual intervention. This addresses the data-tier continuity requirement of the business continuity scenario.

Why this answer

Option A is correct because Azure SQL Database failover groups provide automatic geo-failover of the database to a secondary region, ensuring the data tier remains available during a regional outage without manual intervention. Option C is correct because deploying the App Service app in two regions, each with its own App Service plan, and using Azure Traffic Manager for global traffic distribution provides a multi-region, highly available web tier that can route users to a healthy region if one fails. Option B is not correct because auto-healing and retry logic only address transient application-level faults, not regional or infrastructure-level failures required for business continuity.

Option D is not correct because Azure Front Door with a single App Service instance still leaves a single point of failure in one region. Option E is not correct because Azure Backup and geo-restore are for data recovery/restore scenarios, not continuous availability or automatic failover.

Exam trap

The trap is selecting options that provide high availability within a single region (like auto-healing) or backup/restore (geo-restore) instead of true cross-region redundancy with automatic failover, which is required for business continuity.

218
MCQhard

A company runs an SAP HANA database on Azure large instances (HLI) in the West US region. The database is critical for business operations. They need a disaster recovery solution with a recovery point objective (RPO) of near zero (seconds) and a recovery time objective (RTO) of less than 30 minutes in the event of a region-wide outage. The solution must automatically replicate data to a secondary region (East US) and support automated failover. Which design should they implement?

A.Configure HANA System Replication (async) between the primary and secondary site, and use a Pacemaker cluster with Azure Load Balancer to enable automated failover
B.Use Azure Site Recovery to replicate the HANA large instance VMs with a replication frequency of 30 seconds and enable auto-failover
C.Schedule HANA database backups every 5 minutes to Azure Blob Storage with geo-redundant storage (GRS), and restore in the secondary region on demand
D.Set up HANA System Replication with synchronous mode to the secondary region
AnswerA

HANA System Replication with asynchronous mode provides near-zero RPO. Combined with Pacemaker and Azure Load Balancer, you can achieve automatic failover within the required RTO. This is the recommended approach for SAP HANA DR on Azure.

Why this answer

HANA System Replication (async) provides near-zero RPO by continuously replicating log changes to the secondary region, while a Pacemaker cluster with Azure Load Balancer enables automated failover within the required 30-minute RTO. This combination meets the strict RPO/RTO requirements for SAP HANA on Azure Large Instances, as Azure Site Recovery does not support HLI and synchronous replication would introduce unacceptable latency over the West US to East US distance.

Exam trap

The trap here is that candidates confuse Azure Site Recovery as a viable option for HLI, not realizing it only supports standard Azure VMs, or they assume synchronous replication is always better without considering the latency penalty over inter-region distances.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery does not support Azure Large Instances (HLI) — it only works with standard Azure VMs, and its 30-second replication frequency cannot achieve near-zero RPO (seconds). Option C is wrong because scheduling backups every 5 minutes cannot achieve near-zero RPO (seconds), and manual restore in the secondary region would far exceed the 30-minute RTO. Option D is wrong because synchronous HANA System Replication over the long distance between West US and East US would introduce high network latency, causing unacceptable performance impact on the primary database and potentially violating the RTO due to transaction stalls.

219
MCQmedium

A company runs SQL Server on an Azure virtual machine. They need to ensure high availability within a single Azure region. The solution must provide automatic failover with zero data loss (synchronous replication) and support read-only routing for reporting workloads. Which solution should they implement?

A.SQL Server Always On Availability Group
B.SQL Server Failover Cluster Instance (FCI)
C.Azure Site Recovery
D.Azure Backup
AnswerA

SQL Server Always On Availability Group provides database-level high availability and disaster recovery by maintaining synchronous-commit replicas. With synchronous mode, transaction commits are acknowledged only after being hardened on both primary and secondary, so automatic failover results in zero data loss. Additionally, configuring read-only routing on the secondary replica lets reporting workloads connect to a readable secondary, offloading read traffic without compromising the primary.

Why this answer

SQL Server Always On Availability Groups (AG) provide high availability and disaster recovery at the database level. They support synchronous replication with automatic failover, ensuring zero data loss (RPO=0) within a single Azure region. Additionally, AGs allow secondary replicas to be configured as readable, enabling read-only routing for reporting workloads, which directly meets all stated requirements.

Exam trap

The trap here is confusing Failover Cluster Instances (FCI) with Availability Groups; FCI provides instance-level HA with shared storage but cannot serve read-only workloads from secondary nodes, while AGs offer database-level HA with readable secondaries and synchronous replication.

How to eliminate wrong answers

Option B (SQL Server Failover Cluster Instance) is wrong because it operates at the instance level using shared storage (e.g., Azure shared disks or Storage Spaces Direct), which does not support read-only routing for reporting workloads; secondary nodes are passive and cannot serve read traffic. Option C (Azure Site Recovery) is wrong because it provides disaster recovery replication at the VM level, not database-level synchronous replication, and does not guarantee zero data loss or support read-only routing for SQL Server reporting. Option D (Azure Backup) is wrong because it is a backup and restore solution, not a high availability or automatic failover mechanism; it cannot provide synchronous replication, zero data loss failover, or read-only routing.

220
MCQeasy

Your company has an Azure subscription with multiple virtual networks (VNets) in different regions. You need to ensure that resources in all VNets can communicate with each other privately over the Microsoft backbone network. Which Azure solution should you implement?

A.VNet peering
B.Azure ExpressRoute
C.Azure DNS
D.Azure VPN Gateway
AnswerA

VNet peering establishes one-to-one connectivity between two Azure virtual networks over Microsoft's private backbone, allowing resources in separate VNets to communicate using private IP addresses without any public internet traversal, gateways, or extra cost per flow. This is the native Azure solution for inter-VNet connectivity because it is direct, unilateral, and supports both regional and global peering, making it the correct choice for joining spoke VNets to a hub or linking peered environments.

Why this answer

VNet peering connects Azure virtual networks privately over the Microsoft backbone network, enabling resources in different VNets (including those in different regions) to communicate directly without traversing the public internet. It uses the Azure infrastructure to route traffic between peered VNets with low latency and high bandwidth, meeting the requirement for private inter-VNet communication.

Exam trap

The trap here is that candidates often confuse VNet peering with VPN Gateway, assuming a VPN is required for private connectivity, but VNet peering provides direct private connectivity over the Microsoft backbone without any public internet exposure or gateway overhead.

How to eliminate wrong answers

Option B is wrong because Azure ExpressRoute extends on-premises networks into Azure over a private connection, not for connecting multiple Azure VNets to each other. Option C is wrong because Azure DNS provides domain name resolution services, not network connectivity between VNets. Option D is wrong because Azure VPN Gateway creates encrypted tunnels over the public internet or ExpressRoute, but it is typically used for site-to-site or point-to-site connectivity, not for direct private VNet-to-VNet communication across regions without additional configuration and public internet exposure.

221
MCQmedium

A company runs a custom analytics application that reads data using the NFS 3.0 protocol. The data consists of large files organized in a directory structure. The application also requires POSIX-like access control lists (ACLs) for fine-grained permissions. The solution must be fully managed and support high throughput for parallel reads. Which Azure data service should they use?

A.Azure Blob Storage
B.Azure Files
C.Azure NetApp Files
D.Azure Data Lake Storage Gen2
AnswerD

Azure Data Lake Storage Gen2 is the correct answer because it combines the massive scalability of Azure Blob Storage with a hierarchical namespace, enabling true directory structures and atomic, directory-level rename/delete operations that analytics applications require. It exposes POSIX-compliant access control lists (ACLs) and supports NFS 3.0 endpoints, so an NFS 3.0-based custom application can connect directly while also benefiting from the ABFS driver for Spark, Hadoop, and other analytic frameworks. This unique fusion of hierarchical namespace, POSIX ACLs, NFS 3.0 interoperability, and blob-storage economics makes ADLS Gen2 the only option that fully satisfies all the stated requirements for a cloud-scale analytics data lake.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with POSIX-like ACLs and supports the NFS 3.0 protocol for high-throughput parallel reads. It is fully managed and designed for big data analytics workloads that require fine-grained permissions and directory structure management.

Exam trap

The trap here is that candidates often confuse Azure Files (which supports NFS but only version 4.1) with the NFS 3.0 requirement, or they overlook that Azure NetApp Files, while technically capable, is not the fully managed, high-throughput parallel read solution optimized for analytics that ADLS Gen2 provides.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage does not natively support NFS 3.0 (it requires a preview feature or workaround) and lacks a true hierarchical namespace and POSIX ACLs, relying instead on flat storage and Azure RBAC. Option B is wrong because Azure Files supports SMB and NFS 4.1, not NFS 3.0, and its ACLs are based on Windows NTFS permissions, not POSIX-like ACLs. Option C is wrong because Azure NetApp Files is a fully managed file share service that supports NFS 3.0 and POSIX ACLs, but it is not the best fit for high-throughput parallel reads in a custom analytics application; it is more suited for enterprise workloads requiring low-latency access and is not as optimized for big data analytics as ADLS Gen2.

222
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to automatically detect sign-in risks such as sign-ins from unfamiliar locations, anonymous IP addresses, or leaked credentials. Based on the risk level, they want to apply different controls: for low-risk sign-ins, show a message but allow access; for medium-risk sign-ins, require multi-factor authentication (MFA); for high-risk sign-ins, block the sign-in. They also need to receive a weekly summary report of risk events. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Identity Protection policies
B.Microsoft Entra ID Conditional Access policies with sign-in risk conditions
C.Microsoft Entra ID Access Reviews
D.Microsoft Entra ID Privileged Identity Management (PIM)
AnswerB

Conditional Access policies can evaluate sign-in risk levels (low, medium, high) from Identity Protection and apply granular controls such as block, require MFA, or session controls. Combined with Identity Protection reports, you get the weekly summary.

Why this answer

Microsoft Entra ID Conditional Access policies can integrate sign-in risk conditions from Identity Protection to enforce granular controls based on risk levels. This allows you to configure actions such as showing a message for low risk, requiring MFA for medium risk, and blocking access for high risk, while Identity Protection provides the weekly summary report of risk events.

Exam trap

The trap here is that candidates often confuse Identity Protection (the detection engine) with Conditional Access (the enforcement engine), assuming Identity Protection alone can apply the per-risk-level controls, when in reality Conditional Access policies are required to map risk levels to specific actions like MFA or block.

How to eliminate wrong answers

Option A is wrong because Identity Protection policies alone detect risks and can trigger automated responses, but they do not natively support the granular per-risk-level controls (e.g., show message for low, MFA for medium, block for high) that Conditional Access policies provide; Conditional Access is the enforcement layer. Option C is wrong because Access Reviews are used for periodic attestation of group memberships or application access, not for real-time risk-based sign-in controls or risk event reporting. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not sign-in risk detection or conditional access based on risk levels.

223
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They have a SaaS application that supports SCIM (System for Cross-domain Identity Management). The company wants to automatically create, update, and deactivate user accounts in the SaaS application whenever changes occur in Microsoft Entra ID. They do not want to use custom scripts. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Application Proxy
B.Microsoft Entra ID Provisioning (Automatic User Provisioning)
C.Microsoft Entra ID Connect
D.Microsoft Entra ID B2B Collaboration
AnswerB

Microsoft Entra ID Provisioning (Automatic User Provisioning) is the correct answer because it enables the Entra ID provisioning service to automatically create, update, and deactivate user accounts in any SaaS application that implements a System for Cross-domain Identity Management (SCIM) 2.0 endpoint, based on user and group assignments in Entra ID. This service continuously remediates identity matches against the tenant directory, ensuring that attribute changes and role changes are propagated and that accounts are disabled when a user loses access. It is exactly the mechanism that automates identity lifecycle in SaaS apps, often replacing manual CSV-based administration.

Why this answer

Microsoft Entra ID Provisioning (Automatic User Provisioning) is the correct feature because it natively supports the SCIM (System for Cross-domain Identity Management) protocol to automate the creation, update, and deactivation of user accounts in SaaS applications. This eliminates the need for custom scripts by synchronizing identity changes from Microsoft Entra ID to the target application in near real-time.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Connect (which syncs from on-premises AD) with cloud-to-SaaS provisioning, but the question explicitly targets a cloud-only SaaS application with no on-premises dependency.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Application Proxy provides secure remote access to on-premises web applications, not user provisioning to SaaS apps. Option C is wrong because Microsoft Entra ID Connect is used for hybrid identity synchronization between on-premises Active Directory and Microsoft Entra ID, not for provisioning users to third-party SaaS applications. Option D is wrong because Microsoft Entra ID B2B Collaboration enables external user access to your organization's resources, not automated user lifecycle management in a SaaS application.

224
MCQhard

Your company, Fabrikam Inc., operates a global Software-as-a-Service (SaaS) application that provides real-time analytics. The application runs on Azure Kubernetes Service (AKS) with a microservices architecture. The data tier uses Azure Cosmos DB (Core SQL API) with multi-region writes. The application also uses Azure Event Hubs for event ingestion. The business requires a Recovery Time Objective (RTO) of 10 seconds and a Recovery Point Objective (RPO) of 0 for the entire platform. The solution must support active-active configuration across multiple Azure regions. You have been asked to recommend the disaster recovery design. Which option should you recommend?

A.Deploy AKS in three regions with Azure Traffic Manager. Use Azure Cosmos DB with multi-region writes. Use Azure Event Hubs with geo-disaster recovery. Use Azure Cache for Redis Enterprise with active geo-replication.
B.Deploy AKS in two regions with Azure Front Door. Use Azure Cosmos DB with single write region and auto-failover. Use Azure Service Bus with geo-disaster recovery. Use Azure Cache for Redis Enterprise with active geo-replication.
C.Deploy AKS in three regions with Azure Front Door. Use Azure Cosmos DB with multi-region writes. Use Azure Event Hubs with geo-disaster recovery and active-active pattern. Use Azure Cache for Redis Enterprise with active geo-replication.
D.Deploy AKS in two regions with Azure Front Door. Use Azure SQL Database with auto-failover groups. Use Azure Event Hubs with geo-disaster recovery. Use Azure Cache for Redis Enterprise with active geo-replication.
AnswerC

This solution meets all stated requirements through active-active replication at every layer. Azure Front Door uses anycast-based global load balancing and continuous health probes, enabling failover in less than the 10-second RTO. Azure Cosmos DB with multi-region writes accepts writes in any region, providing RPO=0 and continuous availability. Azure Event Hubs with geo-disaster recovery and an active-active pattern uses paired namespaces with client-side failover/producer logic to keep event flow uninterrupted. Azure Cache for Redis Enterprise with active geo-replication lets all regions read and write the same cache data with automatic conflict resolution, completing the zero-downtime architecture.

Why this answer

It meets the strict RTO of 10 seconds and RPO of 0 by using Azure Front Door for global load balancing with health probes, Azure Cosmos DB multi-region writes for zero data loss, Azure Event Hubs with geo-disaster recovery and active-active pattern for continuous event ingestion, and Azure Cache for Redis Enterprise with active geo-replication for synchronized caching across regions. This combination ensures that all components support active-active configuration and can fail over instantly without data loss.

Exam trap

The trap here is that candidates often assume Azure Traffic Manager or Azure SQL Database can meet sub-10-second RTO and zero RPO, but they overlook the DNS propagation delays in Traffic Manager and the inherent replication lag in SQL Database auto-failover groups.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager does not support active-active configuration with sub-10-second failover; it relies on DNS-based routing with TTL delays, making it unsuitable for the required RTO. Option B is wrong because Azure Cosmos DB with single write region and auto-failover has a non-zero RPO (typically up to 5 seconds) and does not support active-active writes, violating the RPO of 0 requirement. Option D is wrong because Azure SQL Database with auto-failover groups has a typical RTO of 30-60 seconds and RPO of up to 5 seconds, failing both the RTO of 10 seconds and RPO of 0; additionally, it does not support active-active writes across regions.

225
MCQeasy

You need to provide temporary shared access to a specific blob in Azure Storage for a contractor. The access must expire after 24 hours. Which feature should you use?

A.Managed identity
B.Azure role-based access control (RBAC)
C.Storage account access key
D.Shared access signature (SAS)
AnswerD

A shared access signature (SAS) is a signed URI that contains query parameters (e.g., 'sp' for permissions, 'se' for expiry, 'sr' for resource type) and can be scoped precisely to a single blob while the signature is validated by Azure Storage. You can specify read permissions and a short expiration window, and optionally use a user delegation SAS signed with Azure AD credentials to avoid using an account key. This is the standard Azure mechanism for granting temporary, delegated access to a specific blob without exposing the account key or requiring a persistent role assignment.

Why this answer

A shared access signature (SAS) provides delegated, time-limited access to a specific Azure Storage resource, such as a blob, without exposing the storage account key. By configuring the SAS with an expiration time of 24 hours, you grant the contractor temporary access that automatically revokes after that period, meeting the requirement precisely.

Exam trap

The trap here is that candidates often confuse managed identities or RBAC as suitable for temporary access, but neither provides time-bound, scoped delegation to a single blob without persistent permissions or full account access.

How to eliminate wrong answers

Option A is wrong because a managed identity is used for authenticating Azure resources (e.g., VMs, App Services) to Azure services without storing credentials, not for granting temporary external user access to a specific blob. Option B is wrong because Azure RBAC provides persistent, role-based access to storage account resources at the container or account level, not time-bound access to a single blob, and it cannot enforce a 24-hour expiration. Option C is wrong because the storage account access key grants full administrative access to the entire storage account, which violates the principle of least privilege and cannot be scoped to a single blob or set to expire automatically.

Page 2

Page 3 of 11

Page 4

All pages