Courseiva

Microsoft Azure Solutions Architect Expert AZ-305 (AZ-305) — Questions 226–300

795 questions total · 11pages · All types, answers revealed

Page 3

Page 4 of 11

Page 5
226
MCQmedium

A company uses Azure Policy to enforce tagging on resources. The security team reports that some resources are missing the required 'CostCenter' tag. You need to ensure that any resource created without the required tag is automatically remediated by adding the tag with a default value. What should you configure in Azure Policy?

A.DeployIfNotExists effect
B.AuditIfNotExists effect
C.Append effect
D.Deny effect
AnswerA

DeployIfNotExists effect evaluates resources after they are created and, if they are missing the required tag, triggers a remediation task through Azure Policy. This remediation task uses a managed identity to run a nested deployment that adds the missing tag, effectively modifying the existing resource. It is the only effect among the options that both identifies and automatically fixes non-compliant existing resources, making it the correct choice for enforcing tags across the entire environment.

Why this answer

The DeployIfNotExists effect is correct because it automatically remediates non-compliant resources by deploying a tag with a default value when the required 'CostCenter' tag is missing. This effect triggers a deployment task that adds the tag, ensuring continuous compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse Append (which only works during creation/update) with DeployIfNotExists (which can remediate existing resources), leading them to choose Append for automatic remediation of all resources.

How to eliminate wrong answers

Option B (AuditIfNotExists) is wrong because it only audits and reports non-compliance without performing any automatic remediation. Option C (Append) is wrong because it adds the tag during resource creation or update but does not remediate existing resources that are already missing the tag. Option D (Deny) is wrong because it blocks resource creation if the tag is missing, but the requirement is to automatically add the tag with a default value, not to deny creation.

227
MCQmedium

A company runs a critical application on Azure Virtual Machines in the North Europe region. The application uses a SQL Server database on a VM. The company wants to implement a backup solution that provides point-in-time restore for the database to any point within the last 35 days. The solution must minimize administrative effort and cost. What should you recommend?

A.Create a scheduled script that copies the database backup files to Azure Blob Storage.
B.Configure SQL Server transaction log shipping to a secondary VM.
C.Use Azure Backup to back up the SQL Server database.
D.Use Azure Site Recovery to replicate the SQL Server VM to another region.
AnswerC

Azure Backup for SQL Server on Azure VMs provides application-consistent backups and supports point-in-time restore up to 35 days. It is a fully managed solution that minimizes administrative effort and integrates with the Azure portal. It also offers long-term retention options if needed, and the cost is based on the protected instance and storage consumed.

Why this answer

Azure Backup for SQL Server on Azure VMs is a managed solution that provides application-consistent backups and supports point-in-time restore for up to 35 days. It minimizes administrative effort and cost because it is fully integrated with Azure and requires no additional infrastructure.

Exam trap

The trap here is assuming that Azure Site Recovery can provide database-level point-in-time restore.

228
MCQmedium

A company needs a data storage solution for a global application that frequently accesses recent data and less frequently older data. Data is unstructured blobs. They want to automatically move blobs to cool storage after 30 days and to archive storage after 90 days. Additionally, blobs must be retained for 7 years and cannot be deleted or modified during that period. Which Azure Blob Storage features should they combine?

A.Use blob lifecycle management policies and legal hold (immutable blobs).
B.Use blob lifecycle management policies and time-based retention policies.
C.Use Azure Storage Analytics and immutability policies.
D.Use Azure File Sync and lifecycle management.
AnswerB

Blob lifecycle management policies automate cost-efficient data tiering, moving blobs from hot to cool to archive tiers based on age or last modification, thereby reducing storage costs as data ages. Time-based retention policies, a form of immutable blob storage with a fixed retention interval, prevent blobs from being modified or deleted for a specified period—here, 7 years—which satisfies regulatory compliance. Together they meet the global application's need for both automated tiering and fixed-duration write-once-read-many (WORM) protection, whereas a legal hold would leave retention indefinite and untethered to a specific deadline.

Why this answer

Blob lifecycle management policies automatically transition blobs from hot to cool after 30 days and to archive after 90 days, while time-based retention policies enforce immutability for a fixed period (7 years), preventing deletion or modification. This combination meets both the tiering and retention requirements without manual intervention.

Exam trap

The trap here is confusing legal hold (which is indefinite and manually managed) with time-based retention (which has a fixed expiry), leading candidates to choose Option A when they need a defined retention period.

How to eliminate wrong answers

Option A is wrong because legal hold (immutable blobs) has no expiration date and must be manually cleared, making it unsuitable for a fixed 7-year retention period; it also does not support automatic tiering. Option C is wrong because Azure Storage Analytics provides metrics and logging, not lifecycle management or immutability policies. Option D is wrong because Azure File Sync is for syncing on-premises file shares with Azure Files, not for managing blob tiering or retention.

229
MCQhard

You are designing a solution for a critical application that requires low latency between multiple Azure regions. The application must handle failover automatically if a region becomes unavailable. You need to distribute traffic across regions and ensure that users are directed to the closest healthy endpoint. What should you implement?

A.Azure Standard Load Balancer with cross-region load balancing
B.Azure Front Door with priority routing
C.Azure Traffic Manager with geographic routing and endpoint monitoring
D.Azure Application Gateway with autoscaling
AnswerC

Azure Traffic Manager is a DNS-based global traffic manager that resolves user queries to the most appropriate endpoint based on routing methods like geographic, priority, weighted, or performance; when combined with geographic routing and endpoint monitoring, it can direct users from specific geographies to their closest configured regional endpoint and automatically fail over if health checks fail. Because it operates at the DNS layer rather than the anycast or network layer, it provides a clean, global routing mechanism that matches the requirement for critical application availability.

Why this answer

Azure Traffic Manager with geographic routing and endpoint monitoring is the correct choice because it operates at the DNS level, directing users to the closest healthy endpoint based on geographic location. This ensures low latency by routing traffic to the nearest region and provides automatic failover by continuously monitoring endpoint health and rerouting traffic if a region becomes unavailable.

Exam trap

The trap here is that candidates often confuse Azure Front Door's priority routing with geographic routing, but priority routing does not direct users to the closest endpoint—it only provides a static failover order, whereas Traffic Manager's geographic routing dynamically selects the nearest healthy region.

How to eliminate wrong answers

Option A is wrong because Azure Standard Load Balancer with cross-region load balancing operates at Layer 4 and distributes traffic across regional backends, but it does not provide geographic proximity-based routing to direct users to the closest endpoint; it uses a hash-based distribution. Option B is wrong because Azure Front Door with priority routing is designed for global HTTP/S traffic with advanced features like SSL termination and WAF, but priority routing sends all traffic to a primary region and only fails over to a secondary region, not to the closest healthy endpoint based on user location. Option D is wrong because Azure Application Gateway with autoscaling is a regional Layer 7 load balancer that operates within a single Azure region and cannot distribute traffic across multiple regions or provide geographic proximity routing.

230
MCQeasy

You are designing a disaster recovery plan for a web application hosted on Azure App Service. The application uses Azure SQL Database. The company wants to minimize downtime during a regional outage. Which approach should you recommend?

A.Deploy App Service in a single region with Azure Backup for the app and database.
B.Deploy App Service in two regions with Azure Front Door for global load balancing and Azure SQL Database active geo-replication.
C.Deploy App Service across availability zones in one region and use Azure SQL Database zone-redundant configuration.
D.Deploy App Service in two regions with Azure Traffic Manager and use manual database restore.
AnswerB

Deploying App Service in two regions behind Azure Front Door gives you global, anycast-based load balancing with health probes that automatically steer traffic away from a failed region. Meanwhile, Azure SQL Database active geo-replication maintains a continuously copied readable secondary in the paired or selected secondary region, and using a failover group enables automatic, application-transparent failover with a short RTO and low RPO. This combination delivers genuine cross-region disaster recovery: both the compute and data tiers have automated failover paths.

Why this answer

It combines multi-region App Service deployment with Azure Front Door for global load balancing and Azure SQL Database active geo-replication. This ensures that during a regional outage, traffic is automatically routed to the healthy secondary region, and the database is continuously replicated with a readable secondary, enabling near-zero RPO and minimal RTO without manual intervention.

Exam trap

The trap here is that candidates often confuse availability zones (which protect against datacenter failures within a region) with multi-region disaster recovery, leading them to choose Option C, which does not address a full regional outage.

How to eliminate wrong answers

Option A is wrong because deploying in a single region with Azure Backup does not provide automatic failover or load balancing; recovery requires manual restore and DNS changes, leading to significant downtime during a regional outage. Option C is wrong because availability zones protect only against zonal failures within a single region, not a full regional outage, and zone-redundant SQL Database does not provide cross-region failover. Option D is wrong because Azure Traffic Manager can route traffic but lacks health-based routing and SSL offload capabilities of Front Door, and manual database restore from backups results in high RTO and potential data loss, failing to minimize downtime.

231
Multi-Selecthard

Which THREE should you consider when designing a monitoring solution for a critical application that requires high availability and low latency? (Choose three.)

Select 3 answers
A.Dashboard visual appeal and color scheme
B.Data volume and associated costs
C.Log retention period and archival strategy
D.Alerting latency and frequency
E.Custom metric creation for all application counters
AnswersB, C, D

Data volume and associated costs are a primary design consideration because Azure Monitor and Log Analytics charge based on data ingestion, storage, and archival. High metric and log volumes directly increase monthly spend and can degrade query performance if the workspace becomes cluttered, so you must plan for sampling, aggregation, and filtering of telemetry. For example, Application Insights supports sampling to reduce data transfer, and you can set daily caps in Log Analytics to avoid unexpected bills. Estimating the volume generated per resource, and selecting the right pricing tier, ensures the monitoring solution remains sustainable and economical.

Why this answer

Monitoring data volume directly impacts cost, especially in Azure Monitor where data ingestion and retention are billed per GB. For a critical application with high availability and low latency, you must balance the granularity of monitoring data against budget constraints to avoid unexpected costs that could compromise operational sustainability.

Exam trap

The trap here is that candidates confuse 'monitoring solution design' with 'dashboard aesthetics' or assume more metrics always improve observability, ignoring the cost and latency trade-offs inherent in Azure Monitor's pay-per-GB model.

232
MCQeasy

You need to provide a team of developers with access to create and manage Azure resources in a specific resource group. The developers should not be able to modify access policies for other users. Which built-in role should you assign?

A.Contributor
B.Owner
C.Reader
D.User Access Administrator
AnswerA

Contributor is the correct choice because it grants full management rights over all resource types within the assigned scope, allowing developers to create, modify, and delete resources as needed. However, it explicitly excludes the ability to assign roles or manage access, which is not required for the team's task. By using Contributor, you adhere to the principle of least privilege, giving developers the capabilities they need without exposing access-control functions.

Why this answer

The Contributor role allows full management of resources but cannot manage access (role assignments). Owner can manage access. Reader is read-only.

User Access Administrator only manages access, not resources.

233
Multi-Selectmedium

Which TWO of the following are benefits of using Azure Files shares for lift-and-shift migrations of on-premises file servers?

Select 2 answers
A.Integration with Azure File Sync for hybrid scenarios
B.Block-level deduplication
C.Support for iSCSI protocol
D.Automatic tiering of data to archive storage
E.Support for SMB protocol
AnswersA, E

Azure File Sync is a native Azure service that replicates an Azure file share to on-premises Windows Servers, creating a multi-site distributed cache. This integration enables hybrid scenarios where branch offices and local users can access a local server cache with low latency while still benefiting from centralized management, backup, and disaster recovery in Azure. It is a core benefit of Azure Files because it directly extends your cloud file share to existing on-premises infrastructure.

Why this answer

Azure Files shares provide fully managed SMB file shares in the cloud, which are directly compatible with on-premises file servers that use the SMB protocol. This makes them ideal for lift-and-shift migrations because applications can continue accessing files over SMB without code changes. Azure File Sync further extends this by enabling hybrid scenarios where on-premises servers can cache frequently accessed files while tiering to the cloud, simplifying the migration process.

Exam trap

The trap here is that candidates may confuse Azure Files with Azure NetApp Files or on-premises file server features, assuming block-level deduplication or iSCSI support are available, when in fact Azure Files is a managed SMB/NFS service without those capabilities.

234
MCQhard

A globally distributed application requires multi-region writes to a NoSQL database and must tolerate regional write outages. Which Azure service capability should be selected?

A.Azure Table Storage RA-GRS
B.Azure SQL Database serverless only
C.Azure Cosmos DB multi-region writes
D.Azure Files geo-redundant storage
AnswerC

Azure Cosmos DB with multi-region writes enables active-active replication where every region assigned to the account is writable, allowing any region to accept write requests with configurable conflict resolution (e.g., Last-Writer-Wins or custom). Each write is replicated to all other regions asynchronously while the chosen consistency level (such as bounded staleness or eventual) is honored at the client. This architecture provides high write availability, low latency for globally distributed applications, and is the only listed option that natively supports multi-region writes.

Why this answer

Azure Cosmos DB multi-region writes is the correct choice because it provides active-active replication across multiple Azure regions, enabling writes to be accepted in any configured region and automatically replicated. This design ensures that if one region experiences a write outage, the application can continue writing to other regions without interruption, meeting the requirement for multi-region writes and regional write outage tolerance.

Exam trap

The trap here is that candidates often confuse geo-redundant storage options (like RA-GRS or GRS) with active-active multi-region write capabilities, not realizing that most Azure storage services (including Table Storage and Files) only support writes to a single primary region, whereas Cosmos DB is the only service that natively supports multi-region writes.

How to eliminate wrong answers

Option A is wrong because Azure Table Storage RA-GRS (Read-Access Geo-Redundant Storage) supports read access from a secondary region but only allows writes to the primary region, failing the multi-region write requirement. Option B is wrong because Azure SQL Database serverless is a compute tier for a single-region database; it does not support multi-region writes and cannot tolerate regional write outages. Option D is wrong because Azure Files geo-redundant storage replicates data to a secondary region for durability but only supports writes to the primary region, not multi-region writes.

235
MCQhard

A company is designing a solution for a data analytics workload. The company receives streaming data from multiple sources, including IoT devices and social media feeds. The data must be ingested, processed in real-time, and stored for historical analysis. The company also wants to use Power BI to create real-time dashboards from the streaming data. You need to recommend a data pipeline architecture. What should you include?

A.Use Azure IoT Hub for ingestion, Azure Stream Analytics for processing, and Power BI for dashboards.
B.Use Azure Event Hubs for ingestion, Azure Data Lake Analytics for processing, and Power BI for dashboards.
C.Use Azure Event Hubs for ingestion, Azure Stream Analytics for real-time processing, and Power BI for dashboards.
D.Use Azure Event Hubs for ingestion, Azure Synapse Analytics for processing, and Power BI for dashboards.
AnswerC

This option is the only one that correctly assembles a real-time analytics pipeline: Azure Event Hubs ingests high-throughput, time-ordered event streams (such as social media posts) with low latency and native support for multiple independent consumers; Azure Stream Analytics then queries that stream in-memory using SQL-like temporal windows (e.g., tumbling, hopping, sliding) to aggregate and detect patterns as events arrive; Power BI consumes the Stream Analytics output via its streaming API or pre-aggregated datasets to render live dashboards. Together these three services provide the necessary ingestion speed, continuous processing, and real-time visualization, with no batch layer in the critical path.

Why this answer

Azure Event Hubs is designed for high-throughput ingestion of streaming data from multiple sources, including IoT devices and social media feeds. Azure Stream Analytics provides real-time processing with low latency, and it can output directly to Power BI for live dashboards, meeting all requirements for ingestion, real-time processing, and visualization.

Exam trap

The trap here is confusing Azure IoT Hub (device management and bi-directional communication) with Azure Event Hubs (general-purpose event ingestion), and assuming that batch processing services like Azure Data Lake Analytics or Azure Synapse Analytics can handle real-time streaming requirements.

How to eliminate wrong answers

Option A is wrong because Azure IoT Hub is optimized for bi-directional communication with IoT devices and is not the best choice for ingesting social media feeds or general streaming data; it also lacks the native integration with Power BI for real-time dashboards that Event Hubs provides. Option B is wrong because Azure Data Lake Analytics is a batch processing service (U-SQL) and does not support real-time stream processing required for live dashboards. Option D is wrong because Azure Synapse Analytics is primarily a data warehouse for analytics on stored data, not a real-time stream processing engine; it would introduce unnecessary latency for live dashboards.

236
Multi-Selecthard

A company runs a critical application on Azure VMs. They need a backup strategy that meets the following requirements: - Daily backups retained for 35 days - Weekly backups retained for 12 weeks - Monthly backups retained for 36 months - Yearly backups retained for 10 years - Backups must be stored in a geo-redundant storage account Which THREE items must be configured? (Choose three.)

Select 3 answers
A.A simple daily backup policy
B.A backup policy with GFS retention
C.Geo-redundant storage (GRS) for the vault
D.A Recovery Services vault in the paired region
E.A Recovery Services vault in the same region as the VMs
AnswersB, C, E

A backup policy with GFS (grandfather-father-son) retention directly satisfies the staggered schedule: daily, weekly, monthly and yearly tiers with independent retention durations. Recovery Services vault policies natively support these four backup frequencies, so configuring GFS retention fulfils the 35-day, 12-week, 36-month and 10-year requirements in one policy.

Why this answer

Option B is correct because the required retention scheme (daily 35 days, weekly 12 weeks, monthly 36 months, yearly 10 years) is exactly the Grandfather-Father-Son (GFS) retention pattern, which Azure Backup implements through a backup policy configured with daily, weekly, monthly, and yearly retention rules. Option C is correct because the requirement to store backups in geo-redundant storage is satisfied by setting the Recovery Services vault's storage replication type to Geo-Redundant Storage (GRS), which replicates backup data to the Azure paired region. Option E is correct because a Recovery Services vault must be created in the same region as the VMs it protects; the vault is a regional resource and cannot directly back up VMs located in a different region.

Option A is incorrect because a simple daily backup policy only provides daily retention and cannot express weekly, monthly, and yearly GFS retention tiers. Option D is incorrect because the vault itself is created in the VMs' region, not the paired region; geo-redundancy is achieved via the GRS storage setting, which asynchronously replicates data to the paired region.

Exam trap

The trap here is that candidates often confuse the need for a Recovery Services vault in the paired region (Option D) with geo-redundant storage, but Azure Backup achieves geo-redundancy by configuring GRS on the vault's storage, not by deploying a second vault.

237
Multi-Selectmedium

Your company is designing a hybrid identity solution that will allow users to authenticate to Azure resources using their on-premises Active Directory credentials. The solution must support multi-factor authentication (MFA) and conditional access policies. Which TWO components should you include?

Select 2 answers
A.Microsoft Entra Connect
B.Active Directory Federation Services (AD FS)
C.Microsoft Entra ID
D.Azure AD Application Proxy
E.Microsoft Intune
AnswersA, C

Microsoft Entra Connect is the synchronization engine that replicates on-premises Active Directory Domain Services (AD DS) objects and hashed password or pass-through authentication information to Microsoft Entra ID. It enables users to sign in to Azure resources with their corporate AD credentials without needing a separate cloud account, and supports Password Hash Synchronization (PHS), Pass-through Authentication (PTA), and Seamless SSO as managed authentication options. This makes it the correct component because it establishes the identity bridge between the on-premises directory and Entra ID, which is the tenant that authenticates Azure resource access.

Why this answer

Microsoft Entra Connect synchronizes on-premises Active Directory identities to Microsoft Entra ID, enabling users to authenticate with their corporate credentials. Microsoft Entra ID is the cloud-based identity and access management service that processes authentication requests, enforces multi-factor authentication (MFA), and evaluates conditional access policies. Together, they form the core of a hybrid identity solution that supports MFA and conditional access.

Exam trap

The trap here is that candidates often assume AD FS is mandatory for hybrid identity with MFA and conditional access, but Microsoft Entra Connect combined with Microsoft Entra ID natively supports these features without federation.

238
MCQhard

A company needs to store large amounts of unstructured data (log files) for analytics. The data is accessed frequently for the first 30 days, then occasionally for the next 90 days, and rarely after that but must be retained for 7 years for compliance. The data must not be modified or deleted during the retention period, and administrative access must not be able to bypass this restriction. They want to minimize storage costs. Which combination of Azure Blob Storage features should they configure?

A.Configure a lifecycle management policy to move blobs to Cool tier after 30 days and to Archive tier after 120 days. Apply a time-based retention policy with a retention period of 2,555 days and lock it.
B.Enable soft delete and versioning on the storage account, and use a custom script to delete blobs after 7 years. Manually move blobs to Cool and Archive tiers using Azure PowerShell.
C.Set each blob's access tier to Cool on upload, then manually change to Archive after 30 days. Enable Azure Backup on the storage account for retention.
D.Apply a legal hold on the container to prevent deletion, and configure a lifecycle policy to move blobs to Archive after 30 days.
AnswerA

A locked time-based retention policy on the container ensures that blobs cannot be deleted or overwritten for the specified duration (7 years = 2555 days). Lifecycle management moves blobs to cost-efficient tiers. Locking prevents bypass.

Why this answer

It combines a lifecycle management policy to automatically transition blobs from Hot to Cool after 30 days and to Archive after 120 days, minimizing storage costs. The time-based retention policy with a locked retention period of 2,555 days (7 years) ensures that blobs cannot be modified or deleted during the retention period, and locking the policy prevents administrative bypass, meeting the compliance requirement.

Exam trap

The trap here is that candidates often confuse soft delete or legal hold with immutable retention policies, not realizing that only a locked time-based retention policy provides true WORM protection that cannot be bypassed by administrators.

How to eliminate wrong answers

Option B is wrong because soft delete and versioning allow data recovery but do not prevent deletion or modification during the retention period; a custom script to delete blobs after 7 years violates the requirement that data must not be deleted during retention, and manual tier changes are not automated or cost-efficient. Option C is wrong because manually setting access tiers and using Azure Backup does not enforce a write-once-read-many (WORM) policy; Azure Backup retains backups but does not prevent modification or deletion of the original blobs, and manual operations are error-prone and do not meet the compliance requirement for immutability. Option D is wrong because a legal hold prevents deletion but does not prevent modification of blobs, and moving blobs to Archive after 30 days ignores the occasional access requirement for the next 90 days, leading to higher retrieval costs and potential access delays.

239
MCQmedium

A company wants to monitor sign-in activity for their Microsoft Entra ID-integrated applications. They need to detect risky sign-ins, such as sign-ins from anonymous IP addresses or unfamiliar locations, and automatically block or require multi-factor authentication. They also need a dashboard showing risk events and the ability to investigate and remediate. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Access Reviews
D.Microsoft Entra ID Self-Service Password Reset (SSPR)
AnswerA

Identity Protection detects risky sign-ins using Microsoft's threat intelligence, including anonymous IP and unfamiliar location signals, then applies risk-based Conditional Access to block or require MFA. Its dashboard and investigation tooling satisfy the monitoring and remediation requirements.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it specifically detects and responds to risky sign-ins, such as those from anonymous IP addresses or unfamiliar locations, by automatically blocking access or requiring multi-factor authentication. It provides a dashboard of risk events (e.g., leaked credentials, impossible travel) and supports investigation and remediation workflows, directly matching the requirements for monitoring sign-in activity and enforcing conditional access policies.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Identity Protection because both involve 'risk' and 'security,' but PIM is solely for privileged role governance, not for detecting risky sign-ins from anonymous IPs or unfamiliar locations.

How to eliminate wrong answers

Option B (Privileged Identity Management) is wrong because it focuses on managing, controlling, and monitoring access to privileged roles (e.g., global administrator) through just-in-time activation and approval workflows, not on detecting risky sign-ins or enforcing MFA for general users. Option C (Access Reviews) is wrong because it automates periodic attestation of group memberships or application access to ensure only the right users have access, but it does not detect or respond to risky sign-in events in real time. Option D (Self-Service Password Reset) is wrong because it allows users to reset their own passwords without help desk intervention, addressing password management, not risk-based sign-in detection or conditional access enforcement.

240
MCQmedium

A company runs SQL Server on an Azure virtual machine. They need to automate database backups with application-consistency and retain backups for 10 years to meet compliance. They also want to restore to any point in time within the last 35 days. Which Azure Backup solution should they use?

A.Azure Backup for SQL Server in Azure VM
B.Azure Backup for Azure VM
C.Azure Site Recovery
D.SQL Server Always On Availability Groups
AnswerA

Azure Backup for SQL Server in Azure VM is the correct choice because it natively integrates with SQL Server's I/O and VSS to produce application-consistent backups that preserve transactional integrity. It supports full, differential, and transaction-log backups, enabling point-in-time database restoration, and offers centralized policy management with configurable long-term retention (up to 10 years) and geo-redundant storage options.

Why this answer

Azure Backup for SQL Server in Azure VM (Option A) is correct because it provides native application-consistent backups for SQL Server databases running on Azure VMs, supports long-term retention (LTR) up to 10 years using the backup vault's retention rules, and enables point-in-time restore (PITR) for the last 35 days by leveraging SQL Server transaction log backups. This solution is specifically designed for SQL Server workloads and meets both compliance and recovery requirements without additional infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Backup for Azure VM (which provides crash-consistent backups) with Azure Backup for SQL Server in Azure VM (which provides application-consistent backups with PITR), leading them to choose Option B for simplicity, but only Option A meets the specific SQL Server backup and compliance requirements.

How to eliminate wrong answers

Option B is wrong because Azure Backup for Azure VM captures only VM-level snapshots (crash-consistent or file-system-consistent), not application-consistent SQL Server backups, and cannot perform SQL-specific point-in-time restores or retain transaction logs for PITR within 35 days. Option C is wrong because Azure Site Recovery is a disaster recovery (DR) solution focused on replication and failover for business continuity, not a backup service; it does not support long-term retention for 10 years or granular point-in-time restore for SQL databases. Option D is wrong because SQL Server Always On Availability Groups is a high-availability and disaster recovery feature that provides synchronous or asynchronous replication, not a backup solution; it does not automate backups, retain backups for 10 years, or offer point-in-time restore capabilities.

241
MCQmedium

A company runs a critical application on Azure VMs in a single region. They need to ensure the application can failover to another region with minimal data loss and a recovery time objective (RTO) of 1 hour. The application uses managed disks and SQL Server Always On availability groups. What is the MOST cost-effective solution that meets the requirements?

A.Use Azure geo-redundant storage (GRS) for the managed disks and restore the VMs in the secondary region
B.Use Azure Site Recovery to replicate VMs to a secondary region with a recovery plan
C.Use Azure availability zones to protect against regional failures
D.Deploy SQL Server Always On availability groups across two regions
AnswerB

Azure Site Recovery (ASR) provides continuous replication of Azure VMs to a secondary region with a defined recovery point objective (RPO) of seconds and a recovery time objective (RTO) of minutes, well within the 1-hour requirement. By creating a recovery plan, you can orchestrate the failover sequence, including start order, scripted actions, and manual actions, ensuring consistent and predictable recovery. ASR is a cost-effective managed service that does not require additional SQL Server licenses or compute resources beyond the replicated disk storage and the replication appliance (which can be scaled or shared). This makes it the recommended solution for meeting the stated RTO and RPO for critical VMs without over-engineering the architecture.

Why this answer

Azure Site Recovery (ASR) provides orchestrated replication and failover for Azure VMs, supporting both managed disks and SQL Server Always On availability groups. It meets the RTO of 1 hour by enabling a recovery plan that automates the failover sequence, and it minimizes data loss through continuous replication with a Recovery Point Objective (RPO) as low as 30 seconds. This is the most cost-effective solution because ASR replicates only changed blocks and does not require a continuously running secondary VM, unlike a full geo-redundant storage or cross-region Always On deployment.

Exam trap

The trap here is that candidates often confuse geo-redundant storage (GRS) with VM-level disaster recovery, assuming storage replication alone is sufficient for application failover, but GRS does not handle VM state, network configuration, or orchestrated recovery, making it unsuitable for meeting RTO and RPO requirements.

How to eliminate wrong answers

Option A is wrong because Azure geo-redundant storage (GRS) replicates the underlying storage asynchronously, but it does not provide VM-level replication or orchestrated failover; restoring VMs from GRS snapshots would likely exceed the 1-hour RTO and could result in significant data loss due to the asynchronous replication lag. Option C is wrong because availability zones protect only within a single region and cannot provide failover to a secondary region, which is explicitly required. Option D is wrong because deploying SQL Server Always On availability groups across two regions requires a secondary replica in the other region, which incurs ongoing compute and storage costs for the standby VM, making it less cost-effective than ASR, which only spins up resources during failover.

242
MCQeasy

A global e-commerce company needs a database solution that can handle high-velocity writes from user transactions across multiple regions. They require multi-region writes with automatic conflict resolution and single-digit millisecond latency for reads and writes. Which Azure data store should they use?

A.Azure Cosmos DB
B.Azure Table Storage
C.Azure SQL Database
D.Azure Redis Cache
AnswerA

Correct. Azure Cosmos DB is a globally distributed, multi-model database service that natively supports multi-region writes (multi-master) with automatic conflict resolution via last-writer-wins or custom conflict resolution policies, ensuring active-active failover across regions. Its turnkey global distribution replicates data to any number of Azure regions, providing single-digit millisecond read and write latency at the 99th percentile, and it exposes multiple consistency models (strong, bounded staleness, session, consistent prefix, eventual) to balance consistency and performance. This makes it the only listed option that directly satisfies the requirement for a database that can handle global writes with automatic conflict resolution.

Why this answer

Azure Cosmos DB is the correct choice because it offers multi-region writes with automatic conflict resolution using last-writer-wins (LWW) or custom conflict resolution policies, and it guarantees single-digit millisecond latency for both reads and writes at the 99th percentile. Its globally distributed, multi-model design is purpose-built for high-velocity transactional workloads that require active-active replication across regions.

Exam trap

The trap here is that candidates often confuse Azure SQL Database's active geo-replication (which supports only read-scale secondaries) with true multi-region writes, or they assume Azure Table Storage's global replication is equivalent to Cosmos DB's active-active capability.

How to eliminate wrong answers

Option B (Azure Table Storage) is wrong because it does not support multi-region writes or automatic conflict resolution; it is a NoSQL key-value store designed for structured, non-relational data with eventual consistency only. Option C (Azure SQL Database) is wrong because it does not natively support multi-region writes; it uses active geo-replication for read-only secondaries and requires manual failover, not active-active writes. Option D (Azure Redis Cache) is wrong because it is an in-memory cache, not a durable database; it does not provide automatic conflict resolution for writes and is not designed for persistent, multi-region transactional storage.

243
MCQeasy

A company uses Azure Cosmos DB for a globally distributed e-commerce application. They need to ensure that write operations in one region are immediately visible in all other regions. Which consistency level should they choose?

A.Session
B.Eventual
C.Strong
D.Bounded staleness
AnswerC

Strong consistency in Cosmos DB ensures that every read returns the most recently committed write, regardless of which region the read is served from. This is achieved by synchronously replicating each write to all regions before acknowledging the transaction, providing linearizable consistency. It is the only level that meets the stated requirement of immediate global visibility of the latest write, though it comes with higher write latency and requires single-region write configuration.

Why this answer

Strong consistency ensures that write operations are synchronously replicated across all regions before acknowledging the write. This guarantees that any read operation in any region returns the most recent write, providing linearizability. For a globally distributed e-commerce application requiring immediate visibility of writes, Strong consistency is the correct choice.

Exam trap

The trap here is that candidates often confuse 'immediate visibility' with 'Session' consistency, assuming that a single session's writes are enough, but the requirement is for all regions and all clients to see the write immediately, which only Strong consistency guarantees.

How to eliminate wrong answers

Option A is wrong because Session consistency guarantees monotonic reads and writes within a single client session but does not provide immediate cross-region visibility for all clients. Option B is wrong because Eventual consistency allows replicas to converge over time without any guarantee of immediate visibility, leading to stale reads. Option D is wrong because Bounded staleness allows reads to lag behind writes by a configurable time interval (e.g., 5 seconds) or number of versions, which does not meet the requirement for immediate visibility.

244
MCQmedium

A company runs a critical line-of-business application on 10 Azure VMs. They need a disaster recovery solution that replicates the VMs to a secondary region with a recovery point objective (RPO) of 30 minutes and a recovery time objective (RTO) of 1 hour. The solution must support non-disruptive testing of failover for quarterly compliance drills. Which Azure service should they use?

A.Azure Backup
B.Azure Site Recovery
C.Azure Migrate
D.Manual VM replication to secondary region
AnswerB

Azure Site Recovery provides continuous asynchronous replication of Azure VMs to a secondary region, meeting the 30-minute RPO, and supports test failover into an isolated network for non-disruptive quarterly drills while delivering the 1-hour RTO.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs to a secondary region, meeting the RPO of 30 minutes (continuous replication with 30-second RPO) and RTO of 1 hour (orchestrated recovery). It supports non-disruptive test failovers via isolated networks, which is essential for quarterly compliance drills without impacting production.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for backup/restore with longer RPO) with Azure Site Recovery (which is for replication and orchestrated failover), overlooking that the question explicitly requires non-disruptive test failovers and strict RPO/RTO, which only ASR can provide.

How to eliminate wrong answers

Option A is wrong because Azure Backup provides crash-consistent or application-consistent snapshots with a minimum RPO of 1 hour (via backup policy) and does not support orchestrated failover or non-disruptive test failovers; it is designed for long-term retention and restore, not disaster recovery with strict RTO/RPO. Option C is wrong because Azure Migrate is a tool for discovery, assessment, and migration of workloads to Azure, not for ongoing replication or disaster recovery; it lacks the continuous replication and failover orchestration required. Option D is wrong because manual VM replication to a secondary region (e.g., copying VHDs or using custom scripts) cannot guarantee a 30-minute RPO or 1-hour RTO due to manual intervention, lacks automated orchestration, and does not support non-disruptive test failovers without complex custom networking.

245
MCQmedium

You are designing an identity solution for a large enterprise that uses Microsoft Entra ID. The company has a partner organization that needs access to a specific application. The partner uses their own identity provider (IdP). You need to enable seamless access without duplicating user accounts. What should you configure?

A.Federation with the partner's IdP
B.Microsoft Entra External ID
C.Passwordless authentication
D.Identity synchronization
AnswerB

Microsoft Entra External ID is the correct approach because it includes B2B collaboration, which allows external users to sign in using their own identities—whether that be a Microsoft account, a Google account, a Facebook account, or any SAML/WS-Fed identity provider—without creating a separate local account in your tenant. It provides self-service sign-up, conditional access policies, and lifecycle management such as just-in-time access and access reviews, making it ideal for large enterprises that need to collaborate with a broad range of external partners, vendors, and customers. External ID also supports cross-tenant access settings for trusted MFA and device compliance from partner tenants, so the user's own identity provider is the authority for authentication while your tenant controls access policies. This is the only option that directly enables external users to bring their own identities without requiring federation prior to the invitation.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2B) is the correct solution because it allows the partner organization to access the specific application using their own identity provider (IdP) without requiring duplicate user accounts in your tenant. It leverages federation trust, enabling seamless single sign-on (SSO) by authenticating users against their home IdP and issuing a token for your application. This aligns with the requirement for a zero-trust, external identity scenario where user lifecycle is managed externally.

Exam trap

The trap here is that candidates often confuse federation (Option A) with External ID, not realizing that federation is a broader concept that can be implemented via External ID for external users, while the exam expects you to recognize that External ID is the specific service designed for this partner access scenario without account duplication.

How to eliminate wrong answers

Option A is wrong because federation with the partner's IdP typically implies a direct trust relationship between your Entra ID and the partner's IdP for all users, which is more complex and often used for hybrid identity scenarios, not for granting granular application access to external users without account duplication. Option C is wrong because passwordless authentication (e.g., FIDO2, Windows Hello) is an internal authentication method that does not solve the problem of allowing external users from a different IdP to access your application; it focuses on eliminating passwords for your own users. Option D is wrong because identity synchronization (e.g., using Azure AD Connect) would require creating and syncing user objects from the partner's directory into your tenant, which duplicates accounts and violates the requirement to avoid duplication.

246
MCQmedium

A company has deployed several Azure VMs that do not have public IP addresses. Administrators need to securely connect to these VMs using RDP and SSH from the internet over a browser without deploying a jump box or managing VPN connections. The solution must use Microsoft Entra ID authentication for single sign-on. Which Azure service should they use?

A.Azure Jump Box VM
B.Azure Bastion
C.Azure VPN Gateway
D.Azure ExpressRoute
AnswerB

Azure Bastion is a fully managed, PaaS-based RDP/SSH proxy deployed directly into a dedicated subnet within your virtual network, allowing browser-based or native client connections to VMs that have no public IP addresses. It natively integrates with Microsoft Entra ID for user authentication, enabling single sign-on, passwordless sign-in, and Conditional Access enforcement, and it also supports Azure RBAC to control which users can reach which VMs. Because it is a hardened, managed service, it eliminates the need to maintain jump box VMs or public endpoints, and it can enforce session revocation and time-based access policies for enhanced security.

Why this answer

Azure Bastion provides secure, seamless RDP and SSH connectivity to Azure VMs directly from the Azure portal over TLS, without requiring public IP addresses, jump boxes, or VPN connections. It supports Microsoft Entra ID authentication for single sign-on, meeting the requirement for browser-based access with no additional management overhead.

Exam trap

The trap here is that candidates often confuse Azure Bastion with a jump box VM or assume VPN Gateway is required for secure remote access, overlooking that Bastion provides browser-based RDP/SSH without any public IP or VPN infrastructure.

How to eliminate wrong answers

Option A is wrong because a jump box VM would itself require a public IP address or VPN connectivity, and would need to be managed and patched, violating the 'without deploying a jump box' requirement. Option C is wrong because Azure VPN Gateway establishes site-to-site or point-to-site VPN tunnels, requiring client software and VPN configuration, not browser-based access, and does not inherently support Microsoft Entra ID authentication for RDP/SSH sessions. Option D is wrong because Azure ExpressRoute provides a dedicated private network connection from on-premises to Azure, not internet-based browser access, and does not offer RDP/SSH connectivity over a browser.

247
Multi-Selectmedium

Which TWO Microsoft Entra ID features should you use to protect against credential attacks?

Select 2 answers
A.Password Protection
B.Identity Protection
C.Group-based licensing
D.Self-Service Password Reset (SSPR)
E.Application Proxy
AnswersA, B

Password Protection actively blocks users from selecting common, easily guessable passwords by enforcing both Microsoft's global banned password list and a custom banned list you define. It also performs fuzzy matching to catch variations like common letter substitutions, thereby directly reducing the likelihood of successful password spray or brute-force attacks against your tenant.

Why this answer

Password Protection is correct because it specifically targets credential attacks by blocking weak passwords and common variations (e.g., 'Password123!') using a global banned password list and the option to add custom terms. Identity Protection is correct because it uses real-time risk detection (e.g., leaked credentials, anonymous IP addresses) to automatically block or require MFA for suspicious sign-ins, directly mitigating credential-based attacks like password spray or brute force.

Exam trap

The trap here is that candidates often confuse SSPR (a self-service recovery tool) with a proactive attack prevention feature, but SSPR does not block credential attacks—it only helps users after they are locked out or have forgotten their password.

248
MCQmedium

Your organization has a critical application deployed on Azure VMs in the West US region. The application uses a Standard_D8s_v3 VM with two data disks (512 GB each) and a separate log disk (256 GB). The application writes data continuously to the data disks and logs. The business continuity requirements are: RPO of 15 minutes, RTO of 2 hours, and the ability to recover to a specific point in time within the last 7 days. You need to design a disaster recovery solution that replicates the VMs and disks to the East US region. The solution must also support failback to West US after a disaster. What should you do?

A.Use Azure Site Recovery to replicate the VMs to East US with a recovery plan that includes the VM and disks, and configure failback using reprotection
B.Use Azure Migrate to migrate the VMs to East US and then set up replication back to West US
C.Configure Azure Backup for the VMs with a backup policy that has a 15-minute frequency and replicate backups to the East US region using geo-redundant storage
D.Use Azure Storage geo-redundant storage (GRS) for the managed disks and manually attach the disks to a new VM in East US during a disaster
AnswerA

Azure Site Recovery (ASR) is the correct choice because it provides continuous, application-consistent replication of Azure VMs to a secondary region (East US) with a recovery point objective (RPO) as low as a few seconds and a recovery time objective (RTO) that can be met via orchestrated recovery plans. Including the VM and disks in a recovery plan ensures that all dependent resources fail over in the correct order, and reprotection enables automated failback to the primary region after the disaster is resolved, fulfilling the stated DR requirement.

Why this answer

Azure Site Recovery (ASR) is the correct service for orchestrating replication, failover, and failback of Azure VMs between regions. It supports the required RPO of 15 minutes (using near-synchronous replication with change tracking) and RTO of 2 hours, and allows point-in-time recovery via recovery points. The reprotection and failback workflow enables you to replicate back to West US after a disaster, meeting the full business continuity requirements.

Exam trap

The trap here is confusing Azure Backup (which is for backup and long-term retention) with Azure Site Recovery (which is for replication and DR), leading candidates to choose a backup-based solution that cannot meet the required RPO or support failback.

How to eliminate wrong answers

Option B is wrong because Azure Migrate is designed for one-time migration, not ongoing replication with failback; it does not provide the continuous replication or orchestrated failback needed for DR. Option C is wrong because Azure Backup with a 15-minute frequency cannot achieve an RPO of 15 minutes (minimum backup frequency is 4 hours for Azure VM backup), and geo-redundant storage does not provide point-in-time recovery or automated failover orchestration. Option D is wrong because Azure Storage GRS for managed disks does not replicate disk state changes continuously or support point-in-time recovery; manually attaching disks in another region cannot meet the RTO of 2 hours and lacks orchestrated failback.

249
Multi-Selectmedium

Your company is designing a hybrid network architecture that connects multiple on-premises sites to Azure. You need to ensure high availability and redundancy for the connection. Which TWO solutions should you recommend? (Choose two.)

Select 2 answers
A.Deploy two ExpressRoute circuits in active-passive mode
B.Implement Azure DNS Private Resolver for resolution
C.Use Azure VPN Gateway in active-active mode
D.Use a single VPN gateway with active-standby mode
E.Use a single ExpressRoute circuit with a VPN gateway as failover
AnswersA, C

Deploying two ExpressRoute circuits in active-passive mode is correct because each circuit represents a physically distinct path, ideally from different providers and peering locations, to Microsoft's edge, eliminating a single point of failure in the private network. BGP determines the primary path through route preference mechanisms such as local preference or AS path prepend, and on failure the secondary circuit automatically takes over without any configuration change. This architecture satisfies a high-availability hybrid networking requirement and enables the ExpressRoute service-level agreement.

Why this answer

Deploying two ExpressRoute circuits in active-passive mode provides redundancy for the on-premises-to-Azure connection. If the primary circuit fails, traffic automatically fails over to the passive circuit, ensuring high availability. Option C is correct because an Azure VPN Gateway in active-active mode uses two active tunnels to provide redundancy and load balancing, which is essential for a highly available hybrid network.

Exam trap

The trap here is that candidates often confuse redundancy at the gateway level (active-active vs. active-standby) with redundancy at the circuit level, and may incorrectly select a single ExpressRoute circuit with a VPN failover, which still has a single point of failure for the circuit itself.

250
Multi-Selecthard

Which THREE Azure services or features should you use to design a comprehensive monitoring solution for a hybrid infrastructure spanning on-premises and Azure?

Select 3 answers
A.Azure Monitor
B.Network Watcher
C.Log Analytics agent (or Azure Monitor Agent)
D.Azure Arc-enabled servers
E.Azure Traffic Manager
AnswersA, C, D

Azure Monitor is the correct choice because it is the central platform for telemetry collection, analysis, and alerting across Azure and on-premises workloads. It ingests metrics and logs into a unified data plane, supports log queries with KQL, and provides dashboards, alerts, and integration with Log Analytics workspaces and Application Insights. This makes it the foundational service for any hybrid monitoring architecture.

Why this answer

Azure Monitor is the central platform for collecting, analyzing, and acting on telemetry from both Azure and on-premises resources. It provides a unified monitoring experience by aggregating metrics and logs, enabling alerting, dashboards, and integration with other services like Log Analytics. For a hybrid infrastructure, Azure Monitor serves as the core data ingestion and analysis hub, making it essential for a comprehensive monitoring solution.

Exam trap

The trap here is that candidates often confuse Network Watcher (a network diagnostics tool) with a general monitoring solution, or they overlook Azure Arc-enabled servers as a prerequisite for managing and monitoring on-premises machines with Azure Monitor.

251
MCQeasy

A company wants to automatically tier data between hot, cool, and archive access tiers based on last access time to optimize costs. Which Azure feature should they implement?

A.Azure Blob Storage lifecycle management
B.Azure Data Box
C.Azure Backup
D.Azure File Sync
AnswerA

Azure Blob Storage lifecycle management is the correct service because it natively applies predefined rules to automatically move blobs between the hot, cool, and archive access tiers based on conditions such as age or last modified time. These lifecycle policies are evaluated daily and can also delete blobs, ensuring storage costs stay optimized without manual intervention. The rules operate at the storage account or container level, giving granular control over both current tier placement and future transitions.

Why this answer

Azure Blob Storage lifecycle management allows you to define policies that automatically move blobs between hot, cool, and archive access tiers based on conditions such as last access time or age. This directly addresses the requirement to optimize costs by tiering data according to access patterns without manual intervention.

Exam trap

The trap here is that candidates may confuse Azure File Sync's 'cloud tiering' feature with blob lifecycle management, but File Sync only tiers between local server and Azure Files (not between hot/cool/archive tiers) and does not use last access time for tiering decisions.

How to eliminate wrong answers

Option B (Azure Data Box) is wrong because it is a physical data transfer service for offline migration of large datasets, not a tool for automated tiering based on access time. Option C (Azure Backup) is wrong because it provides backup and restore capabilities for Azure resources, not data lifecycle management between access tiers. Option D (Azure File Sync) is wrong because it synchronizes on-premises file servers with Azure file shares and can enable cloud tiering, but it does not support moving data between hot, cool, and archive tiers based on last access time; its tiering is limited to local vs. cloud caching.

252
MCQmedium

A healthcare company is designing a data storage solution for its electronic health records (EHR) system. The system must store patient data in Azure SQL Database with high availability. The solution must meet the following requirements: - Data must be stored in the East US region with automatic failover to a secondary region in West US in case of a regional outage. - The Recovery Point Objective (RPO) must be less than 5 seconds. - The Recovery Time Objective (RTO) must be less than 1 hour. - The solution must minimize costs while meeting the RPO and RTO. Which Azure SQL Database configuration should the company recommend?

A.Deploy Azure SQL Database Managed Instance with failover group to a secondary instance in West US.
B.Deploy Azure SQL Database with active geo-replication to a secondary server in West US. Configure automatic failover using a failover group.
C.Deploy Azure SQL Database Business Critical tier with auto-failover group and a secondary replica in a different availability zone within East US.
D.Deploy Azure SQL Database General Purpose tier with zone-redundant configuration.
AnswerB

Active geo-replication asynchronously replicates changes to a secondary server in West US with a 5-second RPO, and when paired with a failover group, failover is automatic—typically completing in less than an hour—so the workload stays available during a regional outage. This is the standard cross-region DR pattern for Azure SQL Database because it supports readable secondaries and allows the RPO/RTO targets to match the strict uptime and data durability requirements common in healthcare.

Why this answer

Active geo-replication with a failover group provides automatic, asynchronous replication to a secondary region (West US) with an RPO of less than 5 seconds and an RTO of less than 1 hour. This configuration meets the high-availability and disaster recovery requirements while minimizing costs compared to higher-tier options.

Exam trap

The trap here is that candidates may choose the Business Critical tier (Option C) thinking it provides the best availability, but it only offers intra-region zone redundancy, not cross-region disaster recovery, which is required for a regional outage.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database Managed Instance does not support active geo-replication or failover groups with an RPO under 5 seconds; its built-in auto-failover groups have a higher RPO and RTO, and it is more expensive than the required solution. Option C is wrong because the Business Critical tier with a secondary replica in a different availability zone within East US does not provide failover to a secondary region (West US), failing the cross-region disaster recovery requirement. Option D is wrong because the General Purpose tier with zone-redundant configuration only protects against zonal failures within a single region, not a regional outage, and its RPO and RTO do not meet the sub-5-second RPO and sub-1-hour RTO requirements.

253
MCQmedium

A company ingests IoT sensor data into Azure Blob Storage. Data is written frequently and is accessed rarely after the first 24 hours. The company must retain the data for exactly 90 days for compliance. They want to minimize storage costs by automatically moving data to the cheapest possible storage tier as soon as possible. Which Azure Blob Storage lifecycle management policy should they implement?

A.Move to Cool tier after 1 day, delete after 90 days
B.Move to Archive tier after 1 day, delete after 90 days
C.Move to Cool tier after 30 days, delete after 90 days
D.Move to Archive tier after 30 days, delete after 90 days
AnswerA

Moving the sensor data to the Cool tier after just one day aligns lifecycle costs with actual access patterns, since IoT telemetry is typically queried only briefly after ingestion. Cool tier provides significantly lower per-GB storage costs than Hot, and because the retention period of 90 days exceeds Cool's 30-day minimum commitment, no early deletion penalty is incurred. This policy satisfies the compliance requirement to delete after 90 days while minimizing the cost of storing data that is rarely read after the first 24 hours.

Why this answer

The data is rarely accessed after 24 hours, so moving it to Cool tier after 1 day minimizes cost while still allowing low-latency access. The 90-day deletion aligns with the compliance retention requirement. Cool tier is the cheapest online tier, and moving data there as soon as possible (after 1 day) reduces costs without incurring the early deletion penalty or retrieval latency of Archive tier.

Exam trap

The trap here is that candidates often choose Archive tier thinking it is the cheapest, but they overlook the 180-day early deletion penalty and the fact that Cool tier is sufficient for 90-day retention with no penalty, making it the true cheapest option for this exact retention window.

How to eliminate wrong answers

Option B is wrong because moving data to Archive tier after 1 day would make it inaccessible for immediate use (Archive has a retrieval latency of up to 15 hours) and incurs a higher cost for early deletion if deleted before 180 days. Option C is wrong because waiting 30 days to move to Cool tier leaves data in the Hot tier for 29 extra days, incurring unnecessary storage costs when it could have been moved after 1 day. Option D is wrong because moving to Archive tier after 30 days still incurs the early deletion penalty (Archive requires a minimum 180-day retention) and the data is rarely accessed, but Cool tier after 1 day is cheaper and more appropriate.

254
MCQeasy

A startup is building a web application that will be used by a small number of users initially but is expected to grow rapidly. The application runs on Linux and uses a PostgreSQL database. The company wants to minimize operational overhead and costs during the early stages. You need to recommend a platform as a service (PaaS) solution for both the application and the database. What should you recommend?

A.Deploy the application on Azure App Service for Linux and use Azure Database for PostgreSQL.
B.Deploy the application on Azure Kubernetes Service (AKS) and use Azure Database for PostgreSQL.
C.Deploy the application as Azure Functions and use Azure Cosmos DB for storage.
D.Deploy the application on Azure Virtual Machines and use PostgreSQL on the same VM.
AnswerA

Azure App Service for Linux is an enterprise-grade PaaS that fully manages the application runtime and operating system patching, with built-in load balancing, TLS termination, and autoscaling. Pairing it with Azure Database for PostgreSQL yields a fully managed relational database with automated backups, high availability, and predictable scaling, eliminating both application- and data-tier administrative chores. This combination keeps the startup focused only on business logic and precisely satisfies the requirement to minimize operational overhead.

Why this answer

Azure App Service for Linux provides a fully managed PaaS environment for hosting web applications, handling scaling, patching, and load balancing with minimal operational overhead. Azure Database for PostgreSQL is a managed PaaS database service that offers built-in high availability, automated backups, and scaling, which aligns with the startup's need to minimize costs and operational complexity during rapid growth.

Exam trap

The trap here is that candidates may over-engineer the solution by choosing AKS (Option B) for its scalability features, forgetting that PaaS services like App Service can also scale automatically with far less operational burden, especially for a startup with initially few users.

How to eliminate wrong answers

Option B is wrong because Azure Kubernetes Service (AKS) is a container orchestration platform that introduces significant operational overhead (cluster management, node scaling, networking) and is overkill for a small user base, contradicting the goal of minimizing overhead. Option C is wrong because Azure Functions is a serverless compute service designed for event-driven, short-lived workloads, not for hosting a full web application with persistent connections, and Azure Cosmos DB is a NoSQL database, not compatible with the PostgreSQL requirement. Option D is wrong because deploying on Azure Virtual Machines is an IaaS solution that requires manual OS patching, database administration, and scaling, which increases operational overhead and costs, contrary to the PaaS requirement.

255
MCQeasy

A company has virtual machines in Azure that need to be grouped across multiple fault domains and update domains to ensure high availability. They plan to deploy three VMs running the same application tier. Which Azure feature should they use to provide redundancy within a single region?

A.Availability Zone
B.Availability Set
C.Virtual Machine Scale Set with manual scaling
D.Azure Site Recovery
AnswerB

An Availability Set is the correct grouping construct because it logically groups VMs so that Azure automatically distributes them across fault domains (distinct hardware racks with shared power and network switches) and update domains (groups that undergo planned maintenance one at a time). This placement ensures that during either hardware failure or Azure patching, at least one VM in the set remains available, meeting the high-availability requirement within a single datacenter. Availability Sets do not require identical VM configurations, allowing heterogeneous workloads to be protected together.

Why this answer

An Availability Set distributes VMs across multiple fault domains (shared hardware, power, and networking) and update domains (planned maintenance) within a single Azure datacenter. This ensures that at least one VM remains available during both hardware failures and Azure patching cycles. For three VMs running the same application tier, an Availability Set provides the required redundancy without the complexity of zone-level isolation.

Exam trap

The trap here is that candidates often confuse Availability Zones (which provide datacenter-level isolation) with Availability Sets (which provide rack-level isolation within a single datacenter), leading them to select Availability Zones when the scenario only requires intra-datacenter redundancy.

How to eliminate wrong answers

Option A is wrong because Availability Zones provide physical separation across different datacenters within a region, which is overkill and incurs cross-zone latency; the question specifies redundancy within a single region but not across zones. Option C is wrong because Virtual Machine Scale Sets with manual scaling still place VMs across fault and update domains automatically, but the question explicitly asks for grouping across multiple fault and update domains, which is the core purpose of an Availability Set, not a scale set. Option D is wrong because Azure Site Recovery is a disaster recovery solution for replicating VMs to a secondary region, not for providing redundancy within a single region.

256
MCQeasy

A company runs an Azure SQL Database with active geo-replication configured to a secondary region. The primary region experiences a complete outage. The company needs to promote the secondary database to become the new primary with minimal data loss. Which action should they take?

A.Forced failover
B.Planned failover
C.Enable geo-replication
D.Failover
AnswerA

Forced failover is the appropriate action when the primary Azure SQL Database experiences a complete outage and is unreachable. This mechanism immediately promotes the secondary database to become the new primary, ensuring rapid recovery. While active geo-replication is asynchronous and some data loss is inherent if the primary cannot send its final transactions, a forced failover uses the most up-to-date data available on the secondary. This directly satisfies the requirement for minimal data loss by prioritising immediate availability with the latest replicated data.

Why this answer

Forced failover is the correct action because it immediately promotes the secondary database to primary without waiting for synchronization, which is necessary during a complete primary region outage. This option minimizes data loss by accepting any unsynchronized data at the secondary, prioritizing availability over consistency. In contrast, planned failover requires synchronous data transfer and fails if the primary is unreachable.

Exam trap

The trap here is that candidates confuse 'Failover' (which in Azure SQL Database can mean either planned or forced depending on context) with the specific 'Forced failover' action required during a disaster, leading them to select the ambiguous 'Failover' option instead.

How to eliminate wrong answers

Option B (Planned failover) is wrong because it requires the primary database to be online and fully synchronized before promoting the secondary, which is impossible during a complete outage. Option C (Enable geo-replication) is wrong because geo-replication is already configured per the scenario; re-enabling it would not promote the secondary. Option D (Failover) is wrong because 'Failover' in Azure SQL Database context typically refers to a planned failover (with no data loss) or an unplanned failover (forced), but the generic term is ambiguous; the specific action needed here is 'Forced failover' to handle the outage with minimal data loss.

257
MCQmedium

A company deploys a web application across multiple Azure VMs in a single region. They need to distribute incoming HTTP traffic, offload SSL termination, and perform URL-based routing to different backend pools (e.g., /images to one pool, /api to another). Which Azure load balancing solution should they use?

A.Azure Application Gateway
B.Azure Load Balancer
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is the correct choice because it operates at Layer 7 (HTTP/HTTPS), enabling URL path-based routing to distribute traffic to backend Azure VM pools based on request paths. It also provides SSL termination at the gateway, reducing the backend VMs' TLS processing overhead, and supports features like cookie-based session affinity, Web Application Firewall (WAF), and autoscaling—all within a single Azure region, which directly matches the deployment architecture.

Why this answer

Azure Application Gateway is a Layer 7 load balancer that can distribute HTTP traffic, offload SSL termination, and perform URL-based routing to different backend pools. This directly matches the requirements for routing /images and /api traffic to separate pools while handling SSL termination at the gateway.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers can handle HTTP routing and SSL termination, but only Layer 7 solutions like Application Gateway or Front Door can perform URL-based routing and SSL offloading.

How to eliminate wrong answers

Option B is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL termination or URL-based routing, which are Layer 7 features. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that directs traffic based on DNS resolution, not HTTP-level routing or SSL termination. Option D is wrong because Azure Front Door is a global Layer 7 service designed for multi-region scenarios with CDN capabilities, but the question specifies a single-region deployment, making Application Gateway the more appropriate and cost-effective choice.

258
MCQmedium

Your organization uses Azure Monitor to monitor a fleet of 500 VMs running Windows Server. You need to collect security event logs (Event ID 4625 for failed logons) from all VMs and send them to a Log Analytics workspace. The solution must support centralized configuration and be scalable. You also want to filter out high-volume noise events to reduce costs. What should you do?

A.Enable VM Insights on all VMs and use the Performance view to detect failed logons.
B.Stream events to Azure Event Hubs and use a function to filter and send to Log Analytics.
C.Install the Log Analytics agent on each VM and configure Windows Event log collection in the workspace.
D.Deploy the Azure Monitor agent via Azure Policy and create a data collection rule to collect Event ID 4625.
AnswerD

This is the correct, future-ready approach because Azure Monitor agent (AMA) is designed to collect Windows Security events and supports fine-grained XPath filtering in Data Collection Rules (DCRs) to ingest only Event ID 4625. Using Azure Policy ensures the agent is automatically deployed to every VM with consistent configuration, and the DCR can be applied at scale across subscriptions. This avoids manual installation and reduces data costs by filtering noise before it reaches the workspace, while still providing centralized control over the data collection pipeline.

Why this answer

The Azure Monitor agent (AMA) is the current recommended agent for collecting security events from VMs, and using Azure Policy to deploy it ensures centralized, scalable configuration across 500 VMs. A data collection rule (DCR) can be configured to collect only Event ID 4625, filtering out high-volume noise events at the source, which reduces costs by minimizing data ingestion into the Log Analytics workspace.

Exam trap

The trap here is that candidates may choose the Log Analytics agent (MMA) option because it is familiar from legacy setups, but the exam tests knowledge of the newer Azure Monitor agent (AMA) and its centralized configuration via DCRs, which is the recommended and scalable solution for modern environments.

How to eliminate wrong answers

Option A is wrong because VM Insights is designed for performance monitoring (CPU, memory, disk, network) and does not collect security event logs like Event ID 4625; it cannot detect failed logons. Option B is wrong because streaming events to Azure Event Hubs and using a function to filter and send to Log Analytics adds unnecessary complexity and cost; the Azure Monitor agent with a DCR can filter events directly without intermediate services. Option C is wrong because the Log Analytics agent (MMA) is deprecated in favor of the Azure Monitor agent (AMA), and while it can collect Windows event logs, it does not support centralized configuration via DCRs as efficiently as AMA, and it lacks the native filtering capabilities to reduce noise at the source.

259
Multi-Selecthard

You are designing a microservices architecture on Azure Kubernetes Service (AKS). The solution must handle traffic spikes by automatically scaling pods based on CPU utilization. Additionally, you need to minimize cost by scaling down nodes when not in use. Which two features should you implement? (Choose two.)

Select 2 answers
A.Azure Load Balancer
B.Horizontal Pod Autoscaler (HPA)
C.Vertical Pod Autoscaler (VPA)
D.Azure Container Instances (ACI)
E.Cluster Autoscaler
AnswersB, E

Horizontal Pod Autoscaler is a Kubernetes control loop that queries the Metrics API for CPU, memory, or custom application metrics and automatically updates the replica count of a Deployment or ReplicaSet. This scaling mechanism is fundamental to microservices on AKS because it dynamically matches the number of running pod instances to the observed demand, ensuring high availability and cost efficiency without manual intervention.

Why this answer

Horizontal Pod Autoscaler (HPA) automatically scales the number of pod replicas based on observed CPU utilization (or custom metrics), directly addressing the requirement to handle traffic spikes by scaling pods. Cluster Autoscaler automatically adjusts the number of AKS nodes by scaling down unused nodes and scaling up when pods are unschedulable, which minimizes cost by reducing node count during low usage.

Exam trap

The trap here is that candidates often confuse Horizontal Pod Autoscaler (which scales pods) with Cluster Autoscaler (which scales nodes), or mistakenly think that a load balancer or ACI can handle the scaling requirements directly, but the question explicitly requires both pod-level and node-level scaling for cost minimization.

260
Multi-Selecthard

A multinational corporation is designing a backup and disaster recovery strategy for Azure IaaS VMs. The solution must support cross-region failover, meet a recovery point objective (RPO) of 15 minutes, and a recovery time objective (RTO) of 1 hour. Which TWO options should you include in the design?

Select 2 answers
A.Azure Backup with geo-redundant storage (GRS)
B.Azure Backup with locally redundant storage (LRS)
C.Managed disk snapshots
D.Azure Backup with zone-redundant storage (ZRS)
E.Azure Site Recovery
AnswersA, E

Azure Backup with GRS replicates backup data to a secondary region, meeting the cross-region failover requirement and RPO of 15 minutes.

Why this answer

Azure Backup with geo-redundant storage (GRS) (A) is correct because GRS replicates backup data to a secondary Azure region hundreds of miles away, enabling cross-region restore and satisfying the cross-region failover requirement while supporting the 15-minute RPO through frequent backup schedules. Azure Site Recovery (E) is correct because it continuously replicates IaaS VM disks to a target region and can orchestrate failover with RTOs typically under an hour, directly meeting the 1-hour RTO and 15-minute RPO objectives. Azure Backup with LRS (B) is incorrect because locally redundant storage keeps three copies within a single datacenter in one region, providing no cross-region protection.

Managed disk snapshots (C) are incorrect because they are stored regionally and are not a cross-region DR mechanism by themselves. Azure Backup with ZRS (D) is incorrect because zone-redundant storage only replicates across availability zones within one region, not across regions.

Exam trap

Candidates often mistakenly pair Azure Backup with ZRS thinking it provides cross-region redundancy, but ZRS is zone-redundant, not geo-redundant. Additionally, they may overlook that Azure Site Recovery is essential for orchestrated failover with low RTO, while Azure Backup alone (even with GRS) requires a restore operation that may not meet the 1-hour RTO.

261
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to allow external business partners to access an internal web application using their own organizational identities. The solution must support self-service sign-up and enforce multi-factor authentication for partner users. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID B2B collaboration
B.Microsoft Entra ID B2C
C.Microsoft Entra ID Domain Services
D.Microsoft Entra ID Connect
AnswerA

Microsoft Entra ID B2B collaboration is the correct solution because it lets you invite employees from partner organizations as guest users, granting them access to your internal business apps while they authenticate using their own employer-issued Entra ID or other federated credentials. It natively supports conditional access policies such as MFA and allows self-service sign-up for external partners, making it purpose-built for B2B sharing without duplicating identities.

Why this answer

Microsoft Entra ID B2B collaboration is the correct feature because it allows external business partners to access internal applications using their own organizational identities (home directory credentials) without requiring them to have a separate account in your tenant. It supports self-service sign-up through entitlement management and can enforce multi-factor authentication (MFA) via Conditional Access policies that evaluate the partner user's session, even if the partner's home tenant does not enforce MFA.

Exam trap

The trap here is that candidates often confuse B2B collaboration (for business partners with existing organizational identities) with B2C (for customers using social or local accounts), leading them to select B2C when the requirement explicitly states 'business partners' and 'their own organizational identities.'

How to eliminate wrong answers

Option B (Microsoft Entra ID B2C) is wrong because B2C is designed for customer-facing applications where users sign up with social or local identities, not for business partner access with existing organizational identities. Option C (Microsoft Entra ID Domain Services) is wrong because it provides managed domain services (e.g., LDAP, Kerberos) for legacy applications, not external identity federation or self-service sign-up. Option D (Microsoft Entra ID Connect) is wrong because it synchronizes on-premises Active Directory objects to Entra ID for internal users, not for inviting external partners or enforcing MFA on guest users.

262
MCQeasy

Your organization needs to provide temporary, limited-privilege access to Azure resources for external auditors. The access must be time-bound and require approval from a manager. Which Azure feature should you use?

A.Managed identities
B.Conditional Access policies
C.Azure RBAC roles
D.Microsoft Entra Privileged Identity Management (PIM)
AnswerD

Microsoft Entra Privileged Identity Management (PIM) is the correct solution because it provides just-in-time role activation with time-bound assignments and approval-based workflows. Users become eligible for a role and activate it for a limited period by providing a justification, and if required an approver must approve the request. PIM also enforces alerts, auditing, and Multi-Factor Authentication, making it the purpose-built service for temporary limited privileged access.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing time-bound activation of roles with approval workflows. This directly meets the requirement for temporary, limited-privilege access that requires manager approval, making it the correct choice for external auditor scenarios.

Exam trap

The trap here is confusing Azure RBAC roles (static assignments) with PIM's just-in-time activation, leading candidates to choose option C because they overlook the need for time-bound access and approval workflows.

How to eliminate wrong answers

Option A is wrong because Managed identities are designed for Azure resources to authenticate to services without storing credentials, not for granting temporary human access with approval. Option B is wrong because Conditional Access policies enforce access controls based on conditions like location or device state, but they do not provide time-bound role activation or an approval workflow for privileged access. Option C is wrong because Azure RBAC roles define static permissions that are assigned directly to users or groups; they lack built-in time-bound activation and approval workflows, which are required for temporary auditor access.

263
MCQeasy

A financial company must store customer transaction records in Azure Blob Storage. Regulatory requirements mandate that the records must not be modified or deleted for 7 years. Even administrators must be unable to alter or remove the blobs during this period. Which Azure Blob Storage feature should they enable?

A.Immutable storage with time-based retention policy
B.Legal hold
C.Soft delete
D.Versioning
AnswerA

Immutable storage with time-based retention policy enforces write-once-read-many (WORM) semantics on Azure Blob Storage, preventing any modification or deletion of blobs for a user-defined retention interval. This fixed-period lock can be set to exactly 7 years, satisfying the regulatory requirement while ensuring data remains tamper-proof for the mandated duration. Unlike legal hold, the time-based policy has a defined expiry, and the protection is enforced at the storage layer independent of user permissions.

Why this answer

Immutable storage with a time-based retention policy (WORM – Write Once, Read Many) ensures that blobs cannot be modified or deleted for a specified duration, even by administrators. This directly satisfies the 7-year regulatory requirement by locking the data at the storage level, overriding any delete or write operations.

Exam trap

The trap here is that candidates often confuse soft delete or versioning with immutable storage, not realizing that only WORM policies (time-based retention or legal hold) provide true, administrator-proof immutability for a defined period.

How to eliminate wrong answers

Option B (Legal hold) is wrong because legal hold is an indefinite, policy-based lock that must be explicitly cleared; it does not enforce a fixed 7-year retention period and is typically used for litigation, not time-bound regulatory compliance. Option C (Soft delete) is wrong because soft delete only protects against accidental deletion by retaining deleted blobs for a configurable period, but it does not prevent modification or deletion by administrators during the retention window. Option D (Versioning) is wrong because versioning preserves previous blob versions but does not prevent deletion or overwrite of the current version; administrators can still delete or modify blobs, and versioning alone does not enforce a write-once, read-many constraint.

264
MCQmedium

Refer to the exhibit. An Azure Policy is assigned to a subscription. A user tries to create a blob container via the Azure portal and receives a deny error. What is the most likely reason?

A.The policy denies creation of blob containers
B.The blob container requires immutable storage
C.The user is trying to enable public access on the container
D.The storage account does not have encryption enabled
AnswerA

The policy definition applies a Deny effect to the action Microsoft.Storage/storageAccounts/blobServices/containers/write and further constrains the condition to requests where the HTTP method is PUT. Since creating a blob container is performed through a PUT request to the containers endpoint, this policy blocks that creation attempt outright. The policy does not evaluate container properties or settings; it simply prevents the write operation itself, so any PUT aimed at creating a container will fail with an authorization/denial error.

Why this answer

The Azure Policy assigned to the subscription includes a policy definition that explicitly denies the creation of blob containers. When the user attempts to create a blob container via the Azure portal, Azure Policy evaluates the request against the assigned policies and returns a deny error because the action violates the policy rule. This is the most direct and likely reason for the denial.

Exam trap

The trap here is that candidates may assume the error is due to a missing feature or configuration (like immutability or encryption) rather than recognizing that Azure Policy can directly deny resource creation actions based on custom or built-in policy definitions.

How to eliminate wrong answers

Option B is wrong because immutable storage is a feature that can be enabled on a blob container after creation, but it does not prevent the creation of the container itself; the deny error is not related to immutability. Option C is wrong because enabling public access is a configuration setting on a container, not a prerequisite for creation, and Azure Policy would not deny creation solely based on the intent to enable public access unless a specific policy targets that setting. Option D is wrong because encryption is enabled by default on all Azure storage accounts using Azure Storage Service Encryption (SSE), and the absence of encryption would not block container creation; it is a separate compliance check.

265
MCQmedium

You are designing a storage solution for a media company that needs to store large video files (up to 50 GB each) and serve them to a global audience with low latency. The solution must be cost-effective and support resumable uploads. Which Azure storage solution should you recommend?

A.Azure Files with Azure File Sync and Azure CDN.
B.Azure Disk Storage with Azure Load Balancer.
C.Azure Blob Storage with Azure CDN
D.Azure NetApp Files with Azure Front Door.
AnswerC

Azure Blob Storage with Azure CDN is the correct choice for a media company because Blob Storage provides at-scale object storage designed for large binary assets, with support for anonymous read access, SAS tokens, hot/cool/archive tiers, and Azure CDN integration to cache content at edge PoPs for low latency. Blob Storage is considerably more cost-effective for terabytes of media files than any file or block service, and it natively supports AzCopy's resumable uploads, which is critical for transferring very large video assets over intermittent pipelines. The CDN endpoint fronting the blob container offloads origin requests, ensures global low-latency delivery, and can be configured with session affinity, query-string caching, and custom domains, making it the canonical architecture for media distribution in Azure.

Why this answer

Azure Blob Storage is optimized for storing large unstructured data like video files, and Azure CDN ensures low-latency global delivery. Blob Storage natively supports resumable uploads via block blob APIs, making additional services like Azure Files unnecessary. This solution is cost-effective due to Blob Storage's tiered pricing and CDN edge caching.

Exam trap

The trap is that candidates may assume they need Azure Files (option A) or another service for resumable uploads, but Azure Blob Storage's block blob API natively supports resumable uploads, making it the simplest and most cost-effective choice.

How to eliminate wrong answers

Option A is wrong because Azure Files is designed for SMB file shares and shared access, not for serving large video files to a global audience; Azure File Sync adds sync overhead without improving low-latency delivery, and Azure CDN cannot cache Azure Files effectively without additional configuration. Option B is wrong because Azure Disk Storage is for VM disks (block-level storage), not for object storage or serving content globally; Azure Load Balancer distributes traffic to VMs but does not provide low-latency content delivery or resumable uploads. Option D is wrong because Azure NetApp Files is a high-performance NFS/SMB file service for enterprise workloads, not cost-effective for large-scale video serving; Azure Front Door provides global load balancing but does not natively support resumable uploads or replace Blob Storage's object storage capabilities.

266
MCQmedium

A global company stores customer profile data in JSON format. The application requires low-latency writes and reads from multiple regions. The solution must support multi-region writes with automatic conflict resolution and provide high availability. Which Azure Cosmos DB configuration should they choose?

A.SQL API with eventual consistency and multi-region writes enabled
B.MongoDB API with strong consistency and multi-region writes enabled
C.Table API with consistent prefix consistency and single-region writes
D.Gremlin API with session consistency and multi-region writes enabled
AnswerA

The SQL API natively stores JSON documents and supports multi-region writes as long as consistency is not set to strong or bounded staleness. Eventual consistency is the default and, along with session and consistent prefix, is compatible with an Azure Cosmos DB account configured for multiple write regions. When multiple write regions are used, Cosmos DB automatically resolves conflicts using last-writer-wins or a custom conflict resolution policy, making this a fully valid configuration.

Why this answer

The scenario demands low-latency multi-region writes with automatic conflict resolution and high availability. Azure Cosmos DB's SQL API supports multi-region writes with eventual consistency, which is the only consistency level that allows multi-region writes. Eventual consistency provides the lowest latency and highest availability, and Cosmos DB's automatic conflict resolution handles concurrent writes across regions using last-writer-wins (LWW) or custom conflict resolution policies.

Exam trap

The trap here is that candidates often assume strong consistency is required for data integrity, but Azure Cosmos DB enforces that multi-region writes only work with eventual consistency, and automatic conflict resolution handles the trade-off between consistency and availability.

How to eliminate wrong answers

Option B is wrong because strong consistency cannot be used with multi-region writes; Cosmos DB restricts multi-region writes to eventual consistency only, as strong consistency would require synchronous replication across regions, defeating low-latency writes. Option C is wrong because single-region writes do not meet the requirement for multi-region writes, and consistent prefix consistency is not the recommended choice for multi-region write scenarios. Option D is wrong because Gremlin API (graph) is not optimized for JSON document storage and multi-region writes with session consistency do not provide automatic conflict resolution; session consistency is scoped to a single client session and does not handle cross-region conflicts.

267
MCQhard

A company needs to store and analyze petabytes of semi-structured data from IoT devices. The data is append-only and written in time order. They need to support fast queries on time ranges and also aggregate data in real-time. Which Azure data service should they use?

A.Azure Data Explorer
B.Azure Cosmos DB
C.Azure SQL Database
D.Azure Table Storage
AnswerA

Azure Data Explorer is a purpose-built analytics engine for petabyte-scale, time-series data that arrives continuously from IoT sources. It ingests semi-structured payloads (JSON, Avro, etc.) without requiring a predefined schema, then applies columnar storage and a distributed sharding architecture that accelerates real-time aggregation and time-window queries. Its Kusto Query Language (KQL) is designed for slicing, rolling averages, and anomaly detection on streaming telemetry, which makes it the correct choice here.

Why this answer

Azure Data Explorer (ADX) is purpose-built for high-performance analysis of large volumes of time-series and semi-structured data. It supports append-only ingestion, optimized time-range queries via its columnar storage and indexing, and real-time aggregation using Kusto Query Language (KQL) with built-in materialized views and update policies.

Exam trap

The trap here is that candidates often confuse Azure Data Explorer with Azure Cosmos DB because both handle semi-structured data, but Cosmos DB is optimized for transactional workloads with point reads and writes, not for petabyte-scale analytical time-series queries.

How to eliminate wrong answers

Option B (Azure Cosmos DB) is wrong because it is a globally distributed, multi-model NoSQL database optimized for low-latency transactional workloads, not for petabyte-scale analytical queries on append-only time-series data; its indexing and query patterns are not designed for high-throughput time-range scans. Option C (Azure SQL Database) is wrong because it is a relational OLTP database that struggles with petabyte-scale semi-structured data and append-only ingestion rates, and its indexing and query engine are not optimized for time-series analytics. Option D (Azure Table Storage) is wrong because it is a key-value store with limited query capabilities (only on partition and row keys), no native support for time-range aggregations, and poor performance for real-time analytics on large datasets.

268
MCQmedium

A company runs a production Azure SQL Database. They need a business continuity solution that allows point-in-time restore to any time within the last 7 days and provides geo-failover capability with RTO of 1 hour. What is the MOST COST-EFFECTIVE option?

A.Use Azure SQL Database long-term retention (LTR) for backups
B.Deploy a zone-redundant Azure SQL Database
C.Configure active geo-replication with a readable secondary in another region
D.Deploy auto-failover groups with a secondary in another region
AnswerC

Active geo-replication creates an asynchronously replicated, readable secondary database in another Azure region, enabling fast manual failover with a 1-hour RTO when you update the connection string. It supports point-in-time restore on the secondary and costs less than auto-failover groups because it doesn't require multiple databases or managed instance infrastructure. This directly satisfies the geo-disaster-recovery requirement for a single production database.

Why this answer

Active geo-replication with a readable secondary in another region meets the 7-day point-in-time restore requirement (each database has automated backups retained for 7 days by default) and provides geo-failover with an RTO of 1 hour, as the secondary is continuously synchronized and can be manually failed over. It is more cost-effective than auto-failover groups because it does not require the additional listener and routing overhead, and you pay only for the secondary compute and storage.

Exam trap

The trap here is that candidates confuse auto-failover groups (which add automated failover and a listener) with active geo-replication, assuming the extra features are required for the RTO, but the question asks for the most cost-effective option, and active geo-replication meets all stated requirements without the additional cost of the listener and forced same-tier secondary.

How to eliminate wrong answers

Option A is wrong because long-term retention (LTR) extends backup retention beyond 35 days (up to 10 years) but does not provide geo-failover capability or an RTO of 1 hour; it is purely for archival backups. Option B is wrong because zone-redundant databases protect against zonal failures within a single region, not geo-failover to another region, and do not meet the cross-region RTO requirement. Option D is wrong because auto-failover groups provide automated geo-failover with a built-in listener, but they are more expensive than active geo-replication due to the additional read/write listener endpoint and the requirement for a secondary at the same service tier and compute size, whereas active geo-replication allows a lower-cost secondary.

269
MCQhard

A large enterprise is designing a hybrid network architecture. The company has an on-premises data center connected to Azure via ExpressRoute. They want to extend their on-premises network to Azure by using a site-to-site VPN as a backup connection. The company has multiple VNets in Azure that need to communicate with each other and with the on-premises network. The solution must be highly available and provide redundancy for the ExpressRoute connection. You need to recommend a network connectivity design. What should you include?

A.Use Azure ExpressRoute as the primary connection, and configure VNet-to-VNet VPN as a backup for ExpressRoute.
B.Use Azure VPN Gateway to connect the on-premises network to Azure, and use VNet peering for VNet-to-VNet connectivity.
C.Use Azure ExpressRoute as the primary connection, and use Azure Firewall to inspect traffic between VNets.
D.Use Azure ExpressRoute as the primary connection, and configure a site-to-site VPN as a backup. Use VNet peering for VNet-to-VNet connectivity.
AnswerD

This is the architecturally correct hybrid design: ExpressRoute serves as the primary private path with consistent low latency and high throughput, while a site-to-site VPN is provisioned as a failover connection over the public internet to maintain access during an ExpressRoute outage. The VPN is terminated on an Azure VPN Gateway, which, when configured in an active-passive or co-existing setup, can automatically redirect traffic to the encrypted tunnel. VNet peering is then used to enable direct, low-latency connectivity between VNets within Azure, which is independent of the on-premises connections.

Why this answer

It combines ExpressRoute as the primary connection with a site-to-site VPN as a backup, ensuring redundancy for on-premises connectivity. VNet peering is used for VNet-to-VNet communication, which is the recommended method for low-latency, high-bandwidth connectivity between VNets in the same region. This design meets the high availability and redundancy requirements without introducing unnecessary complexity.

Exam trap

The trap here is that candidates often confuse VNet-to-VNet VPN as a backup for ExpressRoute, when in fact a site-to-site VPN from on-premises is required to provide a redundant path for the on-premises connection.

How to eliminate wrong answers

Option A is wrong because VNet-to-VNet VPN is used for connecting VNets to each other, not as a backup for ExpressRoute to the on-premises network; it does not provide a backup path for on-premises connectivity. Option B is wrong because it uses only a VPN Gateway for on-premises connectivity, which lacks the primary high-bandwidth, low-latency ExpressRoute connection and does not meet the requirement for ExpressRoute redundancy. Option C is wrong because Azure Firewall inspects traffic but does not provide a backup connection for ExpressRoute; it addresses security, not redundancy for the WAN link.

270
MCQmedium

Your company runs a mission-critical application on Azure VMs. You need to design a cross-region disaster recovery solution that meets a recovery time objective (RTO) of 15 minutes and a recovery point objective (RPO) of 5 minutes. The solution must minimize costs. What should you recommend?

A.Use Azure SQL Database active geo-replication with a failover group.
B.Use Azure Storage with read-access geo-redundant storage (RA-GRS) and Azure Traffic Manager.
C.Use Azure Backup with geo-redundant storage.
D.Use Azure Site Recovery with replication frequency set to 30 seconds.
AnswerD

Azure Site Recovery (ASR) continuously replicates the VM's disks to a secondary region using a replication frequency configurable down to 30 seconds, which comfortably meets the 5-minute RPO requirement. ASR provides coordinated failover with recovery plans, allowing the VM to be started in the secondary region within the 15-minute RTO target. It is the appropriate DR solution for IaaS VMs, unlike backup, geo-replication, or storage-based options, because it replicates both compute and data asynchronously with low enough lag to satisfy the stated SLA.

Why this answer

Azure Site Recovery (ASR) can replicate Azure VMs to a secondary region with a replication frequency as low as 30 seconds, enabling an RPO of 5 minutes and an RTO of 15 minutes when combined with a planned failover. This meets the mission-critical requirements while minimizing costs compared to always-on active-active solutions, as ASR only incurs costs for replication traffic and storage in the secondary region.

Exam trap

The trap here is that candidates often confuse backup (Azure Backup) with disaster recovery (Azure Site Recovery), assuming geo-redundant backup storage can meet low RPO/RTO targets, when in fact backup is designed for long-term retention and point-in-time restore, not rapid failover.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database active geo-replication with a failover group is designed for PaaS databases, not for replicating entire Azure VMs running a mission-critical application; it does not replicate the VM's OS, configuration, or non-database components. Option B is wrong because read-access geo-redundant storage (RA-GRS) provides read-only access to a secondary region with an RPO typically measured in hours (due to asynchronous replication), and Azure Traffic Manager handles DNS-level routing but cannot achieve the sub-5-minute RPO or 15-minute RTO for VM failover. Option C is wrong because Azure Backup with geo-redundant storage is a backup solution, not a replication or failover solution; its RPO is typically 24 hours or more (based on backup schedule), and recovery involves restoring from a backup, which cannot meet a 15-minute RTO.

271
MCQmedium

A software company hosts multiple small databases for different clients on Azure SQL Database. Each database has low average usage but experiences unpredictable spikes. The company wants to minimize cost by pooling resources across databases while allowing each database to consume resources up to a set limit during spikes. They also need the ability to easily add new databases without manual sizing. Which Azure SQL Database deployment option should they choose?

A.Azure SQL Database elastic pool
B.Azure SQL Database single database with reserved capacity
C.Azure SQL Managed Instance
D.SQL Server on Azure Virtual Machines
AnswerA

An Azure SQL Database elastic pool allocates a shared set of eDTUs or vCores across multiple databases, allowing each database to burst beyond its guaranteed minimum during demand spikes while keeping baseline usage low. You pay for the pool's aggregate compute and storage, not per-database sizing, which dramatically lowers cost when workloads have low average utilization but unpredictable peaks. Adding a new database to the pool requires no additional compute provisioning, and per-database settings like max/min eDTUs let you control resource sharing efficiently.

Why this answer

Azure SQL Database elastic pool is the correct choice because it allows multiple databases to share a fixed pool of resources (eDTUs or vCores), which minimizes cost by pooling resources across databases with low average usage and unpredictable spikes. Each database can automatically burst up to a configurable per-database resource limit (e.g., max eDTU per database) during spikes, and new databases can be added to the pool without manual sizing, as they simply consume from the shared pool.

Exam trap

The trap here is that candidates may choose single database with reserved capacity (Option B) thinking it offers cost savings, but they overlook that reserved capacity applies to a single database and does not provide resource pooling or automatic bursting across multiple databases, making it more expensive for the described workload.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database single database with reserved capacity reserves compute resources for a single database, which does not pool resources across multiple databases and would be cost-inefficient for low-average-usage databases with spikes. Option C is wrong because Azure SQL Managed Instance is a fully managed instance of SQL Server with fixed resource limits per instance, not designed for pooling resources across many small databases with unpredictable spikes, and it requires manual sizing for each new database. Option D is wrong because SQL Server on Azure Virtual Machines requires manual management of VM resources, does not provide built-in resource pooling or automatic bursting across databases, and incurs higher operational overhead and cost for many small databases.

272
MCQmedium

A company runs a data analytics workload that processes large amounts of unstructured data (images and videos). The data is accessed frequently for the first month, then rarely. They need to store the data cost-effectively for 7 years to meet compliance. The solution must support fast retrieval of data within the first month. Which Azure storage solution should they recommend?

A.Azure Blob Storage with hot tier for 30 days, then lifecycle management to cool tier for 6 months, then archive tier
B.Azure Blob Storage with premium tier for 30 days, then lifecycle to archive tier
C.Azure Files with lifecycle management
D.Azure Disk Storage with snapshots
AnswerA

This design correctly aligns storage cost with data access patterns over time. During the first 30 days the data is actively processed, so the hot tier's low latency and high throughput are appropriate; lifecycle management then automatically transitions blobs to the cool tier for 6 months, reducing base storage cost while still allowing analytical reads. After that period, moving to the archive tier provides the cheapest per-gigabyte storage for long-term retention, with retrieval latency acceptable for rarely accessed datasets. Azure Blob Storage scales to massive amounts of unstructured data, making this a cost-effective and operationally efficient lifecycle strategy.

Why this answer

Azure Blob Storage with hot tier for the first 30 days meets the fast retrieval requirement for frequently accessed data, while lifecycle management automatically moves data to cool tier for 6 months and then to archive tier for the remaining 7-year compliance period, minimizing cost. The archive tier offers the lowest storage cost for rarely accessed data, and lifecycle policies ensure seamless transitions without manual intervention.

Exam trap

The trap here is that candidates often confuse 'premium' with 'fast retrieval' and overlook that the hot tier already provides low-latency access for frequently used data, while premium is overkill and cost-prohibitive for this workload.

How to eliminate wrong answers

Option B is wrong because the premium tier is designed for low-latency, high-transaction workloads (e.g., IoT, interactive apps) and is unnecessarily expensive for this scenario; it also lacks a cool tier transition, leading to higher costs before archiving. Option C is wrong because Azure Files is a fully managed file share for SMB/NFS protocols, not optimized for large-scale unstructured data like images and videos, and its lifecycle management is limited compared to Blob Storage tiers. Option D is wrong because Azure Disk Storage provides block-level storage for VMs, not cost-effective long-term archival for unstructured data, and snapshots are incremental backups, not a tiered storage solution for compliance.

273
MCQeasy

A company uses Azure Backup to protect on-premises Windows servers and Azure VMs. They need to restore a file from a backup of an Azure VM that was deleted three months ago. The backup policy retains daily backups for 30 days and weekly backups for 12 months. What is the CORRECT way to restore the file?

A.Azure Backup does not support file-level restore for Azure VMs; restore the entire disk
B.Restore the entire VM from a weekly recovery point and then copy the file
C.Use the 'Restore to a new VM' option and select the file during the restore process
D.Use the file-level recovery option to mount the recovery point as a drive and copy the file
AnswerD

Azure Backup supports file-level recovery for Azure VMs: in the Recovery Services vault, select the recovery point and choose 'File Recovery', which downloads a script (PowerShell for Windows, bash for Linux) that mounts the recovery point as an iSCSI drive on your current VM. You then copy the required file from that mounted drive and, when finished, unmount it to release the connection. This is the correct, supported method because it gives you direct access to the file system without restoring the entire VM or recreating it.

Why this answer

Azure Backup supports file-level recovery for Azure VMs by mounting the recovery point as a network drive using iSCSI. This allows you to browse and copy individual files without restoring the entire VM or disk. Since the backup is older than 30 days but within 12 months, a weekly recovery point is available and can be used for file-level restore.

Exam trap

The trap here is that candidates assume file-level recovery is not available for Azure VMs (similar to on-premises agent backups) or that they must restore the entire VM, but Azure Backup explicitly provides a 'File Recovery' option for Azure VM backups that works even after the VM is deleted.

How to eliminate wrong answers

Option A is wrong because Azure Backup does support file-level restore for Azure VMs via the 'File Recovery' option, which mounts the recovery point as a drive. Option B is wrong because restoring the entire VM is unnecessary and inefficient; file-level recovery avoids the overhead of creating a full VM just to copy a single file. Option C is wrong because the 'Restore to a new VM' option does not allow selecting individual files during the restore process; it restores the entire VM, and file selection is only available through the file-level recovery workflow.

274
MCQhard

Your company has a hybrid identity environment with 10,000 on-premises users synchronized to Microsoft Entra ID using Microsoft Entra Connect. You plan to implement a modern access control strategy for all cloud applications. The requirements are: enforce multifactor authentication (MFA) for all users when accessing sensitive applications, allow users to self-remediate risky sign-ins via a mobile app, and minimize infrastructure complexity. You need to design the identity and governance solution. What should you do?

A.Deploy Azure AD Domain Services and configure Kerberos authentication for cloud apps. Use Azure MFA Server on-premises for MFA enforcement.
B.Configure Microsoft Entra ID Protection to detect risky sign-ins and create a conditional access policy that requires MFA for sensitive apps. Enable the risky user policy to require password change, and use Microsoft Authenticator for self-remediation.
C.Implement Microsoft Defender for Identity to monitor on-premises AD and require MFA via on-premises NPS extension.
D.Use Microsoft Entra Permissions Management to enforce MFA policies and manage user permissions.
AnswerB

Microsoft Entra ID Protection continuously evaluates user and sign-in risk signals (e.g., impossible travel, leaked credentials, anonymous IP) and makes them available to Conditional Access policies. A policy can require Microsoft Entra MFA only when a user is classified as risky for sensitive applications, while the user-risk policy can force an authenticated password change to remediate a compromised account. Microsoft Authenticator enables self-remediation by providing number matching and push notifications so a user can approve MFA and then complete a password reset without a helpdesk call.

Why this answer

It uses Microsoft Entra ID Protection to detect risky sign-ins and a Conditional Access policy to require MFA for sensitive applications, meeting the MFA enforcement requirement. The risky user policy requiring a password change combined with Microsoft Authenticator for self-remediation allows users to resolve their own risk without admin intervention, satisfying the self-remediation requirement. This approach minimizes infrastructure complexity by relying entirely on cloud-native services rather than on-premises components.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Identity or Azure AD Domain Services with identity protection and access control solutions, overlooking that Entra ID Protection and Conditional Access are the correct cloud-native services for risk-based MFA enforcement and self-remediation.

How to eliminate wrong answers

Option A is wrong because deploying Azure AD Domain Services and configuring Kerberos authentication for cloud apps does not enforce MFA or provide self-remediation; Azure MFA Server is deprecated and adds on-premises complexity, contradicting the requirement to minimize infrastructure complexity. Option C is wrong because Microsoft Defender for Identity monitors on-premises AD for security threats but does not enforce MFA or provide self-remediation; the on-premises NPS extension for MFA requires additional infrastructure and does not support user self-remediation via a mobile app. Option D is wrong because Microsoft Entra Permissions Management (formerly CloudKnox) focuses on cloud infrastructure entitlement management and permissions, not on enforcing MFA policies or providing self-remediation for risky sign-ins.

275
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect identity risks, such as users with leaked credentials or sign-ins from anonymous IP addresses, and generate alerts. They also want to automatically trigger a password reset for high-risk users. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Access Reviews
AnswerA

Identity Protection continuously evaluates sign-in and user risk signals, including leaked credentials and anonymous IP sign-ins, raising risk detections automatically. Its risk-based Conditional Access policies can then force a password reset when a user is flagged high risk, satisfying both requirements.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to automatically detect identity risks such as leaked credentials and sign-ins from anonymous IP addresses. It generates alerts based on risk detections and can be configured to automatically trigger remediation actions like forcing a password reset for high-risk users through risk-based policies.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, but Conditional Access is a policy engine that enforces controls based on risk signals, whereas Identity Protection is the service that generates those risk signals and can directly trigger password resets.

How to eliminate wrong answers

Option B (Privileged Identity Management) is wrong because it focuses on just-in-time privileged access management and role activation, not on detecting identity risks like leaked credentials or anonymous IP sign-ins. Option C (Conditional Access) is wrong because it enforces access control policies based on signals (e.g., location, device compliance) but does not natively detect or alert on identity risks or automatically trigger password resets; it can integrate with Identity Protection but is not the primary feature for risk detection. Option D (Access Reviews) is wrong because it provides periodic attestation of group memberships and role assignments, not real-time risk detection or automated password reset triggers.

276
MCQhard

A company uses Microsoft Entra ID (Microsoft Entra ID). They have many guest users with access to internal SharePoint sites and applications. They need to review guest user access every 90 days and automatically remove access if the guest does not respond to the review request. The solution must be fully automated without custom scripting. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Access Reviews
B.Microsoft Entra ID Conditional Access
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Privileged Identity Management
AnswerA

Microsoft Entra ID Access Reviews are the governance feature that handles the recurring recertification of guest accounts, group memberships, and application assignments. An admin can create a review that periodically asks guest users to self-attest or asks their manager to approve continued access, with automatic removal after a specified non-response period. This ensures guest access is regularly validated and cleaned up, meeting the requirement described.

Why this answer

Microsoft Entra ID Access Reviews is the correct feature because it allows administrators to create recurring reviews of guest user access to groups, applications, and SharePoint sites. It can be configured to automatically remove access if the guest does not respond within a specified period (e.g., 90 days), and it supports full automation without custom scripting by leveraging built-in review schedules and auto-apply actions.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Access Reviews, but PIM is designed for privileged roles and requires activation, whereas Access Reviews handle recurring attestation of any user's access, including guest users, with automatic removal on non-response.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Conditional Access enforces access policies based on signals like location or device state, but it does not provide recurring access reviews or automatic removal of access for non-responsive guests. Option C is wrong because Microsoft Entra ID Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) but does not schedule periodic guest access reviews or remove access based on lack of response. Option D is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not recurring reviews of standard guest user access to SharePoint sites and applications.

277
MCQmedium

A company is building a global real-time collaboration platform. The application data is stored as JSON documents and needs to be available for low-latency reads and writes from multiple geographic regions. The application must support multi-region writes so that users can update data from any region with automatic conflict resolution. The company wants a fully managed database service with a guaranteed SLA for availability and throughput. Which Azure data service should they choose?

A.Azure Cosmos DB with SQL API and multiple write regions
B.Azure SQL Database with active geo-replication
C.Azure Table Storage
D.Azure Cache for Redis
AnswerA

Azure Cosmos DB with the SQL API and multiple write regions is the only option that enables true multi-region writes, allowing every regional replica to accept write operations simultaneously. This is essential for a global real-time collaboration platform because users in different parts of the world experience low-latency writes without being forced to a single primary. Cosmos DB automatically handles conflict resolution using policies such as last-writer-wins or custom merge procedures, and its turnkey global distribution provides high availability (99.999% SLA) and multiple well-defined consistency levels, making it the ideal underlying data store for such a workload.

Why this answer

Azure Cosmos DB with SQL API and multiple write regions is the correct choice because it is a fully managed, globally distributed NoSQL database that natively supports multi-region writes with automatic conflict resolution. It provides low-latency reads and writes from any region, a guaranteed SLA for availability (99.999% for multi-region writes) and throughput, and is optimized for JSON document storage, making it ideal for a real-time collaboration platform.

Exam trap

The trap here is that candidates often confuse active geo-replication in Azure SQL Database (which supports only single-region writes) with true multi-region write support, leading them to choose Option B despite its read-only secondary regions.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database with active geo-replication supports only a single writable primary region; secondary regions are read-only, which does not meet the requirement for multi-region writes. Option C is wrong because Azure Table Storage is a key-value store that does not support multi-region writes with automatic conflict resolution and lacks a guaranteed throughput SLA. Option D is wrong because Azure Cache for Redis is an in-memory cache, not a fully managed database service; it does not provide durable storage or native multi-region write capabilities with conflict resolution.

278
Multi-Selecthard

Your company is designing a governance strategy for Azure. You need to ensure that all resource groups in a subscription are created with a specific naming convention and mandatory tags. Which THREE services or features should you use together? (Choose three.)

Select 3 answers
A.Azure RBAC
B.Azure Blueprints
C.Management Groups
D.Azure Policy
E.Resource Locks
AnswersB, C, D

Azure Blueprints packages Role Assignments, Policy Assignments, Azure Resource Manager templates, and resource groups into a single, versionable, assignable artifact. When assigned to a subscription, the included policy assignments automatically enforce naming patterns and tag requirements, while bundled ARM templates can deploy resources with consistent tags. Blueprints maintain a tracking record of assignments and allow a governance team to orchestrate compliance across many subscriptions, making it a holistic governance solution. Because it can directly embed Azure Policy definitions, it is a correct answer for enforcing naming and tag governance.

Why this answer

Azure Blueprints is correct because it enables the orchestrated deployment of Azure Policy, RBAC, and resource templates as a single composable artifact. By defining a blueprint that includes a policy for naming conventions and mandatory tags, you can enforce these requirements consistently across all resource groups within a subscription or management group hierarchy.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which controls permissions) with Azure Policy (which enforces rules on resource properties), or they overlook that Blueprints is the orchestration layer that bundles Policy, RBAC, and templates together to enforce governance at scale.

279
MCQeasy

A company uses Microsoft Entra ID. They want to enforce that all users must use multi-factor authentication (MFA) when accessing sensitive applications from outside the corporate network, but allow access without MFA when coming from the corporate office IP range. Which Microsoft Entra ID feature should they use to create this policy?

A.Conditional Access policy
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Microsoft Entra ID roles
AnswerA

Conditional Access is the Entra ID engine for evaluating access signals, including IP geolocation via named locations, and then applying grant controls such as requiring MFA. A policy can be scoped to users and apps, and for the 'location' condition, an untrusted or unfamiliar IP address triggers the MFA grant control, while trusted corporate IPs may skip it. This directly enforces MFA only when needed, matching the requirement.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to define access controls based on conditions such as user location, device state, and application sensitivity. By creating a policy that requires MFA for all users accessing sensitive applications from outside the corporate network, and excluding the trusted corporate office IP range from the MFA requirement, the company can enforce the desired behavior. This is the correct feature because it directly supports location-based access controls and granular policy conditions.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based policies with Conditional Access's location-based MFA enforcement, assuming that risk policies can also enforce MFA based on network location, but Identity Protection only triggers MFA based on risk level, not static IP ranges.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and remediating identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) and does not provide the ability to enforce MFA based on network location or IP ranges. Option C (Privileged Identity Management, PIM) is wrong because it is designed for just-in-time privileged role activation and access reviews, not for enforcing MFA on end-user access to applications based on location. Option D (Microsoft Entra ID roles) is wrong because roles define administrative permissions within the directory, not access policies for end-user application access; they cannot enforce MFA based on network location.

280
MCQhard

Refer to the exhibit. You deploy this Azure Network Watcher connection monitor to test TCP connectivity on port 443 between two VMs. The test consistently shows 'Unreachable' status. Both VMs are running and have correct NSG rules allowing inbound port 443 from the source VM's IP. What is the most likely cause?

A.The source VM does not have the Network Watcher Agent installed.
B.The destination VM's NSG is blocking the traffic despite the rule.
C.The destination VM's private IP address is incorrect.
D.A firewall on the destination VM is blocking TCP port 443.
AnswerA

Connection Monitor relies on the Network Watcher Agent (AzureNetworkWatcherExtension) installed in the source VM's guest OS to originate synthetic probe traffic. Without that agent, the monitor cannot even send TCP 443 tests to the destination, so the probe results will show 'unreachable' regardless of how permissive the NSGs or route tables are. The exhibit confirms all NSG rules are correct, so a missing source agent is the definitive root cause.

Why this answer

Azure Network Watcher connection monitor relies on the Network Watcher Agent extension installed on both source and destination VMs to collect and report connectivity data. Without the agent on the source VM, the test cannot initiate the TCP probes, resulting in a persistent 'Unreachable' status regardless of NSG rules or VM health.

Exam trap

The trap here is that candidates often assume NSG rules are the sole cause of connectivity failures, overlooking the prerequisite that the Network Watcher Agent must be installed on both VMs for connection monitor to function.

How to eliminate wrong answers

Option B is wrong because the question states that correct NSG rules allowing inbound port 443 from the source VM's IP are in place, so the NSG is not blocking traffic. Option C is wrong because an incorrect private IP address would cause a different error (e.g., 'Invalid endpoint' or failure to resolve), not a consistent 'Unreachable' status in a connection monitor test that already references the correct VM. Option D is wrong because while a guest OS firewall could block port 443, the question specifies that the test consistently shows 'Unreachable' and both VMs are running with correct NSG rules; the most likely cause given the dependency on the Network Watcher Agent is its absence, not a firewall misconfiguration.

281
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to provide external business partners with access to an internal application. The access must be time-limited to 60 days, approved by a manager within the partner company, and automatically expire. The company also needs to generate reports of who has access. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra ID B2B collaboration with entitlement management
B.Microsoft Entra ID B2C custom policies
C.Microsoft Entra ID Identity Governance with Privileged Identity Management (PIM)
D.Microsoft Entra ID Conditional Access with session controls
AnswerA

Microsoft Entra ID B2B collaboration with entitlement management is correct because it specifically addresses granting external partners access to internal applications with time-bound, approval-based access packages. Entitlement management enables admins to create access packages that include multiple assignments, require approvals, set expiration dates, and provide access reviews, while B2B collaboration supplies the necessary identity lifecycle and authentication for external users. This combination delivers governed, auditable, and expiring access for 10 partners, aligning with the requirement for approval and time-bound access.

Why this answer

Microsoft Entra ID B2B collaboration with entitlement management allows you to invite external users from partner companies and manage their access through access packages. These packages can enforce time-limited access (e.g., 60 days), require approval from the partner's manager, and automatically expire. Entitlement management also provides built-in reporting to track who has access, meeting all stated requirements.

Exam trap

The trap here is confusing Identity Governance with Privileged Identity Management (PIM) — PIM is for privileged roles, not for managing external partner access with time-limited, approved, and expiring access packages.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID B2C custom policies are designed for consumer-facing identity scenarios (e.g., sign-up/sign-in for customers), not for granting time-limited access to external business partners with manager approval and automatic expiration. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation for internal users, not on managing external partner access with time limits, approval workflows, and expiration. Option D is wrong because Conditional Access with session controls enforces policies during authentication (e.g., MFA, device compliance) but cannot manage time-limited access, approval workflows, or automatic expiration for external users.

282
MCQhard

A company has multiple Azure VNets deployed in a hub-spoke topology. They want to inspect all outbound internet traffic from spoke VMs using a central firewall and ensure that traffic from all VNets goes through the firewall before reaching the internet. They also need to log all outbound connections. Which architecture should they implement?

A.Deploy network virtual appliances (NVAs) in each spoke VNet and configure user-defined routes (UDRs) to route internet traffic to the NVAs
B.Deploy Azure Firewall in the hub VNet and configure a default route (0.0.0.0/0) in each spoke's route table pointing to Azure Firewall as the next hop
C.Use Azure Application Gateway with Web Application Firewall (WAF) in the hub VNet to inspect all traffic
D.Deploy Azure Firewall in each spoke VNet and use Azure Monitor to aggregate logs
AnswerB

In this design, Azure Firewall is deployed into a dedicated AzureFirewallSubnet in the hub, and each spoke's route table contains a 0.0.0.0/0 UDR with the firewall's private IP as the next hop. Because Azure Firewall performs destination NAT and source network address translation (SNAT), all spoke egress emerges from the hub with a single public IP while every connection is logged and inspectable. This creates a true central enforcement point for outbound traffic, supports policy consistency, and is the standard hub-spoke egress pattern.

Why this answer

Azure Firewall is a managed, stateful firewall-as-a-service that can centrally inspect and log outbound internet traffic. By deploying Azure Firewall in the hub VNet and configuring a default route (0.0.0.0/0) in each spoke's route table with the Azure Firewall private IP as the next hop, all outbound traffic from spoke VMs is forced through the firewall before reaching the internet. This satisfies both the inspection and logging requirements, as Azure Firewall provides built-in outbound connection logging via diagnostic settings.

Exam trap

The trap here is that candidates often confuse Azure Firewall with Azure Application Gateway, mistakenly thinking WAF can inspect outbound traffic, or they assume deploying NVAs per spoke is acceptable for central inspection, missing the requirement for a single central firewall in the hub.

How to eliminate wrong answers

Option A is wrong because deploying NVAs in each spoke VNet violates the central inspection requirement and introduces management overhead; it also does not ensure traffic from all VNets goes through a single central firewall. Option C is wrong because Azure Application Gateway with WAF is a Layer 7 load balancer designed for inbound HTTP/S traffic inspection, not for routing or inspecting all outbound internet traffic (including non-HTTP protocols). Option D is wrong because deploying Azure Firewall in each spoke VNet creates a decentralized model that fails the central inspection requirement, and Azure Monitor alone does not enforce routing—it only aggregates logs without controlling traffic flow.

283
MCQhard

Your company runs a mission-critical application on Azure Virtual Machines that requires a Recovery Time Objective (RTO) of 5 minutes and a Recovery Point Objective (RPO) of 1 minute. The application uses a single VM with a managed disk. You need to design a disaster recovery solution that meets these requirements with minimal cost. What should you recommend?

A.Configure Azure Backup for the VM with a 1-minute backup frequency.
B.Store the managed disk in geo-redundant storage and use Azure Resource Manager templates to redeploy.
C.Use Azure Site Recovery to replicate the VM to a secondary region with a recovery plan.
D.Deploy a second VM in a secondary region and use continuous replication with Azure Migrate.
AnswerC

Azure Site Recovery replicates Azure VM disks continuously to a secondary region and can achieve an RPO as low as 5 seconds and an RTO of minutes, especially when you use recovery plans to sequence failover and runbook steps. Replica VMs are not continuously powered on, so you pay only for replicated storage and compute during test failovers rather than for a full standby VM. This natively meets the 5-minute RPO/RTO requirement and is the cost-effective DR service purpose-built for this scenario.

Why this answer

Azure Site Recovery (ASR) provides continuous replication with RPO as low as 30 seconds and RTO of minutes when using a recovery plan, meeting the 5-minute RTO and 1-minute RPO requirements. ASR replicates the VM to a secondary region and allows orchestrated failover with minimal cost compared to running a standby VM. This is the only option that satisfies both the RTO and RPO targets for a mission-critical application.

Exam trap

The trap here is that candidates confuse Azure Backup (designed for long-term retention with hourly/daily backups) with Azure Site Recovery (designed for replication and rapid failover), and mistakenly think backup frequency can be set to 1 minute, which is technically impossible with Azure Backup's architecture.

How to eliminate wrong answers

Option A is wrong because Azure Backup supports a minimum backup frequency of 4 hours for VM backups (or 12 hours for enhanced policy), far exceeding the 1-minute RPO requirement, and RTO is typically hours due to restore time. Option B is wrong because geo-redundant storage (GRS) for managed disks provides asynchronous replication with an RPO of typically 15 minutes or more, and redeploying via ARM templates does not guarantee a 5-minute RTO due to provisioning delays and lack of pre-staged resources. Option D is wrong because Azure Migrate is a discovery and migration tool, not a disaster recovery replication service; it does not provide continuous replication for DR, and deploying a second VM with manual replication would be costly and fail to meet RTO/RPO without orchestration.

284
MCQmedium

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to design a monitoring solution to detect when users are assigned to high-privilege roles (e.g., Global Administrator) and ensure that any such assignment triggers an automated investigation. Additionally, you need to monitor sign-in failures for guest users and automatically block accounts after 5 failed attempts within 10 minutes. You have the following requirements: 1) Use a cloud-native solution that minimizes administrative overhead. 2) Integrate with Microsoft Sentinel for incident response. 3) Use built-in features where possible. What should you do?

A.Use Microsoft Entra audit logs streamed to Log Analytics, create Azure Logic Apps to detect role assignments and sign-in failures, and trigger Sentinel incidents.
B.Use Azure Policy to audit role assignments and create custom KQL functions in Log Analytics to detect sign-in failures, then forward to Sentinel.
C.Use Microsoft Entra Privileged Identity Management (PIM) alerts for role assignments and Microsoft Entra Identity Protection for sign-in risk policies; integrate both with Microsoft Sentinel.
D.Deploy Microsoft Identity Manager (MIM) on-premises to monitor role changes, and use Azure AD Connect Health for sign-in failures.
AnswerC

This is the correct approach because it uses purpose-built Microsoft Entra security controls rather than custom or legacy tooling. PIM generates alerts on permanent role assignments and privileged role activations, enabling review of who has elevated access, while Identity Protection evaluates sign-in risk signals (e.g., password spray, impossible travel, anonymous IP) and can enforce policies to block sign-ins after repeated failures or require MFA. Both natively integrate with Microsoft Sentinel through out-of-the-box data connectors, giving security analysts a unified SIEM view without building custom orchestration logic.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides built-in alerts for high-privilege role assignments, and Microsoft Entra Identity Protection offers risk-based policies for sign-in failures, including user risk policies that can automatically block accounts after a specified number of failures. Both services natively integrate with Microsoft Sentinel via built-in data connectors, enabling automated incident creation with minimal administrative overhead, meeting all requirements.

Exam trap

The trap here is that candidates often over-engineer a solution with custom Logic Apps or KQL queries, overlooking the fact that PIM and Identity Protection already provide built-in alerting and automated blocking capabilities that natively integrate with Sentinel, satisfying the 'cloud-native' and 'minimize administrative overhead' requirements.

How to eliminate wrong answers

Option A is wrong because while audit logs can be streamed to Log Analytics, using Azure Logic Apps to detect role assignments and sign-in failures introduces unnecessary custom development and administrative overhead, contradicting the requirement to use built-in features and minimize overhead. Option B is wrong because Azure Policy is designed for auditing and enforcing compliance of Azure resources, not for monitoring Entra ID role assignments or sign-in failures; custom KQL functions in Log Analytics would require manual setup and lack the automated blocking capability for guest accounts. Option D is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution that adds complexity and does not provide cloud-native monitoring; Azure AD Connect Health focuses on synchronization health, not sign-in failure monitoring or automated blocking.

285
MCQmedium

A company ingests millions of IoT sensor data points per second. They need a fully managed analytics service optimized for time-series data that can ingest high-velocity data, perform real-time analytics, and store data for historical analysis. The solution must integrate with Azure Stream Analytics for stream processing. Which Azure data service should they choose?

A.Azure Cosmos DB
B.Azure SQL Database
C.Azure Data Explorer (ADX)
D.Azure Blob Storage
AnswerC

Azure Data Explorer (ADX) is a big data analytics service specifically engineered for time-series and log data, combining a columnar storage engine with a distributed, scale-out architecture. It can ingest millions of events per second from Azure Stream Analytics, IoT Hub, or Event Hubs, and its Kusto Query Language (KQL) provides native time-series functions such as bin(), make-series, and series_decompose for real-time aggregation, anomaly detection, and forecasting. The engine uses automatic indexing, caching, and data compression to deliver rapid query responses over billions of records, making it the correct choice for this IoT scenario.

Why this answer

Azure Data Explorer (ADX) is the correct choice because it is a fully managed, high-performance analytics service optimized for time-series and log data. It can ingest millions of IoT sensor data points per second, perform real-time analytics with sub-second query latency, and store data for historical analysis. ADX natively integrates with Azure Stream Analytics for stream processing, making it ideal for this scenario.

Exam trap

The trap here is that candidates often confuse Azure Data Explorer with Azure Cosmos DB or Azure SQL Database because they all support time-series data, but only ADX is purpose-built for high-velocity ingestion and real-time analytics with native Stream Analytics integration.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL database designed for transactional workloads with multi-model support, not optimized for high-velocity time-series analytics or native integration with Azure Stream Analytics. Option B is wrong because Azure SQL Database is a relational database for OLTP workloads, lacking the columnar storage, ingestion pipeline, and query engine optimized for time-series data at millions of events per second. Option D is wrong because Azure Blob Storage is an object storage service for unstructured data, not an analytics engine; it cannot perform real-time analytics or directly integrate with Azure Stream Analytics for stream processing.

286
MCQeasy

A company plans to migrate on-premises applications to Azure. They require users to authenticate using their existing on-premises Active Directory credentials without syncing password hashes to the cloud. Which Microsoft Entra ID authentication method should they use?

A.Microsoft Entra ID Pass-through Authentication
B.Microsoft Entra ID Password Hash Sync
C.Microsoft Entra ID Federation Services (AD FS)
D.Microsoft Entra ID Connect with Seamless SSO
AnswerA

Pass-through Authentication (PTA) uses a lightweight agent on a domain-joined server to validate user passwords directly against on-premises Active Directory. Because authentication occurs on-premises, no password hashes are ever transferred to or stored in Microsoft Entra ID, which precisely satisfies the stated requirement to avoid hash sync. PTA is also simpler to deploy than AD FS while still supporting interactive sign-in.

Why this answer

Pass-through Authentication (PTA) validates user passwords directly against on-premises Active Directory without storing password hashes in the cloud. A lightweight agent on-premises forwards authentication requests to the local domain controller, meeting the requirement to avoid password hash synchronization.

Exam trap

The trap here is that candidates often confuse Seamless SSO (which is a convenience feature, not an authentication method) with a primary authentication method, or they assume AD FS is required when the real constraint is avoiding password hash sync.

How to eliminate wrong answers

Option B (Password Hash Sync) is wrong because it synchronizes password hashes to Microsoft Entra ID, which violates the requirement to not sync password hashes. Option C (AD FS) is wrong because it requires deploying and managing federation infrastructure (on-premises or in Azure) and does not inherently avoid password hash sync; it also introduces additional complexity and a separate trust relationship. Option D (Seamless SSO) is wrong because it is not a standalone authentication method—it is a feature that works with Password Hash Sync or Pass-through Authentication to provide silent sign-on, and by itself it does not handle password validation without one of those methods.

287
MCQeasy

Your organization has a policy that all administrative access to Azure resources must be performed using just-in-time (JIT) access. Which Azure service allows you to enable JIT VM access?

A.Azure Policy
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Azure AD Privileged Identity Management
AnswerB

Microsoft Defender for Cloud is the correct answer because its Just-In-Time (JIT) VM access feature dynamically locks down inbound traffic to VMs using network security groups (NSGs) and opens configured ports only when an authorized user requests access for a predefined time window. The feature integrates with Azure AD and MFA to validate requests, and then automatically restores the NSG rules to a denied state, thereby reducing brute-force and port exhaustion attack vectors.

Why this answer

Microsoft Defender for Cloud provides just-in-time (JIT) VM access, which locks down inbound traffic to Azure VMs by creating network security group (NSG) rules that deny all inbound traffic except for specific ports. When a user requests access, Defender for Cloud temporarily creates an allow rule for the requested ports and source IP, then automatically removes it after the configured time period. This directly enforces the policy that administrative access must be JIT.

Exam trap

The trap here is that candidates often confuse Azure AD Privileged Identity Management (PIM), which handles just-in-time role activation at the Azure RBAC control plane, with Defender for Cloud's JIT VM access, which handles just-in-time network-level access to VM ports at the data plane.

How to eliminate wrong answers

Option A is wrong because Azure Policy is used to enforce organizational standards and assess compliance at scale (e.g., requiring specific VM SKUs or tagging), but it does not provide the time-bound, on-demand access control mechanism for VM ports that JIT requires. Option C is wrong because Microsoft Sentinel is a security information and event management (SIEM) and security orchestration automated response (SOAR) solution that ingests logs and alerts; it can detect threats but does not natively manage JIT VM access. Option D is wrong because Azure AD Privileged Identity Management (PIM) manages just-in-time activation of Azure AD roles and Azure resource roles (e.g., Contributor, Owner) at the control plane level, but it does not control network-level access to VM ports (data plane).

288
MCQmedium

Your company has a hybrid network with multiple on-premises sites connected to Azure via ExpressRoute. You need to design a DNS resolution strategy that allows Azure resources to resolve on-premises hostnames and on-premises clients to resolve Azure hostnames. The solution must minimize administrative overhead. What should you use?

A.Azure Bastion
B.Azure DNS public zones with conditional forwarding
C.Azure DNS Private Resolver
D.Azure Firewall DNS proxy
AnswerC

Azure DNS Private Resolver is the correct choice because it provides managed inbound and outbound DNS endpoints within an Azure virtual network, enabling bidirectional name resolution between on-premises infrastructure and Azure private DNS zones. An inbound endpoint gives on-premises DNS servers a fixed IP address for forwarding queries to Azure private zones, while an outbound endpoint with forwarding rulesets lets Azure query on-premises DNS for internal names. This service supports conditional forwarding natively and removes the need to deploy and patch custom DNS VMs, making it a truly hybrid-native resolution option.

Why this answer

Azure DNS Private Resolver enables hybrid DNS resolution by forwarding DNS queries between on-premises networks and Azure virtual networks without requiring domain-joined VMs or custom DNS servers. It supports conditional forwarding to on-premises DNS servers via ExpressRoute, allowing Azure resources to resolve on-premises hostnames and vice versa, while minimizing administrative overhead through a managed service.

Exam trap

The trap here is that candidates often confuse Azure DNS public zones with private DNS resolution, overlooking that conditional forwarding requires a DNS resolver or forwarder, not just a zone, and that Azure DNS Private Resolver is the managed service designed specifically for hybrid DNS scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Bastion is a managed jump box service for secure RDP/SSH access to VMs, not a DNS resolution service. Option B is wrong because Azure DNS public zones are for internet-facing DNS resolution and do not support conditional forwarding to on-premises DNS servers; conditional forwarding is a feature of DNS servers, not public zones. Option D is wrong because Azure Firewall DNS proxy can forward DNS queries but is designed for outbound traffic filtering and inspection, not for bidirectional hybrid DNS resolution with on-premises conditional forwarding, and it adds unnecessary complexity and cost.

289
Multi-Selectmedium

Which TWO of the following are benefits of using Azure Cosmos DB for a globally distributed application?

Select 2 answers
A.Multiple well-defined consistency levels
B.Full support for SQL Server features like stored procedures
C.Turnkey global distribution across multiple Azure regions
D.Automatic failover to a secondary region without manual intervention
E.Support for only the SQL API
AnswersA, C

Cosmos DB exposes five well-defined consistency levels—Strong, Bounded Staleness, Session, Consistent Prefix, and Eventual—giving you fine-grained control over the trade-off between data freshness and availability/latency. Unlike a fixed default, you can set the consistency level at the account or even at the individual request level, which is a core selling point for globally distributed workloads.

Why this answer

Azure Cosmos DB offers multiple well-defined consistency levels (Strong, Bounded Staleness, Session, Consistent Prefix, Eventual) that allow developers to balance data consistency, availability, and latency according to application requirements. This flexibility is a key benefit for globally distributed applications because different operations may tolerate different levels of staleness while still meeting SLAs.

Exam trap

The trap here is that candidates often confuse 'automatic failover' with 'no manual intervention required'—Azure Cosmos DB requires explicit configuration (enabling automatic failover and setting region priorities) for it to occur automatically, and even then, failover is not instantaneous and may involve a brief period of unavailability.

290
MCQmedium

A company is building a customer-facing web application. They want to allow users to sign in using their existing social accounts (Microsoft, Google, Facebook) or create a local account. The solution must be fully managed and support custom branding. Which Azure service should they use?

A.Microsoft Entra ID B2C (Business to Consumer)
B.Microsoft Entra ID External Identities
C.Microsoft Entra ID B2B collaboration
D.Microsoft Entra ID Application Proxy
AnswerA

Correct. Microsoft Entra ID B2C is the dedicated customer identity and access management (CIAM) service, purpose-built for consumer-facing applications. It supports local accounts (email or user ID with password) and social identity providers such as Google, Facebook, Apple, and Microsoft, and it offers customizable user flows for sign-up, sign-in, and password reset. For a customer-facing web app requiring self-service registration and consumer authentication, Microsoft Entra ID B2C is the exact service to deploy.

Why this answer

Microsoft Entra ID B2C (Business to Consumer) is the correct choice because it is a fully managed identity service designed specifically for customer-facing applications. It supports social identity providers (Microsoft, Google, Facebook) via OAuth 2.0 and OpenID Connect, allows local account creation, and provides extensive custom branding capabilities through customizable user flows and page layouts.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID External Identities (which includes B2B collaboration) with B2C, but External Identities is for business partner access to internal apps, not for building a consumer-facing identity system with social logins and local accounts.

How to eliminate wrong answers

Option B (Microsoft Entra ID External Identities) is wrong because it is primarily designed for B2B scenarios, allowing external business partners to sign in with their own corporate identities, not for consumer social logins or local account creation. Option C (Microsoft Entra ID B2B collaboration) is wrong because it focuses on inviting external business users from other organizations to access internal resources, not on building a customer-facing sign-in experience with social providers. Option D (Microsoft Entra ID Application Proxy) is wrong because it is a reverse proxy service for publishing on-premises web applications to external users, not an identity provider for authentication or sign-in.

291
Multi-Selecthard

Your organization uses Azure Monitor Logs to analyze application performance. You need to create a custom log query that calculates the 95th percentile of response times for a web app over the last 24 hours. Which THREE KQL functions should you use? (Choose three.)

Select 3 answers
A.percentile
B.summarize
C.project
D.sort
E.where
AnswersA, B, E

The percentile function computes the 95th percentile of a numeric column, such as response time, over the queried set. Combined with a time filter and a summarise operator, it satisfies the requirement to calculate p95 response times across the last 24 hours.

Why this answer

Option A, percentile, is correct because it is the KQL aggregation function that computes the 95th percentile value of a numeric column such as response time. Option B, summarize, is correct because percentile must be invoked inside a summarize operator to group and aggregate the data over the desired window. Option E, where, is correct because it filters the dataset to the last 24 hours (for example, where TimeGenerated > ago(24h)) before aggregation.

Option C, project, is not required since it only selects or renames columns and does not perform percentile calculation. Option D, sort, is not required because ordering rows does not contribute to computing a percentile aggregate.

Exam trap

The trap here is that candidates often confuse `project` or `sort` with filtering or aggregation functions, mistakenly thinking they can help narrow the data or compute percentiles, when in fact only `where`, `summarize`, and `percentile` perform the required operations.

292
MCQmedium

A company runs SQL Server on Azure VMs using SQL Server Standard Edition. They need a disaster recovery solution that replicates the database to a secondary Azure region with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. They cannot use Always On Availability Groups due to licensing constraints. They also need to perform non-disruptive disaster recovery drills. Which Azure service should they implement?

A.Azure Backup for SQL Server
B.Azure Site Recovery
C.SQL Server Log Shipping to an Azure VM
D.Geo-replication for Azure SQL Database
AnswerB

Azure Site Recovery continuously replicates Azure VM disks using snapshot technology and can create application-consistent recovery points for SQL Server workloads. It provides automatic failover and, crucially, non-disruptive test failover so you can validate DR readiness without touching production. With properly configured replication frequency and timeouts, ASR can achieve recovery point objectives around 15 minutes and recovery time objectives within 2 hours, meeting the stated requirement.

Why this answer

Azure Site Recovery (ASR) replicates entire SQL Server VMs (including their databases) to a secondary Azure region, supporting RPOs as low as 30 seconds and RTOs of 2 hours or less. It allows non-disruptive disaster recovery drills by performing test failovers in an isolated network without affecting the production environment. This solution avoids the licensing constraints of Always On Availability Groups and works with SQL Server Standard Edition.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (VM-level replication) with Azure Backup (file/volume-level backup) or assume that log shipping can meet the drill requirement, but ASR is the only option that provides automated, non-disruptive test failovers for IaaS SQL Server VMs.

How to eliminate wrong answers

Option A is wrong because Azure Backup for SQL Server is designed for long-term retention and point-in-time restore, not for continuous replication to a secondary region with a 15-minute RPO or for performing non-disruptive DR drills. Option C is wrong because SQL Server Log Shipping to an Azure VM requires manual failover and does not support automated, non-disruptive DR drills; it also has higher RTO and RPO variability compared to ASR. Option D is wrong because Geo-replication for Azure SQL Database applies only to Azure SQL Database (PaaS), not to SQL Server running on Azure VMs (IaaS).

293
MCQhard

Refer to the exhibit. You deploy this ARM template to create an Azure Monitor Workbook. The template deploys successfully. What will the workbook display?

A.CPU utilization averaged over 1-hour intervals.
B.CPU utilization averaged over 5-minute intervals.
C.Memory utilization over time.
D.Disk I/O utilization over time.
AnswerB

This is correct because the query references the Processor object with counter '% Processor Time' and then uses summarize avg(CounterValue) by bin(TimeGenerated, 5m). The average of that counter over each 5-minute window is exactly CPU utilization averaged over 5-minute intervals, and the render timechart visualizes those averages over time. No other object or counter is selected.

Why this answer

The ARM template configures an Azure Monitor Workbook to query the `InsightsMetrics` table for the `cpu_usage_percentage` metric, which is collected by Azure Monitor Agent (AMA) at a default granularity of 1 minute. The workbook uses the `avg` aggregation and a time grain of `5m` (5 minutes) in the query, so it displays CPU utilization averaged over 5-minute intervals. The `summarize` operator with `bin(TimeGenerated, 5m)` explicitly groups data into 5-minute buckets, making option B correct.

Exam trap

The trap here is that candidates assume the default collection interval (1 minute) determines the display granularity, but the `bin()` function in the KQL query explicitly overrides that to 5-minute averages, making option B correct instead of a 1-hour or raw interval.

How to eliminate wrong answers

Option A is wrong because the query uses `bin(TimeGenerated, 5m)` to aggregate data into 5-minute intervals, not 1-hour intervals; a 1-hour interval would require `bin(TimeGenerated, 1h)`. Option C is wrong because the query filters for `cpu_usage_percentage` (CPU metric), not memory utilization; memory would require a metric like `memory_available_bytes` or `memory_percentage`. Option D is wrong because the query targets CPU utilization, not disk I/O; disk I/O would involve metrics such as `disk_read_bytes_per_second` or `disk_write_operations_per_second`.

294
Multi-Selecteasy

Which TWO of the following are features of Azure SQL Database that help ensure high availability? (Select two.)

Select 2 answers
A.Active geo-replication
B.Long-term retention (LTR) backups
C.Automatic tuning
D.Zone-redundant availability
E.Transparent Data Encryption (TDE)
AnswersA, D

Active geo-replication is a correct answer because it replicates your database continuously to a secondary server in a different Azure region, enabling disaster recovery across regional failures. It maintains a readable secondary replica that can be promoted through failover, and you can have up to four secondaries. This directly supports high availability by ensuring data and service remain accessible if the primary region goes down. Because it provides an alternative physical location for the database, it meets the question's criteria.

Why this answer

Active geo-replication (Option A) creates readable secondary replicas of an Azure SQL Database in a paired Azure region, enabling manual or automatic failover to maintain availability during a regional outage. This feature ensures high availability by providing disaster recovery capabilities with a Recovery Point Objective (RPO) of up to 5 seconds and a Recovery Time Objective (RTO) of less than 1 hour, depending on the failover group configuration.

Exam trap

The trap here is that candidates often confuse backup features (like LTR) or security features (like TDE) with high availability mechanisms, but only replication-based solutions (geo-replication and zone-redundancy) directly address availability during failures.

295
MCQhard

A company stores terabytes of archival data that must be retained for 10 years per regulatory requirements. The data is accessed infrequently (once or twice per year) and retrieval latency of up to 5 hours is acceptable. The company wants the lowest storage cost. They also need to ensure data is encrypted at rest and immutability to prevent deletion or modification during the retention period. Which Azure storage solution should they choose?

A.Azure Blob Storage with Hot tier and lifecycle management to Archive tier with WORM policy
B.Azure Blob Storage with Cool tier and lifecycle management to Archive tier with legal hold
C.Azure Blob Storage with Archive tier and immutability policy (time-based retention)
D.Azure Files with premium tier and soft delete
AnswerC

This design places blobs directly in Archive tier, which offers the lowest storage cost of any Blob Storage tier and is specifically designed for long-lived, rarely accessed data. A time-based retention immutability policy on the container can be locked, making it WORM-compliant and preventing blobs from being deleted or overwritten for the configured 10-year period. Because the retention period is enforced automatically and expires on schedule, and because no earlier tier is used, there are no unnecessary transition costs or manual steps.

Why this answer

Azure Blob Storage's Archive tier offers the lowest storage cost for infrequently accessed data, and the immutability policy with time-based retention provides WORM (Write Once, Read Many) compliance to prevent deletion or modification for the required 10-year period. The 5-hour retrieval latency is acceptable for archival data accessed once or twice per year, and encryption at rest is automatically enabled for all Azure Blob Storage tiers.

Exam trap

The trap here is that candidates often confuse legal hold (which is indefinite and does not prevent modification) with time-based retention immutability policy, or they incorrectly choose a higher-cost tier like Hot or Cool thinking lifecycle management will reduce costs, ignoring that the Archive tier itself is the cheapest and directly meets the latency requirement.

How to eliminate wrong answers

Option A is wrong because the Hot tier is the most expensive storage tier and is unnecessary for archival data accessed once or twice per year; lifecycle management to Archive tier adds complexity but the Hot tier cost is wasted. Option B is wrong because legal hold is an indefinite retention mechanism that cannot enforce a specific 10-year retention period, and it does not prevent modification of blobs (only deletion); the Cool tier is also more expensive than Archive. Option D is wrong because Azure Files with premium tier is designed for low-latency file shares and is extremely costly for terabytes of archival data, and soft delete does not provide immutability or prevent modification.

296
Multi-Selecthard

You are designing a governance and compliance solution for a large Azure environment with multiple subscriptions. The solution must enforce tagging policies, restrict resource types, and ensure compliance with regulatory standards. Which THREE Azure services or features should you use? (Choose three.)

Select 3 answers
A.Azure Resource Graph
B.Azure Management Groups
C.Azure Cost Management
D.Azure Blueprints (or Policy Initiatives)
E.Azure Policy
AnswersB, D, E

Azure Management Groups provide a hierarchical structure above subscriptions, allowing you to organize and govern enterprise subscription fleets at scale. Policies and role-based access control assignments placed on a management group are inherited by all descendant subscriptions and resource groups, enabling consistent compliance baselining. They are fundamental for applying governance in a multi-subscription enterprise.

Why this answer

Azure Management Groups (B) are essential for organizing subscriptions hierarchically, enabling the application of governance policies and compliance controls at scale. They allow you to enforce tagging policies, restrict resource types, and ensure regulatory compliance across multiple subscriptions by inheriting Azure Policy and RBAC assignments from the root management group down to individual subscriptions.

Exam trap

The trap here is that candidates often confuse Azure Resource Graph's discovery and query capabilities with actual enforcement, but it only provides read-only resource inventory and cannot apply or enforce governance policies.

297
MCQhard

You are designing a network architecture for a multi-tier application. The front-end tier is an Azure Application Gateway that routes traffic to a web app on Azure App Service. The back-end tier is an Azure SQL Database. You need to ensure that all traffic between the Application Gateway and the web app remains within the Azure backbone network, and that the web app can only be accessed through the Application Gateway. What should you configure?

A.Use Azure Private Link for the web app and disable public access.
B.Enable Service Endpoints for the web app and configure the Application Gateway with a private IP.
C.Deploy Azure Firewall in front of the Application Gateway.
D.Use a site-to-site VPN between the App Service and Application Gateway.
AnswerB

Service Endpoints for the web app restrict inbound traffic to the front-end subnet of the Application Gateway, so only the gateway's subnet can reach the App Service over the Azure backbone, avoiding a hop through the internet. Configuring the Application Gateway with a private IP ensures the gateway itself is not publicly reachable and acts as the sole, internal ingress point. Together they satisfy the 'only via the gateway' requirement without moving the web app off its public endpoint or requiring an Azure Private Link connection.

Why this answer

Enabling Service Endpoints for the web app allows traffic from the Application Gateway to reach the App Service over the Azure backbone network, bypassing the public internet. Configuring the Application Gateway with a private IP and restricting the web app's access to only that private IP ensures the web app can only be accessed through the gateway, meeting both requirements.

Exam trap

The trap here is that candidates often confuse Service Endpoints with Private Link, assuming Private Link is required for private connectivity, but for App Service, Service Endpoints with IP restrictions are the correct and simpler solution for this scenario.

How to eliminate wrong answers

Option A is wrong because Azure Private Link for a web app (App Service) is not directly supported; Private Link is used for PaaS services like SQL Database or Storage, not for App Service. Option C is wrong because deploying Azure Firewall in front of the Application Gateway does not ensure traffic between the gateway and web app stays on the backbone; it only adds inspection and filtering, not private connectivity. Option D is wrong because a site-to-site VPN between App Service and Application Gateway is not a supported configuration; App Service does not support VPN connections, and this would not enforce backbone-only traffic.

298
MCQeasy

A startup needs a cost-effective data storage solution for its application logs. The logs are accessed infrequently but must be available for audit purposes for up to 3 years. The solution should minimize storage costs while allowing data retrieval within 24 hours when needed. Which Azure storage tier should the company recommend?

A.Azure Blob Storage Cool tier
B.Azure Blob Storage Hot tier
C.Azure Blob Storage Archive tier
D.Azure Blob Storage Premium tier
AnswerC

The Archive tier is Azure's most economical storage option for data that is rarely accessed and can tolerate a retrieval latency of up to 15 hours because the blob must be rehydrated to Hot or Cool before reading. It is ideal for long-term retention, backup archives, and compliance records, with the lowest per-GB storage price. This directly satisfies the startup's need for a cost-effective solution for infrequently accessed data.

Why this answer

The Archive tier is the most cost-effective option for data that is infrequently accessed and requires retrieval times of up to 15 hours (standard) or 24 hours (high-priority). Since the logs must be available within 24 hours and stored for up to 3 years, Archive meets both the cost and retrieval requirements, as it offers the lowest storage cost among Azure Blob Storage tiers.

Exam trap

The trap here is that candidates often confuse the Archive tier's retrieval time with the Hot or Cool tiers, assuming Archive is too slow for any audit requirement, but the 24-hour SLA for high-priority rehydration makes it suitable for this scenario.

How to eliminate wrong answers

Option A is wrong because the Cool tier is designed for data accessed less than once per month, but its storage cost is higher than Archive, and it offers near-instant retrieval, which is unnecessary given the 24-hour retrieval window. Option B is wrong because the Hot tier is optimized for frequent access (multiple times per month) and has the highest storage cost, making it unsuitable for infrequently accessed audit logs. Option D is wrong because the Premium tier is intended for low-latency, high-transaction workloads (e.g., IoT, real-time analytics) and incurs the highest cost, which is not justified for archival audit logs.

299
MCQmedium

A healthcare organization stores patient records in Azure SQL Database. They need to ensure that all read queries against the database are directed to a read-only replica to offload the primary. Which feature should you configure?

A.Elastic database queries
B.Failover groups
C.Read scale-out
D.Active geo-replication
AnswerC

Read scale-out in Azure SQL Database uses a readable secondary replica created automatically in the Premium/Business Critical or Hyperscale service tiers, and it routes sessions that specify ApplicationIntent=ReadOnly to that replica. This lets BI and reporting workloads query the secondary while transactional workloads use the primary, and read-only queries are guaranteed to see a transactionally consistent snapshot at the time of the replica's last commit. It is specifically designed to offload reads, not to provide failover or cross-region DR.

Why this answer

Read scale-out in Azure SQL Database allows you to direct read-only queries to a read-only replica, offloading the primary database. By setting the `ApplicationIntent=ReadOnly` connection string parameter, queries are automatically routed to the secondary replica, which is ideal for read-heavy workloads like patient record queries.

Exam trap

The trap here is that candidates confuse Active geo-replication (which also provides readable secondaries) with Read scale-out, but Active geo-replication requires explicit connection string changes per replica, whereas Read scale-out automatically routes read-only queries via the same logical server endpoint.

How to eliminate wrong answers

Option A is wrong because Elastic database queries are used to run distributed queries across multiple databases, not to offload reads to a read-only replica. Option B is wrong because Failover groups provide high availability and geo-replication management, but they do not automatically route read queries to a read-only replica without additional configuration. Option D is wrong because Active geo-replication creates readable secondary replicas in different regions for disaster recovery, but it does not natively support automatic read-only query routing from the primary connection string; it requires manual connection string changes.

300
MCQhard

Refer to the exhibit. This ARM template configures backup for an Azure App Service web app. The backup is scheduled daily. What is the primary limitation of this backup strategy in meeting a disaster recovery RPO of 4 hours?

A.The backup storage account is in the same region as the web app
B.The backup frequency is 1 day, resulting in an RPO of up to 24 hours
C.The retention period of 30 days is too short
D.The backup does not include the web app configuration
AnswerB

A daily backup schedule means that at any given time, the most recent recoverable point can be up to 24 hours old, so the effective RPO is 24 hours. To satisfy a 4-hour RPO, backups must be taken at least every 4 hours—for example, six scheduled backups per day—or supplemented by more frequent manual backups. Since the requirement states a maximum RPO of 4 hours, the daily frequency is the specific reason this ARM template configuration fails.

Why this answer

The backup frequency is set to 1 day, meaning the most recent backup could be up to 24 hours old. To meet a Recovery Point Objective (RPO) of 4 hours, you need backups taken at least every 4 hours. Azure App Service backup does not support sub-daily scheduling natively; you would need to use Azure Backup or custom logic to achieve a 4-hour RPO.

Exam trap

The trap here is that candidates may focus on the storage account being in the same region (a common disaster recovery concern) or the retention period, but the core issue is that the daily backup frequency cannot meet a 4-hour RPO.

How to eliminate wrong answers

Option A is wrong because the backup storage account being in the same region as the web app does not affect the RPO; it affects regional disaster recovery but not the frequency of backups. Option B is correct as explained. Option C is wrong because the retention period of 30 days is unrelated to RPO; RPO concerns how much data you could lose, not how long you keep backups.

Option D is wrong because the ARM template includes the 'siteConfig' section, which backs up the web app configuration; even if it didn't, configuration is not the primary factor for RPO.

Page 3

Page 4 of 11

Page 5

All pages