Courseiva

Microsoft Azure Solutions Architect Expert AZ-305 (AZ-305) — Questions 601–675

795 questions total · 11pages · All types, answers revealed

Page 8

Page 9 of 11

Page 10
601
MCQhard

You are designing a monitoring solution for a critical application that runs on Azure Virtual Machines. The application generates custom performance counters. You need to alert when the custom counter exceeds a threshold and trigger an Azure Automation runbook to remediate. Which two Azure services should you combine? (Select TWO.)

A.Azure Event Grid
B.Azure Monitor
C.Log Analytics
D.Azure Automation
AnswerB, D

Azure Monitor is the core Azure platform service for collecting metrics, logs, and activity data and for alerting on that telemetry. A metric alert rule in Azure Monitor continuously evaluates resource metric values (e.g., CPU percentage, request count) against a threshold and fires an action group when the condition is met, making it the correct foundation for a monitoring and alerting solution.

Why this answer

Azure Monitor is the correct choice because it collects and analyzes custom performance counters from Azure VMs, enabling metric-based alert rules. When a threshold is exceeded, Azure Monitor can trigger an action group that invokes an Azure Automation runbook, providing automated remediation. This combination directly addresses the requirement to alert on custom counters and execute a runbook in response.

Exam trap

The trap here is that candidates often confuse Log Analytics as a direct alerting and remediation service, when in fact it is a data repository that requires Azure Monitor to evaluate alerts and trigger actions via action groups.

How to eliminate wrong answers

Option A is wrong because Azure Event Grid is a pub-sub event routing service for handling discrete events (e.g., resource state changes), not for continuous metric monitoring or threshold-based alerting on custom performance counters. Option C is wrong because Log Analytics is a data storage and query platform for log and performance data; it does not natively trigger alerts or runbooks directly—it relies on Azure Monitor for alerting and action groups to invoke Automation runbooks.

602
MCQeasy

A company stores website static assets in Azure Blob Storage. The assets are updated weekly and must be available for immediate access for 30 days. After 30 days, older versions can be moved to the Cool tier to save costs but must still be accessible within seconds. They want an automated solution. What should they configure?

A.Set the access tier to Cool on the container
B.Use Azure Blob Storage lifecycle management rules
C.Manually change the access tier every 30 days
D.Use Azure Policy to enforce tier changes
AnswerB

Azure Blob Storage lifecycle management lets you define JSON rules with a filter (e.g., prefix or blob index tag) and conditions using the age in days from last modification; setting daysAfterModificationGreaterThan: 30 with a tierToCool action automatically moves qualifying blobs to Cool while leaving newer blobs in Hot. The rule is evaluated asynchronously within 24 hours, which precisely satisfies the 30-day retention requirement without manual intervention or downtime.

Why this answer

Azure Blob Storage lifecycle management rules allow you to automate tier transitions based on age or last modification time. By configuring a rule to move blobs to the Cool tier 30 days after creation, you meet the requirement for immediate access (Cool tier offers sub-second latency) while optimizing costs without manual intervention.

Exam trap

The trap here is confusing Azure Policy (which enforces configuration at resource creation) with lifecycle management (which automates transitions based on time), leading candidates to choose Policy when only lifecycle rules can schedule tier changes.

How to eliminate wrong answers

Option A is wrong because setting the access tier to Cool on the container applies to all blobs immediately, not after 30 days, and would prevent the required immediate access for the first 30 days. Option C is wrong because manually changing the access tier every 30 days is not automated and violates the requirement for an automated solution. Option D is wrong because Azure Policy can enforce compliance rules (e.g., requiring a specific tier) but cannot schedule or automate tier transitions based on age or time.

603
MCQmedium

You are an Azure administrator. The above Azure Policy definition is assigned to a subscription. A developer tries to deploy a Virtual Machine with SKU Standard_DS2_v2. What will happen?

A.The deployment is denied and an error message is returned.
B.The deployment succeeds with a warning logged.
C.The VM is created but the SKU is changed to a different series.
D.The deployment succeeds because the policy only audits.
AnswerA

The policy definition's effect is Deny, so Azure Resource Manager evaluates the VM SKU against the condition before the resource provider accepts the request. When the condition matches, the create or update call is blocked, the deployment status is Failed, and the response contains the policy violation, including the policy name and assignment ID. Because evaluation happens during the PUT request, no VM is ever created or partially provisioned.

Why this answer

The Azure Policy definition assigned to the subscription includes a 'deny' effect for VM SKUs that are not in the allowed list. Since Standard_DS2_v2 is not an allowed SKU, the deployment is denied and an error message is returned to the developer, preventing the VM from being created.

Exam trap

The trap here is that candidates often confuse the 'deny' effect with 'audit' or 'modify' effects, assuming a policy only logs non-compliance or automatically corrects the resource, rather than understanding that 'deny' actively blocks the deployment.

How to eliminate wrong answers

Option B is wrong because a policy with a 'deny' effect does not allow the deployment to succeed with a warning; it actively blocks the deployment. Option C is wrong because Azure Policy does not automatically change the SKU to a different series; it either allows or denies the deployment based on the defined effect. Option D is wrong because the policy uses a 'deny' effect, not an 'audit' effect; an audit effect would log compliance but still allow the deployment to succeed.

604
Matchingmedium

Match each Azure monitoring service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Collect, analyze, and act on telemetry

Query and analyze log data

Application performance monitoring (APM)

Personalized recommendations for best practices

Personalized alerts for service issues

Why these pairings

The correct matches are: Azure Monitor for telemetry collection, Log Analytics for log analysis, Application Insights for APM, and Azure Sentinel for security. Common confusions include swapping Azure Monitor with Application Insights or Log Analytics.

605
MCQmedium

Contoso, Ltd. is migrating a legacy on-premises application to Azure. The application uses a SQL Server database with complex queries and requires read-heavy workloads with sub-10-millisecond latency. The solution must support geo-replication for disaster recovery. Which Azure data service should you recommend?

A.Azure Cosmos DB for NoSQL
B.Azure SQL Database Business Critical
C.Azure SQL Database Hyperscale
D.Azure SQL Managed Instance Business Critical
AnswerB

Azure SQL Database Business Critical uses a premium storage and compute architecture based on Always On Availability Groups, providing multiple readable secondary replicas that can serve read-only traffic for low-latency read-heavy workloads. It also supports active geo-replication across Azure regions, giving disaster recovery and regional read access without changing the application's T-SQL code, and its fully compatible relational engine makes it the best fit for a legacy application that needs both read scaling and minimal migration risk.

Why this answer

Azure SQL Database Business Critical is correct because it uses SQL Server database engine with full T-SQL support for complex queries, provides read-heavy workloads with sub-10-millisecond latency via in-memory OLTP and local SSD storage, and supports active geo-replication for disaster recovery. This tier offers a readable secondary replica in a different Azure region, meeting both latency and geo-replication requirements.

Exam trap

The trap here is that candidates often choose Hyperscale for its scalability and geo-replication features, overlooking that its page server architecture introduces higher read latency for small, frequent queries compared to the local SSD-based Business Critical tier.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB for NoSQL does not support SQL Server T-SQL complex queries and uses a NoSQL API, making it incompatible with the existing SQL Server database. Option C is wrong because Azure SQL Database Hyperscale is optimized for large databases and high throughput but does not guarantee sub-10-millisecond latency for read-heavy workloads due to its page server architecture and potential cache misses. Option D is wrong because Azure SQL Managed Instance Business Critical supports geo-replication only via failover groups with limited read-scale capabilities, and it introduces additional management overhead compared to Azure SQL Database, which is more suitable for a simple migration of a legacy application.

606
MCQhard

You are designing a monitoring solution for an Azure function app that processes messages from Azure Service Bus. The function app is critical and must be highly available. You need to monitor for poison messages and trigger an alert when the dead-letter queue count exceeds 100. What should you use?

A.Azure Service Bus Explorer
B.Azure Monitor metric alert on the dead-letter message count
C.Azure Log Analytics workspace querying Service Bus logs
D.Azure Application Insights availability tests
AnswerB

An Azure Monitor metric alert can directly target the Service Bus namespace and use the 'Deadlettered Messages' metric (available at queue and subscription levels) to detect when messages are routed to the dead-letter queue. This alert can be configured with a threshold (e.g., a count over 100) and a frequency (e.g., every 5 minutes), and it can trigger action groups that send email, SMS, or webhook calls. Metric alerts are low-latency, simple to configure, and do not require diagnostic settings or log ingestion, making them the most direct and efficient way to monitor dead-letter counts in real time. This is the correct choice because it fulfills the requirement to alert proactively without extra layers.

Why this answer

Azure Monitor metric alerts can directly monitor the 'Dead-letter message count' metric for a Service Bus namespace or entity. When this count exceeds 100, the alert triggers, enabling automated response to poison messages without additional query overhead. This is the most efficient and native monitoring solution for real-time threshold-based alerts on Service Bus metrics.

Exam trap

The trap here is that candidates may overthink and choose Log Analytics (Option C) for its querying flexibility, but the question specifically asks for a threshold-based alert on a single metric, which is exactly what Azure Monitor metric alerts are designed for.

How to eliminate wrong answers

Option A is wrong because Azure Service Bus Explorer is a manual tool for browsing queues and dead-letter queues, not an automated monitoring or alerting mechanism. Option C is wrong because Log Analytics queries require logs to be sent to a workspace, which adds latency and cost; metric alerts are simpler and more immediate for threshold-based monitoring. Option D is wrong because Application Insights availability tests monitor HTTP endpoint availability, not Service Bus dead-letter queue metrics.

607
MCQhard

AdventureWorks is a global retailer with a cloud-native architecture. They have a microservices application deployed on Azure Kubernetes Service (AKS). Each microservice needs to store its own data. The data requirements vary: (1) Shopping cart service: key-value data with high write throughput and low latency, data can be lost if not critical; (2) Order service: transactional data with strong consistency and ACID compliance; (3) Product catalog service: semi-structured product data that supports complex queries and is globally distributed for low-latency reads. The solution must use Azure PaaS services and minimize operational overhead. You need to design the data storage for each microservice. What should you recommend?

A.Azure Cosmos DB for all three services.
B.Azure Table Storage for shopping cart, Azure SQL Database for orders, Azure Cosmos DB for product catalog.
C.Azure Cache for Redis for shopping cart, Azure SQL Database for orders, Azure Cosmos DB for product catalog.
D.Azure SQL Database for all three services.
AnswerC

This combination correctly applies the polyglot persistence pattern to match each workload's access requirements. Azure Cache for Redis is an in-memory data store with sub-millisecond latency and built-in TTL, making it ideal for a transient, write-heavy shopping cart that must survive user sessions but not act as a durable system of record. Azure SQL Database provides full ACID compliance, relational integrity, and rich indexing, which are mandatory for order processing because every order transaction must be atomic and isolated. Azure Cosmos DB's flexible document model, tunable consistency levels, and global distribution allow a product catalog to be cached at edge regions and served with low latency while accommodating evolving product attributes. Together they address latency, consistency, and scalability where each technology is strongest.

Why this answer

Azure Cache for Redis provides a high-throughput, low-latency key-value store ideal for the shopping cart service where data loss is acceptable. Azure SQL Database offers full ACID compliance and strong consistency required for transactional order data. Azure Cosmos DB supports semi-structured data with global distribution and complex querying via its SQL API, meeting the product catalog's needs while minimizing operational overhead as a fully managed PaaS service.

Exam trap

The trap here is that candidates often assume Azure Cosmos DB can handle all workloads due to its multi-model nature, overlooking that it lacks native ACID compliance for transactional data and is overkill for simple key-value stores, while also forgetting that Azure Cache for Redis is a PaaS service suitable for high-throughput, loss-tolerant scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB, while versatile, does not natively provide ACID compliance across multiple documents without using transactional batches, and its multi-model nature adds unnecessary complexity and cost for the shopping cart's simple key-value needs; it also lacks the native relational integrity required for the order service. Option B is wrong because Azure Table Storage is a NoSQL key-value store with limited throughput and no native support for high write throughput or low latency at the scale required for a shopping cart, and it does not offer the sub-millisecond latency of an in-memory cache like Redis. Option D is wrong because Azure SQL Database is a relational database that is not optimized for high-write-throughput key-value workloads like the shopping cart, and it cannot natively handle semi-structured data with complex queries or global distribution for low-latency reads as effectively as Cosmos DB.

608
MCQhard

Refer to the exhibit. You are an Azure administrator for a company that enforces a policy that no virtual networks or network security groups can be created. However, a developer reports that they successfully created a virtual network. What is the most likely reason the policy did not block the creation?

A.The policy definition contains a syntax error.
B.The policy only applies to network security groups, not virtual networks.
C.The policy was assigned to a scope that does not include the subscription or resource group where the virtual network was created.
D.The policy effect should be 'append' instead of 'deny'.
AnswerC

Azure Policy assignments are scoped to management groups, subscriptions, or resource groups, and resources are only evaluated if they fall within that chosen scope. If the virtual network was created in a subscription or resource group that is not covered by the policy assignment (or outside the management group hierarchy), the deny effect never triggers. Even a correctly defined policy with a valid scope only affects resources inside that scope; a virtual network outside it will be created without restriction.

Why this answer

Azure Policy assignments are scoped to a specific management group, subscription, or resource group. If the policy was assigned to a scope that does not include the subscription or resource group where the developer created the virtual network, the policy would not apply, and the creation would succeed. The policy definition itself may be valid, but without proper assignment scope, it cannot enforce the deny effect.

Exam trap

The trap here is that candidates may assume a policy definition automatically applies to all resources in the tenant, but Azure Policy requires explicit assignment to a scope, and without proper scope coverage, the policy has no effect.

How to eliminate wrong answers

Option A is wrong because a syntax error in the policy definition would cause the policy to fail at evaluation time, typically resulting in an error message or the policy being non-functional, but it would not allow the virtual network creation to succeed silently; the policy would either not apply or produce an error. Option B is wrong because the question states the policy enforces that 'no virtual networks or network security groups can be created,' implying the policy definition explicitly includes both resource types; if it only applied to network security groups, the developer would not have been able to create a virtual network, but the scenario says they successfully created a virtual network, which contradicts the policy's stated scope. Option D is wrong because the 'append' effect is used to add additional properties or tags to a resource during creation or update, not to block creation; to deny creation, the correct effect is 'deny', and using 'append' would not prevent the virtual network from being created.

609
MCQmedium

A multinational corporation is designing a data storage solution for its global customer data. The data must be stored in the Azure region closest to each customer to minimize latency, but all data must be accessible from a central analytics platform for reporting. The solution must also comply with data residency regulations that require customer data to remain in the country of origin. Which Azure storage solution should the company recommend?

A.Azure Cosmos DB with multi-master writes and conflict resolution
B.Azure Data Lake Storage Gen2 with geo-zone-redundant storage (GZRS)
C.Azure Blob Storage with geo-redundant storage (GRS)
D.Azure SQL Database with active geo-replication
AnswerD

Azure SQL Database active geo-replication is correct because you create a database per customer and configure a readable secondary in the region that customer requires; replication is at the database level so isolation is clean. Even though it replicates the entire database rather than individual rows, that granularity matches the per-customer isolation model. You control both the primary and secondary locations, ensuring data residency while maintaining an active failover endpoint.

Why this answer

Azure SQL Database with active geo-replication allows the creation of a primary database in a central region and readable secondary databases in other regions. This enables low-latency reads for customers by serving data from the closest secondary while respecting data residency because the primary remains in the country of origin and replicas can be limited to the same country. The central analytics platform can query the primary database for reporting.

This solution avoids the global replication that would violate residency requirements.

Exam trap

Candidates may be tempted to choose Azure Cosmos DB with multi-master writes for global distribution, but multi-master replicates data across regions, violating data residency regulations. The correct solution involves keeping data localized via per-country databases with geo-replication limited to the same country.

How to eliminate wrong answers

Option B is wrong because Azure Data Lake Storage Gen2 with GZRS provides geo-zone-redundant storage that replicates data to a secondary region, but it does not support multi-region writes or per-region data isolation for residency compliance; data is replicated as a single copy, not independently stored per country. Option C is wrong because Azure Blob Storage with GRS replicates data to a paired region, which violates data residency requirements by moving customer data out of the country of origin, and it does not offer multi-region write capabilities. Option D is wrong because Azure SQL Database with active geo-replication creates readable secondaries in other regions but only supports writes in the primary region, failing to minimize write latency for customers outside that region, and it does not inherently enforce per-country data isolation without complex sharding.

610
MCQeasy

You are designing a backup strategy for Azure virtual machines that must support application-consistent backups and be capable of restoring to a different Azure region. Which solution should you use?

A.Azure Site Recovery
B.Azure Files
C.Azure Disk Backup
D.Azure Backup
AnswerD

Azure Backup is the native backup service for Azure VMs; it installs an extension that initiates VSS on Windows (and file-consistent snapshots on Linux) to produce application-consistent recovery points. The snapshots are stored in a Recovery Services vault, which can be configured for locally redundant or geo-redundant storage, enabling cross-region restores in the paired region. Azure Backup also provides customizable retention policies, multiple scheduled backups per day, and the ability to restore the full VM, individual files, or disks. This combination of VSS-based consistency, vault storage, and policy-based retention makes it the correct choice for this VM backup strategy.

Why this answer

Azure Backup is the correct solution because it provides native support for application-consistent backups of Azure VMs using the Volume Shadow Copy Service (VSS) on Windows or file-system-consistent snapshots on Linux, and it supports Cross-Region Restore (CRR) to recover backups to a different Azure region. This meets both requirements directly without additional configuration.

Exam trap

The trap here is that candidates confuse Azure Site Recovery (disaster recovery) with Azure Backup (backup), mistakenly thinking replication for failover also provides application-consistent point-in-time backups and cross-region restore capabilities.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery is a disaster recovery solution that replicates VMs for failover, not a backup service; it does not inherently provide application-consistent backups for long-term retention or point-in-time restore. Option B is wrong because Azure Files is a managed file share service, not a backup solution for VMs; it cannot back up entire VMs or provide application-consistent snapshots of VM disks. Option C is wrong because Azure Disk Backup only protects managed disks at the disk level, not the VM level, and it does not guarantee application-consistent backups (it uses crash-consistent snapshots) nor does it support Cross-Region Restore.

611
MCQhard

Your organization has a complex Azure environment with multiple subscriptions. You need to design a governance strategy that ensures: 1) All resources must have specific tags (CostCenter, Environment, Owner). 2) Any resource without required tags must be reported to the compliance team weekly. 3) Virtual machines must not be deployed in certain regions due to data sovereignty. 4) The solution must be automated and use native Azure services. You already have an Azure Log Analytics workspace and a central automation account. What should you include in the design?

A.Use Azure Resource Graph queries to find untagged resources and export to CSV manually each week.
B.Use Azure Blueprints to define tags and region restrictions; use Azure Monitor alerts to report non-compliance.
C.Use Azure Policy with 'deny' effect for missing tags and an Azure Automation runbook to add tags weekly.
D.Use Azure Policy with 'audit' effect for missing tags and region restriction; use Azure Logic Apps triggered by a schedule to query Azure Resource Graph and email the compliance report.
AnswerD

The 'audit' effect allows resource creation but records non-compliance, making it suitable for both existing and new resources that violate tag and region rules. A scheduled Logic App can run Azure Resource Graph queries (such as selecting resources where tags is empty or location is not in the allowed list), format the result set, and send an email report. This gives an automated, auditable, and repeatable compliance reporting mechanism that scales across complex environments.

Why this answer

It uses Azure Policy with 'audit' effect to detect missing tags and region violations without blocking deployment, which satisfies the reporting requirement. Azure Logic Apps, triggered on a schedule, queries Azure Resource Graph to identify non-compliant resources and sends an email report to the compliance team weekly, fulfilling the automation and native service criteria without manual intervention.

Exam trap

The trap here is that candidates often choose 'deny' effect (Option C) thinking it enforces compliance, but the question explicitly requires reporting non-compliance, not blocking resources, making 'audit' the correct effect for this scenario.

How to eliminate wrong answers

Option A is wrong because manually exporting to CSV each week violates the 'automated' requirement and does not use native Azure services for reporting. Option B is wrong because Azure Blueprints cannot enforce runtime region restrictions or tag requirements; they only define initial resource templates, and Azure Monitor alerts are not designed to query resource compliance or generate tag-based reports. Option C is wrong because using Azure Policy with 'deny' effect would block deployment of untagged resources, but the requirement is to report non-compliance, not prevent it; additionally, an Automation runbook adding tags weekly does not address the region restriction or the weekly reporting to the compliance team.

612
MCQmedium

You are designing a network topology for a multi-tier application in Azure. The application has a web tier, an API tier, and a database tier. You need to ensure that the web tier can communicate with the API tier, and the API tier can communicate with the database tier, but the web tier cannot directly access the database tier. Which Azure networking solution should you implement?

A.Azure Firewall
B.Network Security Groups (NSGs) with service tags
C.Azure Application Security Groups (ASGs)
D.VNet peering
AnswerC

ASGs allow you to group VMs and define security rules based on application tiers, simplifying policy management.

Why this answer

Azure Application Security Groups (ASGs) let you group VMs by workload role (web, API, database) and then write NSG rules that reference those groups as source and destination, so you can allow web-to-API and API-to-database while implicitly denying web-to-database. This provides the tiered, role-based segmentation the scenario requires without managing individual IP addresses. ASGs are the purpose-built Azure construct for application-centric micro-segmentation within a VNet.

Exam trap

AZ-305 often tests whether candidates confuse ASGs (application-tier grouping for NSG rules) with service tags (Azure platform service IP ranges), leading them to pick NSGs with service tags when role-based micro-segmentation is required.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a centralized, stateful network security appliance for perimeter and east-west traffic inspection at scale; it can enforce rules but is overkill and not the simplest way to achieve intra-VNet tier isolation between specific VM groups. Option B is wrong because NSGs with service tags alone cannot express 'web tier can talk to API tier but not database tier' cleanly, since service tags represent Azure platform services, not your own workload tiers. Option D is wrong because VNet peering only connects virtual networks and does not provide any traffic filtering or tier isolation between subnets within a VNet.

613
Multi-Selecthard

A company runs an application on Azure VMs that uses Azure SQL Database. They need a disaster recovery solution that ensures the application can fail over to a secondary region with minimal data loss. The solution must include automatic failover for the database and manual failover for the VMs. Which TWO Azure services should they use? (Choose two.)

Select 2 answers
A.Azure SQL Database auto-failover groups
B.Azure Traffic Manager
C.Azure Front Door
D.Azure Site Recovery
E.Azure SQL Database active geo-replication
AnswersA, D

Auto-failover groups provide automatic, policy-driven failover for Azure SQL Database to a secondary region, with asynchronous replication giving minimal data loss. This directly satisfies the stem's requirement for automatic database failover, while VMs are handled separately by manual failover.

Why this answer

Azure SQL Database auto-failover groups (option A) are correct because they provide automatic failover of the database to a secondary region with a defined RPO/RTO, satisfying the requirement for automatic database failover with minimal data loss. Azure Site Recovery (option D) is correct because it orchestrates replication and recovery of Azure VMs to a secondary region, and it supports manual (planned/unplanned) failover, matching the requirement for manual VM failover. Azure Traffic Manager (option B) and Azure Front Door (option C) are traffic-routing and load-balancing services that can direct users to a healthy endpoint, but they do not themselves provide database failover or VM replication/recovery.

Azure SQL Database active geo-replication (option E) enables replicas and manual failover of the database, but it does not provide the automatic failover capability required, so it does not meet the scenario.

614
MCQeasy

You are designing a cloud-native application that will run on Azure Kubernetes Service (AKS). The application needs to authenticate users and manage access to resources. Which identity service should you use?

A.Microsoft Entra External ID
B.Microsoft Entra ID
C.Microsoft Account
D.Azure Active Directory Domain Services
AnswerB

Microsoft Entra ID (formerly Azure Active Directory) is the identity provider (IdP) for the entire Azure platform, authenticating users, service principals, and managed identities via OAuth 2.0, OpenID Connect, and SAML. In a cloud-native application, services such as AKS use Entra ID for RBAC and workload identity federation, allowing pods to fetch tokens without hard-coded secrets. It is the correct choice because the same tenant that defines organizational users also authorizes access to the Azure control plane and integrates with application authentication.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the correct identity service for a cloud-native application on AKS because it provides OAuth 2.0 and OpenID Connect authentication, enabling secure user sign-in and role-based access control (RBAC) for Kubernetes resources. It integrates natively with AKS to manage identities for users and service principals, supporting managed identities for Azure resources without credential management.

Exam trap

The trap here is confusing Microsoft Entra ID (the modern cloud identity provider for enterprise users) with Azure Active Directory Domain Services (a legacy domain service for on-premises-style authentication), leading candidates to pick D for AKS when only Entra ID supports the required OAuth 2.0/OIDC protocols.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra External ID is designed for external-facing scenarios like customer or partner identities, not for authenticating internal users or managing access to AKS resources. Option C is wrong because Microsoft Account is a consumer identity provider for personal accounts (e.g., Outlook, Xbox) and lacks enterprise features like RBAC, group management, and integration with AKS. Option D is wrong because Azure Active Directory Domain Services provides legacy LDAP, Kerberos, and NTLM authentication for domain-joined VMs or lift-and-shift apps, not modern OAuth/OpenID Connect flows required by cloud-native AKS applications.

615
MCQeasy

Your company has multiple Azure subscriptions. You need to ensure that all security-related logs from Azure resources are centralized in a single Log Analytics workspace for analysis. Which Azure service should you use to collect and route these logs?

A.Azure Monitor
B.Microsoft Sentinel
C.Azure Policy
D.Azure Event Hubs
AnswerC

Azure Policy provides a governance control plane that can evaluate and enforce resource configuration at scale, and the built-in 'Deploy Diagnostic Settings to Log Analytics Workspace' initiative or a custom DeployIfNotExists policy will automatically create and remediate diagnostic settings on each supported resource. You can assign that initiative to a management group containing multiple subscriptions, and policy remediation tasks will continuously bring non-compliant resources back into compliance. This makes Azure Policy the correct tool because it enforces, rather than merely observes or analyzes, the routing of resource logs to a central workspace.

Why this answer

Azure Policy is correct because it can enforce the deployment of a diagnostic setting on all Azure resources, automatically routing security-related logs (such as Activity Logs, resource logs, and audit logs) to a single Log Analytics workspace. This ensures centralized collection and analysis without manual configuration per resource, meeting the requirement for a governance-driven approach.

Exam trap

The trap here is that candidates often confuse Azure Policy with Azure Monitor or Sentinel, thinking that monitoring or SIEM tools handle log routing, when in fact Azure Policy is the governance tool that enforces the configuration to centralize logs.

How to eliminate wrong answers

Option A is wrong because Azure Monitor is the platform that collects and analyzes telemetry, but it does not itself route or enforce the collection of logs from multiple subscriptions; it relies on diagnostic settings or other services to ingest data. Option B is wrong because Microsoft Sentinel is a SIEM that uses Log Analytics as its underlying data store, but it is not the service that collects or routes logs—it consumes data already in the workspace. Option D is wrong because Azure Event Hubs is a real-time data streaming service used for high-throughput ingestion, not for centralized log storage or analysis; it would require additional configuration to forward logs to Log Analytics.

616
MCQeasy

You are designing a solution to store large binary files (videos) that are accessed infrequently but must be retained for 7 years for compliance. The solution must minimize storage costs while allowing retrieval within 24 hours. Which Azure storage tier should you use?

A.Premium tier
B.Cool tier
C.Hot tier
D.Archive tier
AnswerD

The Archive tier has the lowest per-gigabyte storage cost in Azure Blob Storage, making it the designated choice for long-term retention where data is rarely accessed. It requires rehydration to a Hot or Cool tier before reading, with a retrieval latency of up to 15 hours (typically a few hours), which is acceptable for archival scenarios. A 180-day minimum storage period and higher per-GB retrieval fees are the trade-offs, but for large binaries stored for years, the storage cost savings dominate.

Why this answer

The Archive tier is the correct choice because it is the lowest-cost storage tier for infrequently accessed data that must be retained for long periods (7 years). It allows retrieval within 24 hours via standard rehydration, meeting the compliance requirement while minimizing storage costs. The other tiers (Premium, Hot, Cool) are more expensive and designed for higher-frequency access, making them unsuitable for this cost-optimization scenario.

Exam trap

The trap here is that candidates often choose Cool tier because they see 'infrequent access' and '24-hour retrieval' and mistakenly think Archive's retrieval time is too slow, but the question explicitly allows up to 24 hours, making Archive the correct cost-optimized choice.

How to eliminate wrong answers

Option A is wrong because the Premium tier is designed for low-latency, high-frequency access (e.g., Azure Virtual Machine disks) and incurs the highest storage costs, which is unnecessary for infrequently accessed videos. Option B is wrong because the Cool tier is optimized for data accessed less than once per month but still has higher storage costs than Archive and is not the most cost-effective for 7-year retention with 24-hour retrieval. Option C is wrong because the Hot tier is intended for frequent access (multiple times per month) and has the highest storage costs among standard tiers, contradicting the goal of minimizing costs for infrequently accessed data.

617
MCQmedium

A company runs a critical application on Azure VMs in the West US region. They need to protect against a regional disaster using Azure Site Recovery. The VMs use unmanaged disks. The recovery point objective (RPO) must be 15 minutes and the recovery time objective (RTO) must be 1 hour. Additionally, they must be able to perform quarterly disaster recovery drills that do not affect the production environment. Which configuration should they use in Azure Site Recovery?

A.Set up replication with a 15-minute snapshot frequency and perform test failover for drills.
B.Use Azure Backup for VM replication and perform restore drills.
C.Configure a recovery plan with a pre-script to take a snapshot every 15 minutes.
D.Enable multi-VM consistency group with a 15-minute consistency frequency.
AnswerA

Azure Site Recovery's replication policy allows configuring a recovery point objective (RPO) of 15 minutes by setting the snapshot frequency, so you can cap data loss at 15 minutes. The built-in test failover feature launches your replicated VMs in an isolated Azure network, letting you run non-disruptive failover drills without affecting production or incurring downtime. This is the only option that directly delivers both the required RPO and a documented, low-risk drill methodology.

Why this answer

Azure Site Recovery supports replication of Azure VMs with unmanaged disks, and a 15-minute snapshot frequency meets the RPO requirement. Test failover allows quarterly disaster recovery drills without impacting the production environment, as it creates isolated copies of VMs in a separate network for validation.

Exam trap

The trap here is confusing Azure Backup (long-term backup) with Azure Site Recovery (replication for disaster recovery), as both can restore VMs but only Site Recovery supports low RPOs and non-disruptive test failovers.

How to eliminate wrong answers

Option B is wrong because Azure Backup is designed for long-term backup retention and restore, not for low-RPO replication (typically 1-2 snapshots per day) and does not support the 15-minute RPO or test failover drills without affecting production. Option C is wrong because recovery plans with pre-scripts cannot take snapshots at a fixed frequency; snapshot frequency is configured at the replication policy level, not via scripts in a recovery plan. Option D is wrong because multi-VM consistency groups ensure crash-consistent or app-consistent snapshots across multiple VMs, but they do not directly set the snapshot frequency; the consistency frequency is separate from the replication frequency, and this option does not address the drill requirement.

618
MCQhard

You are tasked with ensuring that all VMs in the subscription have Azure Hybrid Benefit enabled for Windows Server. You create the Azure Policy shown in the exhibit. However, after assignment, the compliance report shows that some D-series VMs are still non-compliant. What is the most likely cause?

A.The 'deny' effect is incorrectly configured; it should be 'audit' to show compliance.
B.The policy does not apply to existing resources; it only blocks new or updated ones.
C.The 'like' operator does not match standard D-series SKUs.
D.The policy is scoped to a management group that excludes the resource group containing the VMs.
AnswerB

Azure Policy's deny effect operates during create and update operations through the Azure Resource Manager, but it never retroactively changes or removes existing resources. When the policy is assigned, existing VMs are scanned for compliance and will show as 'Non-compliant,' yet they remain running because deny only prevents a request from succeeding. To make existing VMs compliant, you must pair the policy with a DeployIfNotExists/Modify remediation task or manually redeploy them with the approved SKU.

Why this answer

Azure Policy with the 'deny' effect only blocks new or updated resources that violate the policy; it does not automatically remediate existing non-compliant resources. The D-series VMs were likely created before the policy was assigned, so they remain non-compliant until they are redeployed or a remediation task is triggered. To enforce compliance on existing resources, you would need to use a 'deployIfNotExists' or 'modify' effect with a remediation task.

Exam trap

The trap here is that candidates often assume Azure Policy automatically applies to all resources in scope, but they overlook the fundamental difference between 'deny' (only blocks new/updated resources) and 'deployIfNotExists'/'modify' (can remediate existing resources).

How to eliminate wrong answers

Option A is wrong because changing the effect from 'deny' to 'audit' would not make existing VMs compliant; it would only change the compliance state from 'Non-compliant' to 'Non-compliant' (audit reports non-compliance without blocking). Option B is correct as explained. Option C is wrong because the 'like' operator with pattern 'Standard_D*' correctly matches all D-series SKUs (e.g., Standard_D2s_v3, Standard_D4s_v5), as the wildcard '*' matches any suffix.

Option D is wrong because if the policy were scoped to a management group that excludes the resource group, the VMs would not be evaluated at all and would not appear in the compliance report as non-compliant; they would simply be out of scope.

619
MCQhard

A SaaS application must allow external partner users to sign in with their own organization credentials while the company controls application access. What should be used?

A.Create local cloud-only accounts for every partner user
B.Share one account per partner company
C.Use Azure DNS private zones
D.Microsoft Entra External ID/B2B collaboration with Conditional Access
AnswerD

Microsoft Entra External ID/B2B collaboration is the correct architecture because partner users authenticate against their own identity provider—be it Microsoft Entra, Google, or a SAML/WS-Fed IdP—while the resource tenant issues a token and applies its own access controls. Conditional Access policies then run at sign-in for each guest, enabling MFA, session risk, and device compliance checks without suddenly locking out valid partners. This design preserves user-level auditability with access reviews and entitlement management, so a partner user's access can be individually granted and revoked. It is the Azure-native way to meet the external-partner expectation, unlike the other options.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2B) enables external partner users to sign in using their own organization's credentials (their existing Azure AD or Microsoft account) while the company retains control over application access. By combining B2B collaboration with Conditional Access policies, the company can enforce MFA, device compliance, or location-based controls on guest users without managing their identities or passwords.

Exam trap

The trap here is that candidates confuse Azure DNS private zones (a networking feature) with identity federation, or assume that creating local accounts or sharing accounts is acceptable for external collaboration, ignoring the security and manageability requirements of the scenario.

How to eliminate wrong answers

Option A is wrong because creating local cloud-only accounts for every partner user defeats the purpose of federated identity, introduces password management overhead, and violates the requirement that partners use their own credentials. Option B is wrong because sharing one account per partner company eliminates individual accountability, violates security best practices (no audit trail per user), and cannot enforce per-user Conditional Access policies. Option C is wrong because Azure DNS private zones are a networking feature for resolving custom domain names within virtual networks; they have no role in identity federation or external authentication.

620
MCQmedium

A company uses Azure Site Recovery to replicate critical Azure virtual machines (VMs) to a secondary Azure region for disaster recovery. The VMs use managed disks and are part of a multi-tier application. After a failover, the recovery VMs must be automatically placed into a specific availability set to maintain the application architecture. How should the administrator configure this in Azure Site Recovery?

A.Configure the target availability set in the VM replication settings in the Recovery Services vault
B.Create a recovery plan and add a manual step or script to move VMs to the availability set after failover
C.Convert the managed disks to unmanaged disks for replication, then specify the availability set
D.Azure Site Recovery does not support placing VMs into an availability set in the target region
AnswerA

In Azure Site Recovery, when you enable Azure-to-Azure replication for a VM with managed disks, the 'Compute and Network' settings under the replication configuration include an explicit 'Target availability set' field. Selecting the desired target availability set there causes the failed-over VM to be automatically created within that set as part of the failover process. This is the native and supported mechanism to satisfy the requirement of automatic placement in the target region, and no post-failover scripting or disk conversion is needed.

Why this answer

Azure Site Recovery (ASR) allows you to configure the target availability set directly in the replication settings for each VM. When you enable replication for a VM, under the 'Target availability set' setting, you can select an existing availability set in the target region. ASR will then automatically place the recovered VM into that availability set during failover, ensuring the multi-tier application architecture is maintained without manual intervention.

Exam trap

The trap here is that candidates may assume ASR lacks native support for availability sets and default to manual recovery plans or unnecessary disk conversions, overlooking the straightforward configuration option in the replication settings.

How to eliminate wrong answers

Option B is wrong because while recovery plans can include manual steps or scripts, this approach is inefficient and error-prone; ASR natively supports specifying the target availability set in the replication settings, eliminating the need for post-failover manual steps. Option C is wrong because converting managed disks to unmanaged disks is unnecessary and not a supported method for specifying availability sets; ASR works with managed disks and the availability set is configured independently in the replication settings. Option D is wrong because Azure Site Recovery does support placing VMs into an availability set in the target region, as demonstrated by the correct configuration in Option A.

621
MCQhard

A company needs to store sensitive customer data in Azure Blob Storage with encryption at rest using customer-managed keys (CMK) stored in a hardware security module (HSM). Which Azure service should they use to manage the keys?

A.Azure Key Vault (Premium tier)
B.Azure Information Protection
C.Azure Key Vault (Standard tier)
D.Azure Key Vault Managed HSM
AnswerD

Azure Key Vault Managed HSM is the correct service for storing sensitive customer data encryption keys because it is a fully managed, single-tenant, FIPS 140-2 Level 3 validated hardware security module. It provides HSM-backed keys suitable for customer-managed keys (CMK) used in Azure encryption at rest, ensuring keys are protected in dedicated hardware partitions inaccessible to other tenants. Managed HSM also supports more granular access control, powerful Rbac for key management, and full key lifecycle management, making it the appropriate choice for high-security and compliance-driven environments.

Why this answer

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant HSM that is FIPS 140-2 Level 3 validated. It allows you to store customer-managed encryption keys (CMKs) in a hardware security module (HSM) for Azure Storage encryption at rest, meeting the requirement for HSM-backed key storage. The Premium tier of Azure Key Vault also supports HSM-backed keys, but the question specifies 'stored in a hardware security module (HSM)', and Managed HSM provides dedicated HSM partitions with stronger isolation and compliance.

Exam trap

The trap here is that candidates often confuse the Azure Key Vault Premium tier (which supports HSM keys but in a shared multi-tenant HSM) with the dedicated HSM requirement, leading them to select Option A instead of the more appropriate Managed HSM.

How to eliminate wrong answers

Option A is wrong because Azure Key Vault (Premium tier) does support HSM-backed keys, but it is a multi-tenant service with shared HSM pools, not a dedicated HSM; the question's phrasing 'stored in a hardware security module (HSM)' implies a dedicated HSM solution, which Managed HSM provides. Option B is wrong because Azure Information Protection is a classification and labeling service for data protection, not a key management service for encryption at rest. Option C is wrong because Azure Key Vault (Standard tier) uses software-protected keys (FIPS 140-2 Level 1), not HSM-backed keys, and thus cannot meet the requirement for storing keys in an HSM.

622
MCQhard

A company is building a petabyte-scale data lake for analytics. The workload includes Apache Spark and Hive jobs that read and write large files. The storage solution must support a hierarchical namespace for efficient directory operations, POSIX-like access control lists (ACLs) for fine-grained permissions, and must be accessible via the Azure Blob Storage API for compatibility with existing tools. Furthermore, the solution should be optimized for analytics workloads with high throughput. Which Azure data service should they choose?

A.Azure Data Lake Storage Gen2
B.Azure Data Lake Storage Gen1
C.Azure Blob Storage
D.Azure Files
AnswerA

Azure Data Lake Storage Gen2 is correct because it layers a hierarchical namespace onto Blob Storage, providing POSIX ACLs, atomic directory renaming, and a Hadoop-compatible `abfs://` filesystem that Spark, Hive, and Presto can use directly. It also fully supports the Blob API and Azure SDKs, so existing tooling works unchanged, while delivering the scale, encryption, and lifecycle policies needed to run petabyte-scale analytics workloads.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with POSIX-like ACLs and is accessible via the Azure Blob Storage API. This service is specifically optimized for analytics workloads like Apache Spark and Hive, providing high throughput for petabyte-scale data lakes. The hierarchical namespace enables efficient directory operations, while the Blob Storage API ensures compatibility with existing tools.

Exam trap

The trap here is that candidates may confuse Azure Data Lake Storage Gen1 with Gen2, overlooking that Gen1 lacks Blob Storage API compatibility, or they may assume Azure Blob Storage with hierarchical namespace enabled is a separate service, but ADLS Gen2 is the specific offering that combines all required features.

How to eliminate wrong answers

Option B (Azure Data Lake Storage Gen1) is wrong because it uses its own REST API, not the Azure Blob Storage API, breaking compatibility with existing tools that rely on Blob Storage APIs. Option C (Azure Blob Storage) is wrong because it does not support a hierarchical namespace by default (only flat namespace) and lacks POSIX-like ACLs, making it unsuitable for efficient directory operations and fine-grained permissions. Option D (Azure Files) is wrong because it is designed for SMB file shares and shared file access, not for petabyte-scale analytics workloads with high throughput, and it does not support the Blob Storage API or a hierarchical namespace optimized for Spark/Hive.

623
MCQmedium

You are a solutions architect for a large healthcare organization that uses Microsoft 365 and Azure. The organization has a Microsoft Entra ID tenant with 15,000 users. The security team requires that all users use multi-factor authentication (MFA) when accessing cloud applications. Currently, only 60% of users have registered for MFA. The organization wants to enforce MFA registration for all users within 30 days. The solution must minimize user disruption and allow users to register their MFA methods during their normal work hours. The organization uses Microsoft Intune for mobile device management and has a conditional access policy that requires MFA for all cloud apps. You need to design a solution to enforce MFA registration. What should you do?

A.Modify the existing conditional access policy to require MFA for all cloud apps and block access if MFA is not registered.
B.Deploy an Intune compliance policy that requires MFA enrollment on mobile devices.
C.Configure a Microsoft Entra ID MFA registration campaign to target all users and require registration within 14 days.
D.Use Microsoft Entra ID password reset policy to force users to register MFA during password reset.
AnswerC

The Microsoft Entra ID MFA registration campaign is the purpose-built feature to drive adoption by targeting all users, setting a required registration deadline (e.g., 14 days), and gradually reminding them to register without immediately blocking access. Users can snooze or delay the prompt for a limited time, which avoids disruption while still moving the entire tenant toward MFA readiness. This campaign works alongside conditional access policies and is the recommended first step before enforcing MFA for all cloud apps.

Why this answer

A Microsoft Entra ID MFA registration campaign is specifically designed to nudge users to register for MFA with a configurable deadline (up to 14 days) without immediately blocking access. This minimizes disruption by allowing users to register during normal work hours, and it integrates with existing Conditional Access policies that require MFA for cloud apps.

Exam trap

The trap here is confusing enforcement of MFA at sign-in (Conditional Access) with the proactive registration workflow (MFA registration campaign), leading candidates to choose Option A which would cause immediate disruption instead of a phased, user-friendly registration process.

How to eliminate wrong answers

Option A is wrong because modifying the existing Conditional Access policy to block access if MFA is not registered would immediately lock out the 40% of users who haven't registered, causing massive disruption and violating the requirement to minimize user disruption. Option B is wrong because an Intune compliance policy that requires MFA enrollment on mobile devices only applies to mobile devices managed by Intune, not to all 15,000 users accessing cloud apps from any device, and it does not enforce registration within 30 days. Option D is wrong because using the Microsoft Entra ID password reset policy to force MFA registration during password reset only applies when users initiate a password reset, which is not a guaranteed event within 30 days for all users, and it does not proactively enforce registration for all users.

624
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They want to enforce that users accessing sensitive cloud applications from outside the corporate network must use multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management
D.Access Reviews
AnswerA

Conditional Access is the correct answer because it is the policy engine that evaluates sign-in signals—such as user, group, location, device compliance, and session risk—and can require MFA for every user by creating a policy targeting 'All users' with the 'Require authentication strength' or 'Require multifactor authentication' grant control. It is tightly integrated with Entra ID Protection risk signals, allowing MFA to be enforced conditionally or universally, and supports excluding emergency access accounts to avoid lockout.

Why this answer

Conditional Access is the correct feature because it allows administrators to define policies that enforce MFA based on specific conditions, such as network location (outside corporate network) and cloud app sensitivity. By configuring a Conditional Access policy targeting 'All cloud apps' or specific sensitive apps with the condition 'Locations: All trusted/untrusted networks', you can require MFA for external access. This directly meets the requirement without needing additional licenses or features beyond Entra ID Premium P2.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based MFA triggers with Conditional Access's location-based MFA, assuming Identity Protection alone can enforce MFA for external access, but Identity Protection only suggests or triggers MFA via risk policies that require Conditional Access to actually enforce the block or MFA prompt.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and remediating identity risks (e.g., leaked credentials, sign-ins from anonymous IPs) and can trigger MFA via risk-based policies, but it does not natively enforce MFA based solely on network location; it requires integration with Conditional Access for enforcement. Option C (Privileged Identity Management) is wrong because it manages just-in-time privileged role activation and approval workflows, not general user access to cloud apps or MFA enforcement. Option D (Access Reviews) is wrong because it is used for periodic recertification of group memberships and application access, not for real-time authentication enforcement like MFA.

625
MCQhard

Refer to the exhibit. A custom Azure RBAC role is defined as shown. A user assigned this role is unable to delete blobs in a container. What is the most likely reason?

A.The role is scoped to the storage account but not to the container
B.The role does not include read permission on blobs
C.The role does not include any dataActions
D.The role does not include delete permission on blobs
AnswerD

This is correct: the custom role's DataActions list only includes read and write permissions for blobs, notably omitting Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete. Without the delete action, a user assigned this role cannot delete blobs or containers. Therefore, any attempt to delete blob data will be denied, making the missing delete permission the precise reason why the role is insufficient for deletion tasks.

Why this answer

The custom RBAC role definition shown in the exhibit includes 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete' under the 'Actions' section, but this permission is a control plane action, not a data plane action. To delete blobs, the role must include the corresponding data action 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete/action' under 'DataActions'. Without it, the user lacks the necessary data plane permission to perform blob deletion, even though the control plane permission is present.

Exam trap

The trap here is that candidates see 'delete' in the Actions list and assume it covers blob deletion, missing the critical distinction between control plane and data plane permissions in Azure RBAC.

How to eliminate wrong answers

Option A is wrong because the scope of the role (storage account vs. container) does not affect the fundamental requirement for dataActions; the issue is the missing data action, not the scope. Option B is wrong because read permission on blobs (Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read) is not required to delete blobs; the delete operation only requires the delete data action. Option C is wrong because the role does include dataActions in the definition (as shown in the exhibit), but the specific delete data action is missing; the problem is not the absence of all dataActions.

626
MCQmedium

A company runs a critical web application on Azure VMs in two availability zones. They need to ensure the application remains available during a regional outage with an RPO of 5 minutes and an RTO of 15 minutes. What should they implement?

A.Azure Backup
B.Azure Traffic Manager
C.Azure Site Recovery
D.Azure Front Door
AnswerC

Azure Site Recovery is the correct service for this requirement because it provides continuous replication of Azure VMs from the primary region to a secondary region, with an RPO as low as 5 minutes and a typical RTO of 15 minutes for web workloads. It orchestrates failover and failback, enabling the application to be brought up in the secondary region with minimal data loss and downtime. Site Recovery also supports test failover to validate a DR plan without impacting production. Therefore, it meets the critical web application's replication and recovery requirements.

Why this answer

Azure Site Recovery (ASR) is the correct choice because it provides automated replication of Azure VMs from one region to another, enabling failover during a regional outage. With continuous replication, ASR can achieve an RPO of as low as 30 seconds (well within the 5-minute requirement) and, when combined with a well-tested recovery plan, can meet the 15-minute RTO by orchestrating the startup of replicated VMs in the secondary region.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (which handles full VM replication and failover) with Azure Backup (which only handles data backup and restore), or they assume that a traffic manager like Traffic Manager or Front Door alone can provide disaster recovery without the underlying compute replication.

How to eliminate wrong answers

Option A is wrong because Azure Backup is designed for long-term data retention and point-in-time restore (typically with an RPO of 12-24 hours for VM backups), not for rapid, automated failover with a 5-minute RPO and 15-minute RTO. Option B is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that distributes traffic across endpoints but does not replicate VM data or provide automated failover of compute resources; it requires the application to already be running in the secondary region. Option D is wrong because Azure Front Door is a global HTTP/HTTPS load balancer and application delivery controller that provides traffic routing and acceleration, but it does not replicate or fail over underlying VM infrastructure; it assumes the backend is already active.

627
Multi-Selecteasy

Which TWO of the following are benefits of using Azure Policy? (Choose two.)

Select 2 answers
A.Assess compliance of resources against defined policies
B.Enforce tagging conventions on resources
C.Manage access control for resources
D.Create new Azure resources based on a template
E.Automatically remediate non-compliant resources without manual intervention
AnswersA, B

Azure Policy continuously evaluates existing and newly deployed resources against policy definitions and initiatives, aggregating the results into a compliance dashboard that shows per-policy and per-resource compliance states. This assessment process covers properties like resource types, locations, and configuration settings, enabling organizations to identify drift from corporate standards even after enrollment.

Why this answer

Azure Policy is a service that enables you to create, assign, and manage policies that enforce rules and effects over your Azure resources. Option A is correct because one of its primary benefits is the ability to assess the compliance state of existing and newly deployed resources against defined policy definitions, providing a clear compliance dashboard and reports. This assessment is continuous and can be viewed at the subscription, management group, or resource group level.

Exam trap

The trap here is that candidates often confuse Azure Policy's ability to enforce rules (like tagging) with automatic remediation, but automatic remediation requires explicit configuration of the 'deployIfNotExists' or 'modify' effect and a remediation task, making it not a direct benefit of simply using Azure Policy.

628
MCQmedium

A company deploys a web application on Azure virtual machines (VMs) across multiple availability zones in the East US region. The application receives HTTPS traffic. They need to distribute incoming traffic across the VMs, offload SSL/TLS termination, and ensure that client requests from the same user session are always sent to the same backend VM (session persistence). Which Azure load balancing solution should they choose?

A.Azure Load Balancer
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a regional Layer-7 load balancer that terminates SSL and decrypts incoming HTTPS requests, enabling it to inspect HTTP headers and route based on URL paths. It natively provides cookie-based session affinity using the Application Gateway Affinity cookie, which reliably pins a client session to the same backend VM across availability zones. With additional features like URL path-based routing, WebSocket support, and optional WAF integration, it is the appropriate choice for distributing HTTPS traffic to VMs within a single region.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that supports SSL/TLS termination, cookie-based session persistence (affinity), and can distribute HTTPS traffic across VMs in multiple availability zones. These features directly match all three requirements: SSL offloading, session persistence, and cross-zone traffic distribution.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming any load balancer can handle SSL termination and session persistence, but only Layer 7 solutions like Application Gateway or Front Door provide cookie-based affinity and SSL offload.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and does not support SSL/TLS termination or application-layer session persistence; it can only maintain session affinity using source IP hashing, which is not cookie-based and less reliable for HTTPS. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not perform SSL termination or session persistence; it directs clients to regional endpoints based on DNS resolution, not per-request load balancing. Option D is wrong because Azure Front Door is a global Layer 7 service that supports SSL termination and session affinity, but it is designed for global distribution across regions, not for distributing traffic within a single region across availability zones; it adds unnecessary latency and complexity for a regional-only workload.

629
MCQmedium

A company runs multiple on-premises workloads that are critical. They need a disaster recovery solution that can replicate workloads to Azure and enable failover in the event of an on-premises outage. The solution must support non-VMware and non-Hyper-V physical servers. Which Azure service should they use?

A.Azure Backup
B.Azure Site Recovery
C.Azure Migrate
D.Azure Disaster Recovery
AnswerB

Azure Site Recovery is the correct DRaaS solution for this scenario. It performs continuous replication of on-premises VMware VMs, Hyper-V VMs, and physical servers to Azure storage, and it tracks application state so that a failover can start a replica in Azure. Site Recovery supports orchestrated failover and test failover through recovery plans that sequence application dependencies, and it provides precise RPO/RPO control. This makes it the only option that actively replicates on-premises workloads for automated disaster recovery rather than just protecting data or migrating once.

Why this answer

Azure Site Recovery (ASR) is the correct service because it provides orchestrated replication and failover for on-premises physical servers (including non-VMware, non-Hyper-V) to Azure. It supports physical-to-Azure (P2A) replication using the Mobility service installed on the source server, enabling automated failover during an outage. This directly meets the requirement for critical workload disaster recovery with failover capability.

Exam trap

The trap here is that candidates often confuse Azure Backup (data protection) with Azure Site Recovery (disaster recovery with failover), or assume that 'Azure Disaster Recovery' is a valid service name, when in fact the correct service is Azure Site Recovery.

How to eliminate wrong answers

Option A is wrong because Azure Backup is designed for backup and restore of data (files, folders, VMs, databases) to a Recovery Services vault, not for continuous replication and automated failover orchestration required for disaster recovery. Option C is wrong because Azure Migrate is a tool for assessing and migrating on-premises workloads to Azure, not for ongoing replication and failover after migration. Option D is wrong because 'Azure Disaster Recovery' is not a standalone Azure service; the correct service name is Azure Site Recovery, and this option is a distractor that does not exist as a named service.

630
MCQhard

A multinational organization is designing a Microsoft 365 deployment for 10,000 users. The organization requires that all users have a consistent experience and that desktop settings follow users across devices. The solution must also support offline access to files and automatic sync. Which Microsoft 365 service should the organization use?

A.Microsoft Entra ID
B.Microsoft Intune
C.Enterprise State Roaming
D.OneDrive for Business
AnswerD

OneDrive for Business provides a full client-side sync engine that replicates files from SharePoint Online to the local disk, enabling true offline access and background re-synchronization when connectivity returns. Its Known Folder Move feature redirects Windows known folders—Documents, Desktop, and Pictures—into OneDrive, allowing user files to roam seamlessly across multiple devices. Together with Files On-Demand, OneDrive meets both offline access and user data sync, making it the only listed option that satisfies the stated requirements.

Why this answer

OneDrive for Business is the correct choice because it provides per-user cloud storage with offline file access via Files On-Demand and automatic sync through the OneDrive sync client. It also enables desktop settings (such as desktop, documents, and pictures folders) to follow users across devices via Known Folder Move, ensuring a consistent experience. This directly meets the requirements for offline access, automatic sync, and cross-device settings roaming.

Exam trap

The trap here is confusing Enterprise State Roaming (which roams Windows settings) with OneDrive for Business (which roams files and provides offline sync), leading candidates to pick Option C when the question explicitly requires offline file access and automatic sync.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (formerly Azure AD) is an identity and access management service that handles authentication and authorization, not file sync, offline access, or desktop settings roaming. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for syncing files or roaming desktop settings. Option C is wrong because Enterprise State Roaming syncs Windows settings and application data across devices using Azure AD, but it does not provide offline file access or automatic file sync; that is a capability of OneDrive for Business.

631
Multi-Selecthard

Which TWO of the following are requirements for using Azure SQL Database auto-failover groups? (Select two.)

Select 2 answers
A.Both servers must be in the same Azure region.
B.The primary and secondary servers must be in different Azure regions.
C.The secondary server must have the same logical server name.
D.The databases must be in different elastic pools.
E.The databases must use the same service tier.
AnswersB, E

Primary and secondary servers must be in different regions to ensure geo-redundancy and disaster recovery. This is correct.

Why this answer

Option B is correct because auto-failover groups are designed for geo-replication and disaster recovery, requiring the primary and secondary logical servers to reside in different Azure regions to provide regional failover capability. Option E is correct because the databases in the failover group must be on the same service tier (and same compute tier/edition) so that the secondary can properly host the replicated databases and maintain consistent performance characteristics. Option A is incorrect because placing both servers in the same region defeats the purpose of geo-failover and is not a requirement.

Option C is incorrect because the secondary server must have a different logical server name; it is the failover group listener that provides a stable connection endpoint, not identical server names. Option D is incorrect because elastic pool membership is not a requirement for auto-failover groups; databases can be in elastic pools or single databases, and they do not need to be in different pools.

Exam trap

Candidates often mistakenly think the secondary server must have the same logical server name as the primary, but in fact it must be different. Also, the requirement for servers to be in different regions is strict; they cannot be in the same region.

632
MCQhard

Your organization has a hybrid identity solution using Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You need to design a solution that allows users to use their on-premises credentials to authenticate to cloud applications, but you want to avoid synchronizing password hashes to the cloud. Which authentication method should you choose?

A.Seamless Single Sign-On
B.Pass-through Authentication
C.Active Directory Federation Services (AD FS)
D.Password Hash Synchronization
AnswerB

Pass-through Authentication is correct because it validates the user's password directly against the on-premises Active Directory without ever storing a password hash in Azure AD. An agent on the on-premises server listens via an outbound connection to the Azure AD Service Bus; when a sign-in occurs, the cloud sends the credentials to the agent, which checks them against AD and returns a success or failure result. This design meets the explicit requirement to avoid synchronizing password hashes, while still allowing Azure AD and Microsoft 365 to authenticate users with their existing on-premises credentials.

Why this answer

Pass-through Authentication (PTA) is the correct choice because it validates users' passwords directly against on-premises Active Directory without ever storing password hashes in the cloud. This meets the requirement to avoid synchronizing password hashes while still enabling authentication to cloud applications via Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse Seamless SSO as an independent authentication method, when it is actually a convenience feature that must be paired with either PTA or PHS, and they may overlook the explicit requirement to avoid password hash synchronization.

How to eliminate wrong answers

Option A is wrong because Seamless Single Sign-On is not an authentication method; it is a feature that provides automatic sign-in when users are on domain-joined devices, but it requires either Password Hash Synchronization or Pass-through Authentication as the underlying method. Option C is wrong because Active Directory Federation Services (AD FS) can avoid password hash synchronization, but it introduces additional infrastructure complexity and is not the simplest solution that meets the requirement; the question asks for an authentication method, and PTA is more straightforward for this specific need. Option D is wrong because Password Hash Synchronization explicitly synchronizes password hashes to the cloud, which directly violates the requirement to avoid that.

633
MCQhard

A company has multiple Azure subscriptions and wants to enforce consistent network policies across all VNets. They need to ensure that all traffic going out to the internet is inspected by a central firewall. The solution must be scalable and support multiple regions. What should they implement?

A.Use Azure Virtual WAN with a secured hub and Azure Firewall Manager
B.Deploy Azure Firewall in each subscription and route traffic through it
C.Use Azure Policy to enforce route tables on each VNet
D.Create VNet peering and use a network virtual appliance in one subscription
AnswerA

Azure Virtual WAN with a secured hub consolidates all networking into a single managed backbone, and Azure Firewall Manager provides a consistent, central security policy applied across every hub in all subscriptions. This approach eliminates the need to configure per-subscription inspection, because routing and security are integrated. Firewall Manager also offers cross-subscription governance and centralized logging, making it the only option that delivers both scalable connectivity and mandatory traffic inspection at the enterprise level.

Why this answer

Azure Virtual WAN with a secured hub and Azure Firewall Manager provides a centralized, scalable solution for enforcing consistent network policies across multiple subscriptions and regions. It enables a hub-and-spoke architecture where all internet-bound traffic from VNets is routed through a central Azure Firewall for inspection, with Azure Firewall Manager offering global policy management and automated routing.

Exam trap

The trap here is that candidates often choose Option C (Azure Policy) because they confuse policy enforcement with actual traffic routing, not realizing that Azure Policy only audits or enforces configuration compliance, not dynamic traffic inspection paths.

How to eliminate wrong answers

Option B is wrong because deploying Azure Firewall in each subscription creates a decentralized, inconsistent policy enforcement model that increases management overhead and fails to provide a single point of inspection for cross-subscription traffic. Option C is wrong because Azure Policy can enforce route tables, but it cannot dynamically route all internet traffic through a central firewall across multiple regions; it only ensures compliance with static routing configurations, not the actual traffic inspection path. Option D is wrong because VNet peering and a single network virtual appliance (NVA) in one subscription is not scalable across multiple regions and does not provide centralized policy management; it also introduces a single point of failure and complex routing updates.

634
MCQhard

A company is designing a hub-spoke network topology in Azure. The hub contains a third-party network virtual appliance (NVA) for inspection. Spokes need to communicate with each other, and all inter-spoke traffic must be routed through the NVA in the hub. Which configuration should they use?

A.Set route tables on spoke subnets with a 0.0.0.0/0 route to the Internet
B.Configure Azure Firewall in the hub with forced tunneling to on-premises
C.Create user-defined routes (UDRs) in each spoke subnet that force traffic to go through the hub NVA
D.Use VNet peering with gateway transit enabled
AnswerC

The correct approach is to create user-defined routes on each spoke subnet with a route for the other spoke's address space and the next hop set to the private IP address of the hub NVA. Because VNet peering is non-transitive, spoke-to-spoke traffic will not automatically flow through the hub; the UDR overrides the system route to force that path. You must also enable IP forwarding on the NVA network interface and ensure the NVA is in a hub subnet so return traffic takes a symmetric path. This gives precise, deterministic control of inter-spoke inspection and is the standard hub-spoke design pattern.

Why this answer

User-defined routes (UDRs) allow you to explicitly override Azure's default system routes. By adding a route in each spoke subnet with the hub NVA's private IP as the next hop for inter-spoke traffic (e.g., 10.1.0.0/16 -> 10.0.0.4), all traffic between spokes is forced through the NVA for inspection. This ensures the hub-spoke topology meets the requirement without relying on Azure Firewall or Internet routing.

Exam trap

The trap here is that candidates often confuse VNet peering's built-in transitive routing (which is disabled by default) with the ability to force traffic through an NVA, mistakenly thinking peering alone or gateway transit can achieve the required inspection without explicit UDRs.

How to eliminate wrong answers

Option A is wrong because a 0.0.0.0/0 route to the Internet would send all outbound traffic to the Internet, not through the hub NVA, and would not route inter-spoke traffic correctly. Option B is wrong because Azure Firewall with forced tunneling to on-premises would route traffic to on-premises, not through the hub NVA, and does not satisfy the requirement for inter-spoke inspection within Azure. Option D is wrong because VNet peering with gateway transit enables spokes to use a VPN gateway in the hub, but it does not force inter-spoke traffic through an NVA; it only provides transitive routing via the gateway, not custom inspection.

635
MCQmedium

A company has Microsoft Entra ID Premium P2 licenses and wants to ensure that privileged roles (e.g., Global Administrator) are only activated when needed and with approval. They also need to regularly review who has access to these roles. Which combination of features should they use?

A.Privileged Identity Management (PIM) and Microsoft Entra ID Access Reviews
B.Identity Protection and Conditional Access
C.Entitlement Management and Conditional Access
D.Microsoft Entra ID Access Reviews and Identity Protection
AnswerA

PIM is the correct core service because it provides just-in-time, time-bound activation of privileged Microsoft Entra roles with approval workflows and audit trails, which directly satisfies the requirement to ensure privileged access is controlled. Access Reviews complements PIM by enabling recurring recertification of role assignments, so administrators can automatically remove or keep access based on attestation. Together they fulfill both activation governance and periodic review, making this combination the only one that fully addresses the stated requirement.

Why this answer

Privileged Identity Management (PIM) provides just-in-time (JIT) activation of privileged roles with approval workflows, meeting the requirement for activation only when needed and with approval. Microsoft Entra ID Access Reviews then enable recurring certification of role assignments, ensuring that access is regularly reviewed and stale or inappropriate assignments are removed. Together, they form the correct combination for managing and governing privileged roles.

Exam trap

The trap here is that candidates often confuse Identity Protection (risk-based detection) with PIM (role activation and governance), leading them to select options that include Identity Protection instead of PIM for privileged role management.

How to eliminate wrong answers

Option B is wrong because Identity Protection focuses on detecting and remediating identity-based risks (e.g., compromised credentials, sign-in anomalies) and Conditional Access enforces access policies based on signals; neither provides JIT activation with approval or recurring access reviews for privileged roles. Option C is wrong because Entitlement Management manages access packages and resource access for external users and groups, not specifically privileged role activation with approval; Conditional Access does not provide role activation or review capabilities. Option D is wrong because while Access Reviews are correct, Identity Protection does not offer JIT activation or approval workflows for privileged roles, leaving the core requirement unmet.

636
Multi-Selecteasy

You are designing a network architecture for a three-tier application in Azure. The web tier must be accessible from the internet. The application tier must only accept traffic from the web tier. The database tier must only accept traffic from the application tier. Which TWO Azure services should you use to enforce these network rules? (Choose two.)

Select 2 answers
A.Azure Bastion
B.Network Security Groups (NSGs)
C.Azure Application Gateway
D.Azure Front Door
E.Azure Firewall
AnswersB, C

Network Security Groups are stateful, distributed packet filters applied at a subnet or network interface (NIC) level, with rules that allow or deny traffic based on source/destination IP, port, endpoint, and protocol. For a three-tier application, you can associate a distinct NSG with each subnet—for example, the web subnet allows HTTPS from the internet or Application Gateway, the application subnet allows only a specific port from the web subnet, and the data subnet allows only the database port from the application subnet. This implements least-privilege segmentation directly within the VNet at no additional cost and without introducing a centralized appliance or extra network hop.

Why this answer

Network Security Groups (NSGs) are the correct choice because they act as a distributed, stateful firewall that can filter traffic at the subnet or NIC level using source and destination IP addresses, ports, and protocols. By applying NSGs to the subnets hosting the application and database tiers, you can create inbound rules that restrict traffic to only the preceding tier's subnet or IP range, enforcing the required east-west segmentation without introducing additional latency or cost.

Exam trap

The trap here is that candidates often choose Azure Firewall (Option E) for all network security needs, overlooking that NSGs are the native, lightweight solution for east-west traffic filtering within a virtual network, and Azure Firewall is typically reserved for centralized inspection, logging, and outbound traffic control.

637
MCQeasy

A company deploys a web application on Azure VMs within a single region. They need to distribute incoming HTTP traffic across multiple VMs, offload SSL encryption, and maintain session persistence (sticky sessions) for user sessions. Which Azure load balancing solution should they use?

A.Azure Load Balancer
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a Layer 7 reverse proxy that understands HTTP/S, enabling SSL termination at the gateway so VMs receive decrypted traffic and offload cryptographic overhead. It provides cookie-based session affinity (sticky sessions) using Application Gateway Affinity cookies, ensuring requests from the same user session reach the same VM. These capabilities map directly to the deployment's requirement for inbound web traffic distribution within a single region, making it the correct choice.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that can route HTTP/HTTPS traffic, offload SSL/TLS encryption, and support session affinity (sticky sessions) using cookies. Unlike a Layer 4 load balancer, it can inspect application-layer data, making it ideal for web applications requiring SSL termination and persistent user sessions.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support SSL offloading and sticky sessions, but only Layer 7 solutions like Application Gateway or Front Door provide these application-layer features.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot offload SSL encryption or maintain HTTP-based sticky sessions; it only distributes traffic based on IP and port. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not handle SSL offloading or session persistence at the application layer; it directs clients to endpoints based on DNS resolution. Option D is wrong because Azure Front Door is a global Layer 7 service designed for multi-region distribution and acceleration, not for intra-region load balancing with SSL offloading and sticky sessions within a single region; it adds unnecessary complexity and cost for a single-region scenario.

638
MCQhard

Your organization has a hybrid identity infrastructure using Microsoft Entra ID (formerly Azure AD) and Active Directory Domain Services (AD DS) on-premises. You plan to deploy a critical application on Azure VMs that must remain available even if the on-premises network connection fails. The application authenticates users via on-premises AD DS. You need to design an identity disaster recovery solution that works during a network outage. What should you implement?

A.Create a site-to-site VPN connection with a secondary on-premises data center.
B.Configure Azure AD Connect with password hash synchronization and enable seamless single sign-on.
C.Deploy Microsoft Entra Domain Services and join the Azure VMs to the managed domain.
D.Use Azure AD Application Proxy to publish the application and authenticate via Azure AD.
AnswerC

Microsoft Entra Domain Services provides a fully managed, Microsoft-owned Active Directory domain in the cloud that supports Kerberos, NTLM, LDAP, group policy, and domain join without any Azure-to-on-premises network dependency. User and group objects flow into the managed domain from your Azure AD tenant, which is populated from on-premises AD via Azure AD Connect, so existing domain users continue to authenticate. When you join Azure VMs to the Entra DS managed domain, the Azure VMs authenticate directly against the cloud managed domain, allowing them to keep working even if the primary data center and all on-premises domain controllers are offline.

Why this answer

Microsoft Entra Domain Services provides a managed domain that is synchronized from your on-premises AD DS via Azure AD Connect. By joining the Azure VMs to this managed domain, the application can authenticate users against the managed domain even when the on-premises network connection fails, ensuring local authentication within Azure without dependency on the on-premises AD DS.

Exam trap

The trap here is that candidates often confuse Azure AD (a cloud identity service) with a domain-joined environment; they may choose password hash synchronization (Option B) thinking it provides domain services, but it only enables cloud authentication, not a managed domain for VMs.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN to a secondary on-premises data center still relies on on-premises AD DS and does not address the requirement for availability during a network outage; if the primary connection fails, the secondary also depends on on-premises infrastructure. Option B is wrong because password hash synchronization with seamless single sign-on enables cloud authentication via Azure AD but does not provide a domain-joined environment for Azure VMs; the application requires on-premises AD DS authentication, and during an outage, Azure AD cannot authenticate against on-premises AD DS without network connectivity. Option D is wrong because Azure AD Application Proxy publishes applications for remote access and authenticates via Azure AD, but it does not provide a managed domain for Azure VMs to authenticate against on-premises AD DS during a network outage; it still requires the application to reach on-premises AD DS for authentication.

639
MCQmedium

A company has an on-premises application running on physical servers with various operating systems. They want to use Azure as a disaster recovery site with an RPO of less than 1 hour and an RTO of less than 4 hours. They need to replicate the servers to Azure and support failover and failback. Which Azure service should they use?

A.Azure Site Recovery
B.Azure Backup (MARS agent)
C.Azure Migrate
D.Azure File Sync
AnswerA

Azure Site Recovery (ASR) replicates physical servers to Azure using the Mobility service, which continuously writes data to a cache storage account and then to Azure-managed disks, achieving RPO as low as 30 seconds. It supports both crash-consistent and app-consistent snapshots for Windows and Linux, and enables orchestrated failover via recovery plans. With RTOs in hours, ASR meets the DR requirement for rapid recovery and offers failback to the original on-premises physical server or VMware VM.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback for physical servers and VMs to Azure, meeting the RPO of <1 hour and RTO of <4 hours. It supports heterogeneous operating systems on physical servers and provides continuous replication with recovery points as low as 30 seconds, enabling both planned and unplanned failover with full failback capability.

Exam trap

The trap here is that candidates confuse Azure Backup (which provides long-term archival backups) with Azure Site Recovery (which provides near-continuous replication and orchestrated failover), failing to recognize that the RPO and RTO requirements demand a replication-based DR solution, not a backup service.

How to eliminate wrong answers

Option B (Azure Backup with MARS agent) is wrong because it is designed for file/folder and system state backup with a minimum RPO of 1 day (daily backup), not sub-hourly replication, and it does not support orchestrated failover or failback of entire servers. Option C (Azure Migrate) is wrong because it is a discovery, assessment, and migration tool, not a disaster recovery service; it does not provide ongoing replication or failover/failback capabilities. Option D (Azure File Sync) is wrong because it only syncs file shares between on-premises and Azure, not entire server workloads, and lacks failover/failback orchestration for disaster recovery.

640
MCQmedium

Your company runs an on-premises application that needs to be failed over to Azure in the event of a disaster. The application uses a SQL Server database and requires an RPO of 15 minutes and an RTO of 1 hour. You plan to use Azure Site Recovery (ASR) for the VMs and Azure SQL Database for the database. Which combination of actions should you take?

A.Use ASR with 5-minute replication and configure SQL Server Log Shipping to an Azure VM.
B.Use ASR with 30-minute replication frequency and backup the SQL Server database every 15 minutes.
C.Use ASR with 15-minute replication for the VMs and configure a failover group for Azure SQL Database with active geo-replication.
D.Use ASR with 15-minute replication and restore the SQL Server database from backup.
AnswerC

ASR with 15-minute replication meets the RPO for the VMs, replicating the entire virtual machine to the secondary region with near-synchronous frequency. Azure SQL Database failover groups with active geo-replication provide automatic, database-level failover to a readable secondary in the paired region, which meets the RTO without manual intervention. This combination uses each service's native DR capability, ensuring that both the application tier and the database tier can fail over together.

Why this answer

It meets both the RPO of 15 minutes and RTO of 1 hour. Azure Site Recovery (ASR) with 15-minute replication ensures VM replication within the RPO, while Azure SQL Database failover groups with active geo-replication provide automatic, continuous data synchronization and a fast, orchestrated failover for the database, achieving the required RTO.

Exam trap

The trap here is that candidates often assume ASR can handle both VM and database replication, but ASR does not replicate SQL Server databases in a transactionally consistent manner for Azure SQL Database; a separate database-level solution like failover groups is required.

How to eliminate wrong answers

Option A is wrong because SQL Server Log Shipping to an Azure VM introduces a manual failover process and potential delays, making it difficult to achieve a 1-hour RTO, and ASR with 5-minute replication is unnecessary and not a standard configurable frequency (ASR supports 30-second, 5-minute, and 15-minute intervals, but 5-minute is not the issue; the database solution is the problem). Option B is wrong because ASR with 30-minute replication exceeds the 15-minute RPO requirement, and backing up the SQL Server database every 15 minutes does not provide a failover-ready replica, leading to potential data loss and longer recovery times. Option D is wrong because restoring the SQL Server database from backup cannot achieve a 1-hour RTO due to the time required to restore large backups, and ASR with 15-minute replication alone does not address the database failover requirement.

641
MCQeasy

A company is designing a virtual network architecture for a three-tier application (web, application, database). They want network isolation between tiers and secure access from the internet to the web tier only. Which Azure networking solution should they use?

A.Azure Virtual Network with subnets for each tier and Network Security Groups.
B.Azure Virtual Network with a single subnet and application security groups.
C.Azure Virtual Network with subnets and Azure Firewall.
D.Azure Virtual Network with subnets and a network virtual appliance (NVA).
AnswerA

This approach uses separate subnets for the web, application, and data tiers, establishing Layer-3 network boundaries within the virtual network. Network Security Groups (NSGs) are stateful, built-in filters that you associate with each subnet to enforce inbound and outbound rules, such as allowing internet traffic only to the web tier on ports 80/443 and permitting the web subnet to talk to the app subnet on a specific application port. Because NSGs are natively supported and incur no extra cost, this is the most efficient and standard method for isolating tiers and controlling east-west traffic without introducing additional appliances or routing complexity.

Why this answer

Deploying each tier in its own subnet within an Azure Virtual Network and applying Network Security Groups (NSGs) allows granular inbound/outbound rule enforcement. NSGs can restrict traffic so that only the web tier is reachable from the internet (via a public IP or Azure Load Balancer), while the application and database tiers are isolated from direct internet access and can only communicate with the adjacent tier as defined by NSG rules.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing Azure Firewall or an NVA for basic isolation, not realizing that NSGs with subnets are the native, cost-effective, and fully supported method for network segmentation within a single Azure VNet.

How to eliminate wrong answers

Option B is wrong because a single subnet with Application Security Groups (ASGs) still places all VMs in the same broadcast domain and does not provide network-level isolation between tiers; ASGs only group VMs logically for NSG rule application, but they do not prevent lateral traffic within the subnet without explicit NSG rules, and a single subnet cannot enforce separate routing or address spaces. Option C is wrong because Azure Firewall is a managed, stateful firewall service used for centralized inspection and logging across VNets or hybrid networks, but it is overkill and not the simplest solution for basic tier isolation within a single VNet; NSGs alone provide sufficient subnet-level filtering without the cost and complexity of a firewall. Option D is wrong because a Network Virtual Appliance (NVA) is typically used for advanced traffic inspection, routing, or security functions (e.g., third-party firewalls, WAN optimization) and is unnecessary for simple tier isolation; it adds operational overhead and cost when NSGs can achieve the same isolation with less complexity.

642
MCQmedium

A company runs a file server on an Azure VM in the East US region. They want to back up the file shares to Azure and be able to restore individual files if accidentally deleted. They also need to be able to restore the entire file share to a secondary region (West US) in case of a regional disaster. The solution should automatically protect the file shares and provide versioning for up to 30 days. Which Azure service and configuration should they recommend?

A.Configure Azure Backup on the Azure file share using a Recovery Services vault with geo-redundant storage (GRS). Enable cross-region restore on the vault.
B.Use Azure File Sync to sync the file share to an on-premises server, and then back up the on-premises server using Azure Backup.
C.Enable soft delete and versioning on the storage account, and configure replication to a secondary region using RA-GRS.
D.Create a scheduled Azure Automation runbook that takes snapshots of the file share every day and copy them to a storage account in West US.
AnswerA

Azure Backup for Azure Files is the native managed backup service that takes scheduled snapshots of the file share and stores recovery points in a Recovery Services vault. By selecting GRS for the vault and enabling cross-region restore, you gain the ability to restore the entire share to the paired region (East US to West US) if a regional disaster occurs. The service also supports granular item-level restore, allows you to specify backup frequency and retention, and automatically manages the snapshot lifecycle, making it the only option here that meets both backup and DR requirements.

Why this answer

Azure Backup for Azure file shares uses a Recovery Services vault and can be configured with geo-redundant storage (GRS) to replicate backup data to a paired secondary region. Enabling cross-region restore on the vault allows restoring the entire file share to the secondary region (West US) during a regional disaster. Azure Backup automatically protects the file share with scheduled backups and provides up to 30 days of retention for point-in-time restores of individual files or the entire share.

Exam trap

The trap here is that candidates often confuse storage account replication (RA-GRS) with backup and restore capabilities, thinking that replication alone provides disaster recovery restore functionality, but it does not support point-in-time file-level restore or cross-region restore of backups without Azure Backup's cross-region restore feature.

How to eliminate wrong answers

Option B is wrong because Azure File Sync is designed for hybrid sync and tiering, not for backup; it does not provide native cross-region disaster recovery or versioning for up to 30 days, and backing up an on-premises server adds unnecessary complexity and does not directly meet the requirement to restore to a secondary Azure region. Option C is wrong because soft delete and versioning on the storage account provide protection against accidental deletion and overwrites, but they do not offer a backup solution with scheduled backups, cross-region restore capability, or the ability to restore the entire file share to a secondary region in a disaster scenario; RA-GRS replication is for storage account data redundancy, not for backup restore. Option D is wrong because a scheduled Azure Automation runbook that takes snapshots and copies them to another region is a custom, non-native solution that lacks the automated backup scheduling, versioning, and cross-region restore capabilities provided by Azure Backup; it also introduces operational overhead and does not guarantee the 30-day versioning requirement.

643
MCQeasy

Your company uses Microsoft Entra ID and has recently deployed Microsoft Sentinel. You need to design a monitoring solution to detect brute-force attacks against user accounts. The solution should use built-in analytics rules where possible and must trigger an automated response to temporarily disable the affected account. What should you include in the design?

A.Use the built-in 'Brute force attack against an Entra ID account' analytics rule in Microsoft Sentinel and connect a playbook to disable the user.
B.Use Microsoft Entra Identity Protection to detect brute-force and configure a conditional access policy to block sign-ins.
C.Stream sign-in logs to Log Analytics and create a scheduled query that alerts on multiple failures, then manually disable accounts.
D.Create a custom KQL query in Microsoft Sentinel and configure an automation rule to disable the account.
AnswerA

The Microsoft Sentinel built-in analytics rule 'Brute force attack against an Entra ID account' already contains the KQL detection logic needed to identify repeated failed sign-ins and other brute-force indicators in Entra ID sign-in logs. By triggering an automation rule on the alert, you can invoke a Microsoft Sentinel playbook—an Azure Logic Apps workflow—that automatically disables the compromised user account. This provides both automated detection and automated response, satisfying the requirement to use built-in rules whenever possible.

Why this answer

Microsoft Sentinel includes a built-in analytics rule specifically for detecting brute-force attacks against Microsoft Entra ID accounts. By connecting a playbook to this rule, you can automate the response to temporarily disable the affected user account, meeting the requirement for an automated response without custom development.

Exam trap

The trap here is that candidates may confuse Microsoft Entra Identity Protection's ability to block sign-ins with the requirement to disable the user account, or they may overlook the 'use built-in analytics rules where possible' constraint and opt for a custom KQL query.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Identity Protection detects risk events like brute-force but uses Conditional Access policies to block sign-ins, not to disable user accounts; disabling accounts requires a different mechanism. Option C is wrong because it relies on manually disabling accounts, which does not meet the requirement for an automated response. Option D is wrong because it suggests creating a custom KQL query and automation rule, but the question specifies using built-in analytics rules where possible, making a custom query unnecessary and less efficient.

644
MCQeasy

A company wants to allow remote users to access an internal web application hosted on-premises without opening inbound firewall ports. They need seamless single sign-on (SSO) using Microsoft Entra ID credentials. Which Azure service should they use?

A.Microsoft Entra ID Application Proxy
B.Microsoft Entra ID B2C
C.Microsoft Entra ID Domain Services
D.Microsoft Entra ID Connect
AnswerA

Microsoft Entra ID Application Proxy is a reverse proxy that securely publishes on-premises web applications to remote users through the Microsoft Entra ID service. It uses a lightweight connector on the internal network that initiates outbound connections, eliminating the need for inbound firewall ports or VPN. This enables seamless single sign-on and integration with Conditional Access policies, making it the ideal solution for internal app access.

Why this answer

Microsoft Entra ID Application Proxy provides secure remote access to on-premises web applications without requiring inbound firewall ports. It works by establishing an outbound connection from the on-premises Application Proxy connector to the Entra ID service, then routing user traffic through that tunnel. It integrates with Entra ID for pre-authentication and supports seamless SSO using the user's existing Entra ID credentials via Kerberos constrained delegation (KCD) or header-based authentication.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Application Proxy with a VPN or DirectAccess solution, but the key differentiator is that Application Proxy requires no inbound firewall rules and uses outbound-only connectivity, which is a common exam scenario for secure remote access.

How to eliminate wrong answers

Option B (Microsoft Entra ID B2C) is wrong because it is designed for customer-facing identity management with social or local accounts, not for providing secure remote access to internal on-premises applications. Option C (Microsoft Entra ID Domain Services) is wrong because it provides managed domain services (e.g., LDAP, Kerberos) for Azure VMs but does not offer a reverse proxy or remote access capability for on-premises apps. Option D (Microsoft Entra ID Connect) is wrong because it is a synchronization tool that syncs on-premises AD objects to Entra ID; it does not provide any application proxy or remote access functionality.

645
MCQmedium

You are designing a backup strategy for Azure VMs that host a file server. The backup must support daily backups with a retention of 30 days, and the ability to restore individual files quickly. The solution must minimize backup storage costs. What backup policy should you configure?

A.Use Azure Backup with daily backup, retention of 30 days, and use locally redundant storage (LRS) for backup data.
B.Use Azure Backup with daily backup, retention of 30 days, and enable instant restore snapshot for file-level recovery.
C.Use Azure Backup with daily backup, retention of 30 days, and use geo-redundant storage (GRS) for backup data.
D.Use Azure Backup with weekly backup, retention of 30 days, and use geo-redundant storage (GRS) for backup data.
AnswerB

Incorrect. While daily backups and 30-day retention are correct, this option does not specify storage redundancy. Without specifying LRS, the backup storage may default to GRS, increasing cost unnecessarily. The instant restore snapshot feature is automatically enabled and does not need to be explicitly configured.

Why this answer

Option B is correct because Azure Backup for Azure VMs uses instant restore snapshots to provide fast file-level recovery. The backup policy defines the daily backup schedule, 30-day retention, and instant restore snapshot retention. Storage redundancy (LRS/GRS) is configured at the Recovery Services vault level, not in the backup policy; to minimize costs, select LRS at the vault level separately.

Option A is incorrect because it treats LRS as part of the backup policy and does not address the file-level recovery requirement. Option C uses GRS, which increases cost unnecessarily, and option D uses weekly backups, which violates the daily backup requirement.

Exam trap

Candidates may mistakenly treat storage redundancy as part of the backup policy and choose LRS in the policy. Storage replication is set at the Recovery Services vault level, not in the backup policy. Also, file-level recovery is enabled through instant restore snapshots, so the policy must include that aspect.

To minimize costs, select LRS at the vault level separately.

How to eliminate wrong answers

Option C is wrong because geo-redundant storage (GRS) increases backup storage costs unnecessarily for a scenario that only requires local durability and does not mandate cross-region redundancy. Option D is wrong because weekly backups would result in a maximum data loss of up to 7 days, failing the daily backup requirement, and GRS adds unnecessary cost. Option B is wrong because while instant restore snapshots enable file-level recovery, they are a feature of Azure Backup that is already available and not a separate policy configuration; the question asks for a backup policy, and enabling instant restore does not minimize storage costs—it may actually increase costs due to snapshot retention.

646
Multi-Selectmedium

Which TWO actions should you take to design a monitoring solution for a multi-tier application running on Azure VMs? (Select TWO.)

Select 2 answers
A.Deploy VM Insights on each VM
B.Configure Azure Monitor Agent to collect metrics and logs from each tier
C.Create a Log Analytics workspace and connect all VMs
D.Instrument the application with Application Insights
E.Enable Azure Monitor for VMs on all VMs
AnswersB, D

Configuring the Azure Monitor Agent (AMA) is the foundational action for infrastructure monitoring because AMA collects metrics and logs from VMs in each tier and sends them to Azure Monitor Metrics and Log Analytics workspaces. Using data collection rules (DCRs), you can define exactly which counters and logs to capture per workload. This directly addresses the requirement to monitor all tiers, making it a correct primary action.

Why this answer

Azure Monitor Agent is the modern, unified agent that collects metrics and logs from Azure VMs and sends them to Azure Monitor, Log Analytics workspaces, and other destinations. For a multi-tier application, collecting data from each tier is essential for end-to-end monitoring. Option D is correct because Application Insights provides application performance monitoring (APM) by instrumenting the application code itself, capturing telemetry like request rates, dependency calls, and exceptions, which is critical for understanding the behavior of a multi-tier application.

Exam trap

The trap here is that candidates confuse 'VM Insights' (a feature that provides visualizations and dependency mapping) with the underlying agent installation, or they think that creating a Log Analytics workspace is a primary monitoring action rather than a prerequisite, leading them to select options A, C, or E instead of the correct combination of agent-based collection and application instrumentation.

647
MCQmedium

A company runs a critical application on Azure virtual machines in the West US region. They need a disaster recovery solution that replicates VMs to East US with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. They also need to perform non-disruptive disaster recovery drills. Which Azure service should they use?

A.Azure Backup
B.Azure Site Recovery
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Site Recovery directly addresses the DR requirement by continuously replicating Azure VMs to a secondary Azure region, with a recovery point objective (RPO) as low as 15 minutes for supported disk types. It enables orchestrated failover and failback, and crucially allows test failover using isolated networks so you can validate end-to-end recovery without impacting production or incurring downtime. Recovery plans can sequence multi-tier application startup, making it the correct choice for this critical workload.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs between regions. It supports RPOs as low as 15 minutes (continuous replication with crash-consistent or app-consistent snapshots) and RTOs of 2 hours or less, and it enables non-disruptive disaster recovery drills via test failover that isolates replicated VMs in a separate virtual network without impacting production.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for backup/restore with longer RPOs) with Azure Site Recovery (which is for replication and failover with low RPO/RTO), or they mistakenly think a traffic-routing service like Traffic Manager or Front Door can provide disaster recovery replication without actually moving or copying VM data.

How to eliminate wrong answers

Option A is wrong because Azure Backup is designed for long-term retention and point-in-time restore of VM data (typically with a minimum RPO of 1 hour for disk snapshots), not for continuous replication with sub-15-minute RPO or orchestrated failover with a 2-hour RTO; it also does not support non-disruptive drills. Option C is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes incoming traffic to healthy endpoints, but it does not replicate VM data or provide any disaster recovery replication, RPO/RTO guarantees, or drill capabilities. Option D is wrong because Azure Front Door is a global application delivery network with HTTP/S load balancing and acceleration, but it does not handle VM-level replication, failover orchestration, or recovery point objectives; it only redirects traffic based on backend health.

648
MCQmedium

You are designing a backup strategy for Azure Files shares that contain critical data. The backup must support snapshot-based backups and allow restoration to a specific point in time. The solution must also protect against accidental deletion. What should you use?

A.Use Azure File Sync with cloud tiering.
B.Use Azure Storage account geo-redundant storage (GRS) with versioning.
C.Use Azure Backup for Azure Files with soft delete enabled.
D.Use Azure Backup for Azure Files without soft delete.
AnswerC

Azure Backup for Azure Files is the correct solution because it provides fully managed, snapshot-based backups with granular recovery points for point-in-time restore. Enabling soft delete ensures that when a file share is deleted, the share and its snapshots are retained for the configured retention period (1 to 365 days), preventing accidental loss and allowing recovery. This combination delivers both backup and accidental-deletion protection.

Why this answer

Azure Backup for Azure Files provides snapshot-based backups that support point-in-time restoration, and when combined with soft delete, it protects against accidental deletion by retaining deleted data for a configurable retention period (default 14 days). This meets all stated requirements: snapshot backups, point-in-time restore, and deletion protection.

Exam trap

The trap here is that candidates may confuse Azure File Sync with Azure Backup, or assume that storage replication (GRS) alone provides backup and deletion protection, when in fact Azure Files requires explicit backup configuration and soft delete for those capabilities.

How to eliminate wrong answers

Option A is wrong because Azure File Sync with cloud tiering is a synchronization and caching solution, not a backup service; it does not provide snapshot-based backups or point-in-time restoration. Option B is wrong because geo-redundant storage (GRS) with versioning provides replication and object versioning for blobs, but Azure Files does not support versioning—only blob storage does; GRS alone does not offer snapshot-based backups or point-in-time restore for file shares. Option D is wrong because Azure Backup for Azure Files without soft delete fails to protect against accidental deletion, which is a stated requirement; soft delete is essential for that protection.

649
MCQhard

A global company is deploying a microservices application on AKS clusters in multiple Azure regions. They need to provide a single endpoint for users worldwide with SSL offloading, web application firewall, and URL path-based routing to the nearest healthy AKS cluster. They also need global load balancing with automatic failover. Which Azure service should they use?

A.Azure Front Door
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Load Balancer
AnswerA

Azure Front Door is a global application delivery controller that operates at Layer 7, using Anycast to terminate connections at the nearest point of presence. It directly satisfies the multi-region AKS requirement by performing SSL offloading, applying a web application firewall, and routing requests to different AKS clusters based on URL paths. Its global health probes and failover are distinct from DNS-based or regional approaches, making it the only listed service that can steer user traffic across the globe while preserving HTTP semantics.

Why this answer

Azure Front Door is the correct choice because it provides global HTTP/HTTPS load balancing with SSL offloading, web application firewall (WAF) integration, and URL path-based routing. It uses Anycast-based routing to direct users to the nearest healthy AKS cluster, ensuring low latency and automatic failover across regions.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Azure Traffic Manager, but Traffic Manager only provides DNS-level routing without application-layer features like SSL offloading, WAF, or path-based routing.

How to eliminate wrong answers

Option B is wrong because Azure Application Gateway is a regional load balancer that operates within a single Azure region and cannot provide global load balancing or cross-region failover. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not support SSL offloading, WAF, or URL path-based routing at the application layer. Option D is wrong because Azure Load Balancer is a Layer 4 (TCP/UDP) load balancer that operates regionally and lacks application-layer features like SSL termination, WAF, and path-based routing.

650
MCQhard

A multinational corporation needs to design a global DNS solution for Azure resources. They require automatic failover across Azure regions and low-latency responses based on the client's geographic location. The solution must also support custom domains without exposing the underlying Azure public IP addresses. Which combination of Azure services should they use?

A.Azure Traffic Manager with geographic routing and Azure Front Door
B.Azure Application Gateway with Azure Front Door
C.Azure DNS with Azure Traffic Manager
D.Azure Traffic Manager with priority routing and Azure Application Gateway
AnswerA

Azure Traffic Manager with geographic routing is the correct DNS-level mechanism for a multinational workload because it uses the client’s source DNS resolver location to select the optimal regional endpoint, enabling true global load balancing. Azure Front Door complements it by terminating HTTPS at the edge, providing the custom domain and managed TLS certificates, and allowing the origin to be exposed privately via private link, which is essential when user-facing traffic can’t hit the endpoint directly. Together they deliver global DNS failover plus application-layer routing and security, which is why this is the required combination.

Why this answer

Azure Front Door provides global load balancing with automatic failover across regions and low-latency routing based on the client's geographic location via its anycast protocol. Azure Traffic Manager with geographic routing complements this by directing traffic to specific regional endpoints based on the client's origin, and together they support custom domains while hiding the underlying Azure public IP addresses through Front Door's frontend endpoint.

Exam trap

The trap here is confusing regional services like Application Gateway with global services like Front Door, and assuming that DNS-based routing alone (Traffic Manager) can achieve low-latency geographic routing without the anycast edge network of Front Door.

How to eliminate wrong answers

Option B is wrong because Azure Application Gateway is a regional layer-7 load balancer that does not provide global failover or geographic routing across Azure regions. Option C is wrong because Azure DNS only provides name resolution and does not perform traffic routing, failover, or hide public IP addresses. Option D is wrong because Azure Traffic Manager with priority routing does not support geographic-based low-latency responses, and Azure Application Gateway is regional, not global.

651
MCQmedium

Your organization uses Microsoft Sentinel for security monitoring. You need to create a rule that triggers an incident when a user from a specific IP address performs more than 10 failed sign-ins within an hour. Which rule type should you use?

A.Microsoft Security rule
B.Scheduled query rule
C.Anomaly detection rule
D.Fusion rule
AnswerB

A scheduled query rule is the correct choice because it periodically executes a KQL query over a defined lookback window and evaluates the results against an alert condition. You can aggregate events with operators such as 'summarize count() by User, bin(TimeGenerated, 5m)' and design the query to return rows only when that aggregated count exceeds the desired threshold, such as five failed logins. The rule's configurable run frequency, lookback period, and alert settings make it the standard Sentinel mechanism for deterministic event-count threshold detection.

Why this answer

A scheduled query rule is the correct choice because it allows you to define a custom KQL query that counts failed sign-in events from a specific IP address over a 1-hour window and triggers an incident when the count exceeds 10. This rule type is designed for user-defined detection logic based on log data, such as SigninLogs, and supports aggregation and threshold-based alerting.

Exam trap

The trap here is that candidates confuse scheduled query rules with anomaly detection rules, assuming any threshold-based alert is 'anomaly detection,' but anomaly detection requires baseline learning and cannot enforce a static numeric threshold like 10.

How to eliminate wrong answers

Option A is wrong because Microsoft Security rules are prebuilt templates from Microsoft security products (e.g., Microsoft Defender for Cloud) and cannot be customized to count specific IP addresses or set custom thresholds like 10 failed sign-ins per hour. Option C is wrong because anomaly detection rules use machine learning to identify unusual patterns in baseline behavior, not fixed thresholds on a specific IP address. Option D is wrong because Fusion rules correlate multiple low-fidelity alerts from different sources to detect advanced multi-stage attacks, not single-condition threshold-based triggers.

652
Multi-Selecteasy

A company is designing a storage solution for its backup data. The backups must be stored for 10 years for compliance reasons. The solution should minimize storage costs while ensuring data durability. Which two Azure services should the company consider? (Choose two.)

Select 2 answers
A.Azure Blob Storage Archive tier
B.Azure Files with snapshots
C.Azure NetApp Files with cross-region replication
D.Azure Disk Storage with incremental snapshots
E.Azure Backup with long-term retention policy
AnswersA, E

Azure Blob Storage Archive tier is the correct choice because it offers the lowest storage cost per GiB for data that is rarely accessed, such as backups retained for decades. Archive tier supports long-term retention with configurable lifecycle policies, and it provides secure storage with encryption and optional immutability to meet compliance. While data retrieval may require hours of rehydration, for infrequent backup restores this trade-off is acceptable.

Why this answer

Azure Blob Storage Archive tier is correct because it provides the lowest-cost storage for data that is rarely accessed, with a 10-year retention period meeting compliance requirements. It offers 11 nines of durability (99.999999999%) by storing multiple copies across Azure regions, ensuring data integrity over the long term.

Exam trap

The trap here is that candidates often confuse Azure Backup with long-term retention (which is a service that manages backup lifecycle and can use Archive tier) with other Azure storage services that are not designed for cost-effective, long-term archival, such as Azure Files or Azure NetApp Files.

653
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to enable users to reset their own passwords without contacting the help desk. They also want to enforce multi-factor authentication (MFA) during the password reset process. Which Microsoft Entra ID feature should they enable?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Self-Service Password Reset (SSPR)
D.Microsoft Entra ID Conditional Access
AnswerC

SSPR is the Microsoft Entra ID feature purpose-built for end users to unlock or reset their own passwords without helpdesk intervention, and it can enforce multi-factor authentication as part of the reset flow. When combined with the combined registration experience, users register their MFA methods once, and administrators can require two or more verification methods in the SSPR policy, meaning the user must prove possession of multiple factors before the password is changed. This directly satisfies both the need for self-service reset and the need to enforce MFA during that reset, because the verification gate is an integral part of SSPR itself.

Why this answer

Microsoft Entra ID Self-Service Password Reset (SSPR) enables users to reset their own passwords without help desk intervention. When combined with Microsoft Entra ID Conditional Access, SSPR can enforce multi-factor authentication (MFA) during the password reset process, meeting both requirements.

Exam trap

The trap here is that candidates often confuse Conditional Access as the sole solution for password reset, but Conditional Access only enforces policies on top of SSPR; without SSPR enabled, users cannot reset their own passwords at all.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Identity Protection is a risk-based detection and remediation tool that identifies potential vulnerabilities and suspicious activities, but it does not directly enable self-service password reset or enforce MFA during password reset. Option B is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not self-service password reset or MFA enforcement for end users. Option D is wrong because Microsoft Entra ID Conditional Access is a policy engine that enforces access controls (like MFA) based on conditions, but it does not provide the self-service password reset capability itself; it can only be used to secure the SSPR process.

654
MCQmedium

A company manages a fleet of millions of IoT devices that send telemetry data every minute. The data must be stored for 10 years to meet compliance requirements. For the first 30 days, data is accessed frequently for real-time dashboards and alerting. After 30 days, data is only accessed occasionally for historical analysis and reporting. The solution must be cost-effective and support high ingestion rates. Which Azure service should the company use to store and query this data?

A.Azure Blob Storage with Azure Data Lake Storage Gen2
B.Azure Data Explorer
C.Azure SQL Database
D.Azure Cosmos DB with SQL API
AnswerB

Azure Data Explorer is the only service here built specifically for high-fidelity time-series analytics: its columnar engine ingests millions of events per second, automatically creates inverted indexes, and uses a hot/cold cache with data tiering to balance performance and cost. KQL natively supports time-based operations such as bin(), summarize, anomaly detection, and lag/lead calculations, which can run on both streaming and historical data. This makes it the appropriate choice for a fleet of millions of devices where real-time visibility and long-term retention are required.

Why this answer

Azure Data Explorer (ADX) is designed for high-ingestion, time-series telemetry data and supports real-time dashboards and alerting on fresh data, while also providing cost-effective long-term storage for historical queries. Its columnar storage and indexing enable fast analytics on billions of records, making it ideal for IoT scenarios with millions of devices sending data every minute and a 10-year retention requirement.

Exam trap

The trap here is that candidates often choose Azure Blob Storage or Cosmos DB because they associate them with 'storage' or 'IoT,' but they fail to recognize that Azure Data Explorer is the only service purpose-built for high-velocity time-series analytics with built-in hot/cold tiering and native support for real-time alerting and long-term retention at scale.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with Azure Data Lake Storage Gen2 is optimized for batch analytics and large file storage, not for real-time querying and alerting on high-velocity telemetry data; it lacks native time-series indexing and low-latency query capabilities. Option C is wrong because Azure SQL Database is a relational OLTP system that cannot cost-effectively handle the ingestion rate of millions of events per minute or the 10-year retention of massive telemetry volumes without significant performance degradation and high costs. Option D is wrong because Azure Cosmos DB with SQL API is a globally distributed NoSQL database designed for low-latency reads/writes on operational data, but it is not optimized for high-throughput time-series ingestion and analytical queries over long retention periods, and its cost would be prohibitive for storing billions of telemetry records for 10 years.

655
MCQmedium

A multinational company uses Microsoft Entra ID for identity. They need to grant external partners access to specific SharePoint Online sites. The access must be time-limited and require approval from a resource owner. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Entitlement Management.
B.Microsoft Entra ID B2C.
C.Microsoft Entra ID Conditional Access.
D.Microsoft Entra ID Identity Protection.
AnswerA

Entitlement Management is an identity governance feature that lets administrators create access packages containing SharePoint Online sites, Teams, and other resources, and publish them to internal or external users. Policies within an access package define who can request access, who must approve, and when the access expires, enabling time-limited collaboration. For external partners, it supports Connected Organizations and identity providers including Google and Microsoft accounts, automatically removing access when the policy ends. This directly provides the request/approval/expiration workflow needed for the scenario.

Why this answer

Microsoft Entra ID Entitlement Management (A) is the correct feature because it enables organizations to manage external partner access to resources like SharePoint Online sites through access packages. These access packages can enforce time-limited access and require approval from designated resource owners, directly meeting the scenario's requirements.

Exam trap

The trap here is that candidates may confuse Entitlement Management (which handles external user access governance) with B2C (which is for customer-facing apps) or Conditional Access (which is a security policy layer, not a provisioning workflow).

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID B2C (Business-to-Consumer) is designed for customer-facing identity management with social logins, not for granting external partners access to internal resources like SharePoint sites. Option C is wrong because Microsoft Entra ID Conditional Access enforces policies based on signals like location or device state, but it does not provide time-limited access or approval workflows for external partner access. Option D is wrong because Microsoft Entra ID Identity Protection focuses on detecting and remediating identity risks (e.g., leaked credentials), not on managing external user access with time limits and approvals.

656
MCQeasy

You are designing a monitoring solution for Azure SQL Database. The requirement is to track query performance metrics such as CPU usage, data IO, and wait statistics over time. You need to identify performance bottlenecks and provide historical data for analysis. Which Azure service should you use?

A.Azure Monitor Metrics for Azure SQL Database
B.Azure SQL Analytics (preview) in Azure Monitor
C.Azure SQL Database Intelligent Insights
D.Query Performance Insight for Azure SQL Database
AnswerD

Query Performance Insight for Azure SQL Database is the correct choice because it is the native Azure portal feature designed specifically to surface query-level performance data, including execution count, CPU time, duration, and logical reads per query over a customizable time window. It also displays wait statistics tied to query tuning recommendations, allowing you to pinpoint poorly performing SQL statements and observe their historical trends without requiring additional configuration beyond the database's query store.

Why this answer

Query Performance Insight for Azure SQL Database is the correct choice because it provides built-in, intelligent analysis of top queries by CPU, data IO, and wait statistics over time, enabling you to identify performance bottlenecks and review historical data. It is specifically designed for Azure SQL Database and offers a customizable time range for trend analysis, directly meeting the requirement to track query performance metrics and analyze historical data.

Exam trap

The trap here is that candidates often confuse Azure SQL Analytics (a broader monitoring solution) with Query Performance Insight (a focused query-level tool), or they assume Azure Monitor Metrics provides query-level details when it only offers aggregate resource metrics.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Metrics for Azure SQL Database provides platform-level metrics (e.g., DTU/CPU percentage, storage) but does not offer per-query performance details like wait statistics or historical query-level analysis. Option B is wrong because Azure SQL Analytics (preview) in Azure Monitor is a broader monitoring solution that aggregates metrics and logs across multiple Azure SQL databases, but it does not provide the granular, query-specific historical performance data and wait statistics that Query Performance Insight offers. Option C is wrong because Azure SQL Database Intelligent Insights uses built-in intelligence to automatically detect and alert on performance issues, but it does not provide the detailed, customizable historical query performance metrics (CPU, IO, wait stats) that are needed for manual bottleneck analysis.

657
MCQeasy

A company needs to implement a hybrid identity solution that allows users to access both on-premises applications and Microsoft 365 using a single identity. The company has on-premises Active Directory Domain Services (AD DS). They want to synchronize identities to the cloud while also enabling password writeback for self-service password reset. Which Azure service should they use?

A.Microsoft Entra ID
B.Microsoft Entra Connect Health
C.Microsoft Entra Connect
D.Microsoft Entra Domain Services
AnswerC

Microsoft Entra Connect is the correct on-premises synchronization tool that bridges on-premises Active Directory and Microsoft Entra ID, performing password hash sync, pass-through authentication, and, when properly configured with the required Microsoft Entra ID Premium license, password writeback. When a user resets a password in the cloud, Entra Connect receives that reset securely, encrypts it, and updates the on-premises AD password, ensuring the new credential works immediately for both on-premises and cloud authentication.

Why this answer

Microsoft Entra Connect (formerly Azure AD Connect) is the correct tool for synchronizing on-premises AD DS identities to Microsoft Entra ID while enabling password writeback for self-service password reset (SSPR). It supports the required hybrid identity scenarios, including password hash synchronization or pass-through authentication, and can be configured to write passwords back to on-premises AD DS via the SSPR writeback feature.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect (the sync tool) with Microsoft Entra ID (the cloud directory) or Microsoft Entra Domain Services (a managed domain service), leading them to select the wrong service for hybrid identity synchronization and password writeback.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is the cloud-based identity and access management service itself, not the synchronization tool; it does not directly perform identity sync or password writeback. Option B is wrong because Microsoft Entra Connect Health provides monitoring and diagnostics for the sync infrastructure but does not perform identity synchronization or password writeback. Option D is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., LDAP, Kerberos) for cloud VMs, not identity synchronization or password writeback to on-premises AD DS.

658
MCQhard

Refer to the exhibit. You are a security administrator reviewing a custom Azure Policy assignment. The policy definition with ID 'abc123' is an initiative containing two policies: one that audits storage accounts with blob public access enabled and one that deploys a diagnostic setting for network security groups. The scope includes a production resource group. However, the compliance state shows 'Non-compliant' for several resources. What is the most likely reason for the non-compliance?

A.The scope is incorrectly targeting the resource group, missing the subscription.
B.The audit policy is preventing the creation of storage accounts with public access.
C.The enforcement mode is set to 'Default' which disables policy evaluation.
D.The diagnostic setting deployment policy requires a remediation task to bring non-compliant resources into compliance.
AnswerD

A DeployIfNotExists policy is designed to deploy a resource when the policy condition is met, but it does not automatically apply the deployment during evaluation. After the evaluation cycle, the policy enters a non-compliant state and a remediation task must be run to deploy the diagnostic setting to the storage account. Without that remediation task, even though the policy is correctly assigned and enforced, the configuration remains missing. Hence, the storage account lacks the diagnostic setting because the needed remediation task has not been executed.

Why this answer

The policy that deploys a diagnostic setting for network security groups is a 'DeployIfNotExists' (DINE) policy. DINE policies do not automatically remediate existing non-compliant resources; they require a remediation task to be created and run, which will deploy the diagnostic settings to bring the resources into compliance. The audit-only policy for storage accounts does not require remediation, but the DINE policy's non-compliance indicates that the diagnostic settings are missing and need to be deployed via a remediation task.

Exam trap

The trap here is that candidates often assume all policy effects (like 'DeployIfNotExists') automatically remediate non-compliant resources, but in reality, they only mark non-compliance and require a separate remediation task to deploy the required configuration.

How to eliminate wrong answers

Option A is wrong because the scope includes the production resource group, which is a valid scope for policy assignment; missing the subscription is not an issue as policies can be assigned at the management group, subscription, or resource group level. Option B is wrong because an audit policy only evaluates and reports compliance; it does not prevent creation or enforce any action, so it cannot be the reason for non-compliance. Option C is wrong because the 'Default' enforcement mode does not disable policy evaluation; it enables evaluation and enforcement, whereas 'Disabled' mode would disable evaluation.

659
Multi-Selecthard

Which THREE of the following are best practices for designing a business continuity solution using Azure Backup? (Choose three.)

Select 3 answers
A.Enable soft delete to protect backup data from accidental deletion
B.Configure a single backup policy for all resources to simplify management
C.Use geo-redundant storage (GRS) for the backup data to protect against regional disasters
D.Use separate Recovery Services vaults for different workloads or regions
E.Grant all users 'Backup Contributor' role to ensure backups are taken
AnswersA, C, D

Soft delete in Azure Backup adds a safety net by retaining deleted backup data for a default retention period (14 days) after deletion, allowing recovery of backup items that were accidentally or maliciously removed. This prevents permanent data loss when a Recovery Services vault or a backup item is deleted, because the protected data and its restore points remain available for restoration within the soft-delete window. Administrators must explicitly re-enable soft delete if disabled, and re-deleting an item after the soft-delete period results in permanent deletion.

Why this answer

Enabling soft delete in Azure Backup protects backup data from accidental or malicious deletion by retaining deleted backup data for an additional 14 days (configurable up to 14 days). This ensures that even if a backup item is deleted, the data remains recoverable, which is a critical best practice for business continuity.

Exam trap

The trap here is that candidates often confuse 'simplifying management' (Option B) with best practice, but Azure Backup requires workload-specific policies to meet RPO/RTO requirements, and a single policy would either over-retain or under-protect different resources.

660
MCQmedium

A company is designing a data storage solution for a global e-commerce platform that requires low-latency access to product catalog data from multiple Azure regions. The data is read-heavy, with occasional updates. Which Azure data store should they recommend?

A.Azure Cache for Redis
B.Azure Blob Storage
C.Azure SQL Database
D.Azure Cosmos DB
AnswerD

Azure Cosmos DB is a fully managed NoSQL database purpose-built for turnkey global distribution with multi-region writes and reads at single-digit millisecond latency. Each container can be mapped to multiple Azure regions, and data is replicated with multiple consistency models—from strong to eventual—giving developers predictable latency and availability trade-offs. With automatic failover and an SLA-backed 99.999% availability, Cosmos DB is the only option here engineered specifically as a distributed, low-latency, globally redundant data store.

Why this answer

Azure Cosmos DB is the correct choice because it provides globally distributed, multi-region writes with tunable consistency levels and single-digit-millisecond latency for read-heavy workloads. Its ability to replicate data across Azure regions and serve reads from the nearest region directly addresses the requirement for low-latency global access to product catalog data with occasional updates.

Exam trap

The trap here is that candidates often choose Azure Cache for Redis (Option A) because they associate low-latency with caching, but fail to recognize that the question requires a durable, globally distributed primary data store, not a cache layer that depends on an underlying database.

How to eliminate wrong answers

Option A is wrong because Azure Cache for Redis is an in-memory cache, not a durable primary data store; it would require an underlying persistent store and cannot serve as the authoritative source for product catalog data that needs occasional updates. Option B is wrong because Azure Blob Storage is optimized for unstructured blob data (images, videos, backups) and does not support low-latency, sub-second queries on structured product catalog data with indexing and consistency guarantees. Option C is wrong because Azure SQL Database is a relational database that, while supporting read replicas, does not natively provide multi-region, multi-master replication with automatic failover and tunable consistency for global low-latency reads; it requires complex manual configuration and has higher latency for cross-region access.

661
Multi-Selectmedium

Which Azure service can be used to implement a globally distributed database that supports multi-region writes and provides low-latency access to users worldwide?

Select 1 answer
A.Azure Storage with geo-redundant storage (GRS).
B.Azure Cache for Redis with geo-replication.
C.Azure Cosmos DB with multi-master enabled.
D.Azure Database for PostgreSQL with geo-replication.
E.Azure SQL Database with active geo-replication and failover groups.
AnswersC

Correct. Azure Cosmos DB with multi-master enabled natively supports multi-region writes with automatic conflict resolution and low-latency access worldwide.

Why this answer

Azure Cosmos DB with multi-master enabled (Option C) is the only Azure service among the options that natively supports multi-region write operations, allowing data to be written to any Azure region simultaneously with automatic conflict resolution and low-latency access globally. Azure SQL Database with active geo-replication and failover groups (Option E) does not support concurrent multi-region writes; it enables read-only replicas in secondary regions and failover to a single writable region, which does not meet the requirement for multi-region writes. Other options either don't support multi-region writes or aren't database services.

Exam trap

The trap is that candidates may mistake Azure SQL Database's active geo-replication and failover groups as supporting multi-region writes. However, it only allows writes in one region at a time after failover, not concurrent writes. Azure Cosmos DB with multi-master is the only service that provides true multi-region write capability.

662
MCQhard

A large enterprise wants to enforce zero-trust conditional access policies that use real-time user risk, sign-in risk, and device compliance. Which combination of Microsoft Entra ID features should they use?

A.Microsoft Entra ID Identity Protection and Conditional Access
B.Microsoft Entra ID Privileged Identity Management and Access Reviews
C.Microsoft Entra ID B2B and External Identities
D.Microsoft Entra ID Domain Services and Managed Identities
AnswerA

Identity Protection evaluates millions of signals per sign-in to calculate user and sign-in risk, detecting anomalies such as leaked credential use, impossible travel, and anomalous token behavior. Conditional Access then consumes those risk signals in real time to enforce step-up authentication (e.g., MFA or password change) or block access entirely, operationalizing zero trust at the identity plane with adaptive, context-aware policies.

Why this answer

Microsoft Entra ID Identity Protection provides real-time risk detection for users and sign-ins, while Conditional Access policies can enforce access controls based on those risk signals and device compliance. Together, they enable zero-trust conditional access by blocking or requiring MFA when user or sign-in risk is high, and ensuring only compliant devices can access resources.

Exam trap

The trap here is that candidates confuse Privileged Identity Management (PIM) with risk-based conditional access, but PIM only manages role activation and does not evaluate user/sign-in risk or device compliance in real time.

How to eliminate wrong answers

Option B is wrong because Privileged Identity Management (PIM) and Access Reviews focus on just-in-time privileged role activation and periodic attestation, not on real-time user/sign-in risk or device compliance. Option C is wrong because B2B and External Identities are designed for guest user collaboration and identity federation, not for enforcing risk-based conditional access policies on internal users. Option D is wrong because Azure AD Domain Services provides managed domain services (like LDAP, Kerberos) for legacy apps, and Managed Identities are used for Azure resource authentication, neither of which offer risk detection or conditional access enforcement.

663
MCQmedium

A company runs a critical application on Azure VMs. They want to back up the VMs using Azure Backup. The retention requirements are: daily backups for 35 days, weekly backups for 52 weeks, and yearly backups for 10 years. Which backup policy should they create?

A.Create a custom backup policy with a daily backup schedule and retention rules for daily (35), weekly (52), and yearly (10 years)
B.Use the default backup policy provided by Azure Backup
C.Use Azure Site Recovery (ASR) to replicate the VMs and meet the retention
D.Use Azure Backup for VMs with instant recovery enabled
AnswerA

A custom backup policy in Azure Backup allows you to define a daily backup schedule and independent retention rules for each backup frequency. With the requested settings, daily restore points are kept for 35 days, weekly restore points for 52 weeks (one year), and yearly restore points for 10 years, all within Azure Backup's supported retention limits. This directly meets the compliance and recovery requirements by controlling both when backups are captured and how long each frequency tier is retained.

Why this answer

Azure Backup allows you to create a custom backup policy that defines a daily backup schedule and separate retention rules for daily, weekly, and yearly retention points. This directly meets the requirement of 35 days daily, 52 weeks weekly, and 10 years yearly retention, as Azure Backup supports granular retention policies with multiple tiers (daily, weekly, monthly, yearly) within a single policy.

Exam trap

The trap here is that candidates may confuse Azure Backup's default policy (which only covers short-term retention) with the ability to customize retention tiers, or mistakenly think Azure Site Recovery can serve as a backup solution for long-term retention, when in fact it is for replication and failover, not backup retention.

How to eliminate wrong answers

Option B is wrong because the default backup policy in Azure Backup typically retains daily backups for only 30 days (not 35) and does not include weekly or yearly retention rules, so it cannot meet the specified requirements. Option C is wrong because Azure Site Recovery (ASR) is designed for disaster recovery and replication, not for long-term backup retention; it does not support retention policies for years and is not a backup solution for meeting retention schedules. Option D is wrong because instant recovery is a feature that enables faster restore from snapshots, but it does not modify or extend retention policies; the default or custom policy still governs retention, and instant recovery alone cannot satisfy the 35-day, 52-week, and 10-year retention requirements.

664
Multi-Selecthard

A mission-critical web application must tolerate a full Azure region outage. The business requires automatic failover and global HTTP acceleration. Which two components should be included in the design? (Choose 2.)

Select 2 answers
A.Deploy the application to at least two Azure regions.
B.Use Azure Front Door with health probes and origin failover.
C.Use only availability zones in one region.
D.Use Azure Bastion for failover routing.
AnswersA, B

Multi-region deployment is the only architecture that can survive a full regional outage because a region is a complete independent Azure deployment with its own core services, power, cooling, and network. Even with perfect code and infrastructure, a single region has a single region failure scope; paired regions give independent availability and planned maintenance. A mission-critical system must therefore establish at least two regional origins before any automated failover can work, making this the baseline for true disaster recovery.

Why this answer

Deploying the application to at least two Azure regions provides geographic redundancy, ensuring that if one entire region fails, the application can still operate from the other region. This is a fundamental requirement for tolerating a full region outage. Option B is correct because Azure Front Door provides global HTTP acceleration and automatic failover by using health probes to monitor endpoint health and routing traffic to healthy origins, which meets the business requirements for both automatic failover and performance.

Exam trap

The trap here is that candidates often confuse availability zones (which protect against datacenter failures within a region) with multi-region deployments (which are required for region outage tolerance), leading them to incorrectly select Option C as sufficient.

665
MCQmedium

A SaaS company uses Azure SQL Database for a multi-tenant application. They have 80 tenant databases, each with varying and unpredictable usage patterns. The company wants to optimize costs without sacrificing performance and wants the ability to easily add new tenant databases without over-provisioning. Which deployment option should they use?

A.Azure SQL Database elastic pool
B.Single Azure SQL Database per tenant
C.Azure SQL Managed Instance
D.Azure SQL Database Hyperscale
AnswerA

For a multi-tenant SaaS workload, elastic pools let you purchase a shared set of eDTUs or vCores that is distributed across many Azure SQL databases. This model excels when tenant usage is intermittent and peaks do not align, so the aggregate resource consumption is far lower than the sum of individual peak requirements, reducing overall cost while maintaining predictable per-database pricing.

Why this answer

Azure SQL Database elastic pool is the correct choice because it allows multiple tenant databases to share a fixed set of resources (DTUs or vCores), automatically absorbing the unpredictable usage spikes of individual tenants without over-provisioning. This model optimizes cost by paying for the pooled resources rather than each database's peak capacity, and new tenant databases can be added seamlessly to the pool without upfront resource allocation.

Exam trap

The trap here is that candidates often choose Single Azure SQL Database per tenant (Option B) because they think it provides isolation and simplicity, but they overlook the cost inefficiency of over-provisioning for unpredictable peaks, which is exactly the problem elastic pools solve.

How to eliminate wrong answers

Option B (Single Azure SQL Database per tenant) is wrong because it requires provisioning each database for its peak load, leading to significant over-provisioning and higher costs when tenants have unpredictable, varying usage patterns. Option C (Azure SQL Managed Instance) is wrong because it is a fully managed instance of SQL Server with fixed resource limits per instance, designed for lift-and-shift scenarios, not for cost-efficient multi-tenant elasticity with many small databases. Option D (Azure SQL Database Hyperscale) is wrong because it is optimized for very large databases (up to 100 TB) with high throughput and rapid scaling, not for pooling many small, unpredictable tenant databases; it would be unnecessarily expensive and complex for this workload.

666
MCQmedium

A company wants to deploy a web application on Azure virtual machines (VMs). The application experiences variable traffic patterns, so the company needs to automatically add or remove VM instances based on CPU utilization. They also want the application to remain highly available even if an Azure datacenter fails. Which combination of Azure services should they use?

A.Virtual Machine Scale Sets configured with autoscale rules based on CPU and distributed across availability zones
B.Azure App Service with autoscale rules and deployment slots
C.Azure Load Balancer with a backend pool of VMs and autoscale rules applied to individual VMSS
D.Azure Traffic Manager with endpoints in separate regions and Manual scaling of VMs
AnswerA

Virtual Machine Scale Sets are the only compute option listed that runs your workload on IaaS VMs while natively supporting horizontal autoscale: you define a scale condition (e.g., scale out by one instance when CPU percentage exceeds 75%, scale in when below 25%) and Azure applies it to the entire set. Deploying the VMSS across multiple availability zones places instance replicas in physically separate datacenters within the region, so a zone outage does not take down the entire web tier. This combination directly satisfies both the CPU-based automatic scaling and the zone-failure protection requirement.

Why this answer

Virtual Machine Scale Sets (VMSS) with autoscale rules based on CPU utilization automatically add or remove VM instances to match variable traffic patterns. Distributing the VMSS across availability zones ensures the application remains highly available even if an entire Azure datacenter fails, because availability zones are physically separate datacenters within a region.

Exam trap

The trap here is that candidates often confuse Azure App Service (PaaS) with IaaS VM solutions, or assume that a load balancer alone can handle autoscaling, when in fact autoscale rules must be configured directly on the VMSS resource.

How to eliminate wrong answers

Option B is wrong because Azure App Service is a Platform-as-a-Service (PaaS) offering, not a VM-based solution, and the question explicitly requires deployment on Azure virtual machines. Option C is wrong because Azure Load Balancer distributes traffic but does not itself perform autoscaling; autoscale rules must be applied directly to the VMSS, not to individual VMs, and the phrase 'applied to individual VMSS' is redundant and misstates the architecture. Option D is wrong because Traffic Manager provides global DNS-based traffic routing across regions, but manual scaling of VMs does not meet the requirement for automatic scaling based on CPU utilization.

667
MCQhard

A company runs a high-performance computing (HPC) workload that requires low-latency access to large files (hundreds of GB) from thousands of Azure VMs concurrently. The files must be accessible via the NFS protocol and the solution must be a fully managed, POSIX-compliant file system that can scale throughput linearly with capacity. Which Azure storage solution should they choose?

A.Azure NetApp Files
B.Azure Files (premium tier)
C.Azure Blob Storage with NFS 3.0 support
D.Azure HPC Cache
AnswerA

Azure NetApp Files is a fully managed, enterprise-grade file service built on NetApp ONTAP, providing both NFS and SMB protocols with POSIX-compliant semantics. It is engineered for high-performance computing, offering sub-millisecond latencies, tens of thousands of IOPS, and multi-GiB/s throughput that scales linearly by adding capacity. It also supports advanced data management features like snapshots, clones, and near-instantaneous resizing, making it the optimal choice for demanding HPC workloads.

Why this answer

Azure NetApp Files is the correct choice because it provides a fully managed, POSIX-compliant NFS file system that can scale throughput linearly with capacity. It is designed for HPC workloads requiring low-latency access to large files from thousands of concurrent VMs, offering sub-millisecond latency and high throughput that increases as you add capacity.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with NFS support as a fully POSIX-compliant file system, overlooking its lack of full POSIX compliance and linear throughput scaling, or they assume Azure Files premium tier can match the performance and scalability of Azure NetApp Files for HPC workloads.

How to eliminate wrong answers

Option B is wrong because Azure Files (premium tier) uses SMB protocol by default and, while it supports NFS, it does not provide the linear throughput scaling with capacity required for HPC workloads; its performance is capped per share and does not scale linearly. Option C is wrong because Azure Blob Storage with NFS 3.0 support is not a fully POSIX-compliant file system; it lacks features like hard links and directory rename operations, and its throughput does not scale linearly with capacity in the same way as a true file system. Option D is wrong because Azure HPC Cache is a caching service that accelerates access to existing storage (e.g., on-premises or Azure Blob), not a fully managed, POSIX-compliant file system itself; it does not provide a native NFS file system with linear throughput scaling.

668
MCQhard

Your company, Contoso Ltd., is a global financial services firm with a primary data center in London and a disaster recovery site in Paris. They are migrating their on-premises SQL Server databases to Azure. The databases include: (1) a 2-TB customer database with high transaction throughput, requiring an RPO of 5 seconds and an RTO of 30 seconds; (2) a 500-GB reporting database that is read-only and can tolerate an RPO of 1 hour and an RTO of 2 hours; (3) a 100-GB archival database that is accessed once a month. The solution must minimize costs while meeting requirements. You need to recommend a storage and database strategy for each database. What should you recommend?

A.Use Azure SQL Managed Instance for all databases with auto-failover groups.
B.Use Azure SQL Database with active geo-replication for the customer database, geo-restore for the reporting database, and long-term retention for the archival database.
C.Use Azure Cosmos DB for the customer database, Azure SQL Database for reporting, and Azure Blob Storage for archival.
D.Use Azure SQL Database with active geo-replication for all databases.
AnswerB

Active geo-replication on the customer database continuously replicates transactions to a readable secondary in another region, giving you a low RPO and fast failover for the mission-critical transactional workload. Geo-restore for the reporting database uses geo-redundant backups to recover to another region only when a disaster occurs, avoiding the cost of maintaining a live secondary. Long-term retention on the archival database supports configurable backup retention up to ten years at blob storage pricing, satisfying compliance requirements without continuous replication. This tiered strategy pairs the right recovery and retention mechanism with each database's functional and cost requirements.

Why this answer

It aligns the recovery objectives and cost constraints for each database. The customer database requires an RPO of 5 seconds and RTO of 30 seconds, which active geo-replication can meet by continuously replicating transactions to a secondary region with an RPO of 5 seconds and RTO of 30 seconds (including failover time). The reporting database tolerates an RPO of 1 hour and RTO of 2 hours, making geo-restore (which restores from geo-redundant backups with up to 1-hour RPO) a cost-effective choice.

The archival database is accessed monthly, so long-term retention (LTR) backups stored in Azure Blob Storage minimize cost while meeting the infrequent access pattern.

Exam trap

The trap here is that candidates often assume all databases need the highest availability feature (active geo-replication) without considering cost optimization, or they mistakenly think Azure SQL Managed Instance can achieve sub-minute RPO, when in fact its auto-failover groups have a 5-minute RPO limit due to the use of distributed availability groups.

How to eliminate wrong answers

Option A is wrong because Azure SQL Managed Instance with auto-failover groups cannot achieve an RPO of 5 seconds (auto-failover groups have a maximum RPO of 5 minutes) and is more expensive than necessary for the reporting and archival databases. Option C is wrong because Azure Cosmos DB is a NoSQL database and does not support SQL Server workloads or the required ACID transactions for the customer database; Azure Blob Storage for archival lacks native SQL querying and backup restore capabilities needed for the archival database. Option D is wrong because using active geo-replication for all databases incurs unnecessary cost for the reporting database (which only needs geo-restore) and the archival database (which only needs LTR), and active geo-replication does not support the read-only reporting database's lower RPO/RTO requirements efficiently.

669
MCQeasy

A company has multiple branch offices and needs to connect them to Azure and to each other using a scalable, managed solution that simplifies network architecture. The solution should support automatic routing and integration with ExpressRoute and VPN. Which Azure service should they use?

A.Azure Virtual Network
B.Azure Virtual WAN
C.Azure ExpressRoute
D.Azure VPN Gateway
AnswerB

Azure Virtual WAN is a managed networking service that creates a hub-and-spoke architecture with integrated routing, automatically interconnecting branches, Azure VNets, and on-premises locations. It natively supports Site-to-Site VPN, Point-to-Site VPN, and ExpressRoute, and it performs automatic route table generation and propagation across all spokes. Virtual WAN also enables branch-to-branch connectivity without manual peering, making it the only option here that delivers a scalable, zero-touch global transit network.

Why this answer

Azure Virtual WAN is a managed networking service that aggregates branch, VPN, and ExpressRoute connectivity into a single hub-and-spoke architecture. It automatically handles routing between branches and Azure, supports any-to-any connectivity, and integrates natively with ExpressRoute and VPN gateways, making it the correct choice for a scalable, managed solution that simplifies network architecture.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN with Azure Virtual Network, thinking that a simple VNet with VPN gateways can scale to interconnect multiple branches, but they overlook the managed, automatic routing and aggregation capabilities that Virtual WAN provides for multi-site topologies.

How to eliminate wrong answers

Option A is wrong because Azure Virtual Network is a fundamental building block for creating isolated networks in Azure, but it does not provide managed, automatic routing between multiple branch offices or native integration with ExpressRoute and VPN at scale; it requires manual configuration of peering, gateways, and routing. Option C is wrong because Azure ExpressRoute is a dedicated private connection from on-premises to Azure, but it does not connect multiple branch offices to each other or provide automatic routing between them; it is a connectivity option, not a managed WAN service. Option D is wrong because Azure VPN Gateway provides site-to-site VPN connectivity from a single branch to Azure, but it does not offer a managed, scalable hub for interconnecting multiple branches or automatic routing between them; it requires additional configuration and does not aggregate multiple connections into a single managed topology.

670
MCQhard

You are designing a business continuity solution for a global e-commerce platform that runs on Azure Kubernetes Service (AKS) in multiple regions. The application must remain available even if an entire Azure region fails. The application uses Azure Cosmos DB for its database. You need to ensure that the application can continue to serve traffic with minimal disruption. What should you recommend?

A.Use Cosmos DB with geo-redundant storage and deploy a single AKS cluster with Azure Site Recovery.
B.Deploy AKS clusters in two regions with Azure Traffic Manager and use Cosmos DB single-region writes with async replication.
C.Configure Cosmos DB with multi-region writes and deploy AKS clusters in two regions behind Azure Front Door.
D.Deploy the application to a single region and use Azure Backup for Cosmos DB to restore in another region.
AnswerC

This is the correct solution because it delivers a true active-active architecture with zero data loss and minimal downtime. Cosmos DB multi-region writes allows the database to accept writes in both regions, and the service automatically synchronizes all regions with a single write consistency model; during a regional outage, Cosmos DB automatically fails over the affected region without any manual intervention, preserving both availability and RPO. Azure Front Door fronts the two AKS clusters with global load balancing at Layer 7, providing instant failover via health probes, SSL offload, and path-based routing—it can route traffic to the healthy region in seconds, unlike DNS-only solutions. The combination of multi-region writes (no RPO loss) and Front Door (near-zero RTO) satisfies the business continuity requirement for a globally distributed application, making this the only option that meets the stated goals.

Why this answer

It combines multi-region writes in Azure Cosmos DB with AKS clusters deployed in two regions behind Azure Front Door. Multi-region writes provide active-active failover with RTO near zero and 99.999% read/write availability, while Azure Front Door offers global load balancing and automatic failover at the application layer. This architecture ensures the application remains available even if an entire Azure region fails, with minimal disruption.

Exam trap

The trap here is that candidates often confuse Azure Storage geo-redundant storage (GRS) with Cosmos DB's native multi-region replication, or they assume that single-region writes with async replication (Option B) provide sufficient availability, ignoring the risk of data loss and manual failover delays.

How to eliminate wrong answers

Option A is wrong because Cosmos DB does not use geo-redundant storage (GRS) — that is a feature of Azure Storage accounts, not Cosmos DB; Cosmos DB uses its own multi-region replication. Also, deploying a single AKS cluster with Azure Site Recovery does not provide active-active failover; Site Recovery is for disaster recovery with RTO in minutes, not for minimal disruption. Option B is wrong because Cosmos DB single-region writes with async replication have a potential for data loss (RPO > 0) and failover is not automatic, requiring manual or scripted intervention, which contradicts 'minimal disruption'.

Option D is wrong because deploying to a single region and using Azure Backup for Cosmos DB to restore in another region results in significant downtime (RTO in hours) and data loss (RPO based on backup frequency), which is not acceptable for a global e-commerce platform requiring minimal disruption.

671
MCQmedium

A company stores log data in Azure Blob Storage. The logs are accessed frequently for the first 30 days, then only occasionally for up to 1 year, and after that must be retained for 7 years for compliance purposes. The company wants to minimize storage costs by automatically moving data to cheaper tiers. Which Azure Blob Storage lifecycle management policy should they implement?

A.Move to Cool tier after 30 days, move to Archive tier after 365 days, delete after 2555 days
B.Move to Cool tier after 30 days, move to Archive tier after 365 days, delete after 7 years
C.Move to Cool tier after 30 days, move to Archive tier after 30 days, delete after 2555 days
D.Move to Archive tier after 30 days, keep in Archive until deletion after 2555 days
AnswerA

This policy correctly matches the log usage lifecycle: for the first 30 days data remains Hot for frequent queries; from day 30 to day 365 it is moved to Cool because access becomes occasional but still needed; after 365 days it is moved to Archive for long-term compliance while deletion occurs after 2555 days (exactly 7 years). That transition sequence minimizes cost: Hot for active use, Cool for sporadic retrieval with no rehydration fee, and Archive for rarely accessed records, with deletion eliminating any further storage charges. The rule uses numeric day values as Azure requires.

Why this answer

It aligns with the access patterns: move to Cool tier after 30 days (frequent access period), move to Archive tier after 365 days (occasional access period ends), and delete after 2555 days (7 years retention). This minimizes costs by transitioning data to progressively cheaper storage tiers and automatically deleting it when compliance retention expires.

Exam trap

The trap here is that candidates may choose Option B thinking '7 years' is acceptable in the policy, but Azure requires the 'delete after' action to be specified in days (2555), not years, and they may overlook the early deletion penalty of the Archive tier when moving data too soon.

How to eliminate wrong answers

Option B is wrong because it specifies 'delete after 7 years' without converting to days; Azure lifecycle management policies require the 'delete after' action to be defined in days, not years, and 7 years equals 2555 days, not a literal '7 years' string. Option C is wrong because it moves data to Archive tier after only 30 days, which would incur early deletion fees and retrieval costs since logs are still accessed occasionally for up to a year; Archive tier is for rarely accessed data and has a 180-day minimum storage charge. Option D is wrong because it moves data directly to Archive tier after 30 days, ignoring the Cool tier entirely, which increases costs due to early deletion penalties and higher retrieval costs for the occasional access period up to 365 days.

672
MCQhard

Refer to the exhibit. The ARM template provisions a VM. The deployment succeeds but the VM fails to start. What is the most likely cause?

A.The admin password is in plaintext and does not meet complexity requirements
B.The data disk size 1023 GB exceeds the maximum for StandardSSD_LRS
C.The network interface resource ID is incorrectly formatted
D.The VM size Standard_D2s_v3 is not available in the region
AnswerD

Correct. As explained, the VM size not being available in the region can lead to a successful deployment but the VM failing to start.

Why this answer

The VM size Standard_D2s_v3 may not be available in the specified region or subscription. ARM template deployments can succeed in provisioning the resource definition, but the VM fails to start if the scheduler cannot allocate a host that supports this VM size. This is a common issue when the size is restricted or not available in the region, causing a delayed failure after deployment.

Exam trap

The trap here is that candidates assume any deployment success means all configuration is valid, but Azure separates infrastructure provisioning from guest OS configuration, so password or other guest-level failures can occur after deployment succeeds.

How to eliminate wrong answers

Option B is wrong because StandardSSD_LRS supports data disks up to 4095 GB, so 1023 GB is well within the limit. Option C is wrong because the network interface resource ID format in the exhibit (e.g., /subscriptions/.../networkInterfaces/...) is correctly formatted; an incorrect format would cause a deployment failure, not a VM start failure. Option D is wrong because if the VM size were unavailable in the region, the deployment itself would fail with a capacity error, not succeed and then fail to start.

673
MCQeasy

A company needs a fully managed NoSQL database for a new application with a key-value and document data model. They require single-digit millisecond latency at any scale, multi-region writes with automatic conflict resolution, and a serverless capacity option to handle unpredictable traffic. Which Azure data service should they use?

A.Azure Table Storage
B.Azure Cosmos DB
C.Azure Cache for Redis
D.Azure SQL Database
AnswerB

Azure Cosmos DB is the correct choice because it is a fully managed, multi-model NoSQL database that guarantees single-digit millisecond latency for reads and writes at the 99th percentile. Its multi-region writes capability lets you write to any region with automatic conflict resolution policies and a health-based failover, while the serverless mode adds throughput and storage per request, making it ideal for spiky or unpredictable workloads.

Why this answer

Azure Cosmos DB is the correct choice because it is a fully managed NoSQL database that supports both key-value and document data models natively. It guarantees single-digit millisecond latency at any scale, offers multi-region writes with automatic conflict resolution via its multi-master replication, and provides a serverless capacity mode that automatically scales based on demand, making it ideal for unpredictable traffic.

Exam trap

The trap here is that candidates often confuse Azure Table Storage as a NoSQL database that supports multi-region writes, but it lacks document support and automatic conflict resolution, making Cosmos DB the only option that meets all requirements.

How to eliminate wrong answers

Option A is wrong because Azure Table Storage is a key-value store but does not support a document data model, lacks multi-region writes with automatic conflict resolution, and does not offer a serverless capacity option (it uses provisioned throughput). Option C is wrong because Azure Cache for Redis is an in-memory caching service, not a fully managed NoSQL database; it does not natively support document data models or multi-region writes with conflict resolution. Option D is wrong because Azure SQL Database is a relational database (SQL-based), not a NoSQL database, and does not support key-value or document data models natively, nor does it offer multi-region writes with automatic conflict resolution.

674
MCQhard

You are designing a data storage solution for an IoT application that ingests millions of events per second. Each event is a small JSON message (under 1 KB). The solution must support real-time analytics and allow queries on recent data (last 24 hours) with low latency. Historical data (older than 24 hours) should be stored in a cost-optimized manner for occasional compliance queries. Which combination of Azure services should you recommend?

A.Azure Cosmos DB for both real-time and historical data
B.Azure Event Hubs for ingestion and Azure Functions for querying
C.Azure SQL Database with elastic pool
D.Azure Data Explorer for real-time analytics and Azure Blob Storage for historical data
AnswerD

Azure Data Explorer is a fast, fully managed analytics database specifically designed for querying large volumes of time-series and log data, with built-in high-throughput ingestion from sources like Event Hubs and low-latency queries for real-time dashboards. For historical data, Azure Blob Storage provides economical, tiered object storage that retains massive data volumes at a fraction of the cost, enabling that data to be rehydrated or queried on demand via technologies like Synapse or ADX’s external table feature. This architecture cleanly separates the hot path for interactive real-time analysis from the cold path for long-term retention, satisfying both performance and cost constraints.

Why this answer

Azure Data Explorer (ADX) is purpose-built for real-time analytics on high-velocity data streams, ingesting millions of events per second with sub-second query latency on recent data. Azure Blob Storage provides a cost-optimized tier (e.g., Cool or Archive) for historical data older than 24 hours, which can be queried occasionally via ADX’s continuous export or external table feature. This combination meets both the low-latency real-time analytics requirement and the cost-effective long-term storage need.

Exam trap

The trap here is that candidates often confuse high-throughput ingestion with query capability, assuming that any service that can ingest data (like Event Hubs) can also serve real-time queries, or that a general-purpose database (like Cosmos DB or SQL Database) can handle the extreme volume and analytics pattern of IoT telemetry.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB, while fast for transactional workloads, is not optimized for high-throughput ingestion of millions of events per second for real-time analytics; its per-request cost and indexing overhead would be prohibitive for this volume, and it lacks native time-series analytics capabilities. Option B is wrong because Azure Event Hubs is an ingestion service, not a query engine; Azure Functions are stateless and unsuitable for low-latency ad-hoc queries over terabytes of recent data, and they cannot efficiently handle the querying requirement. Option C is wrong because Azure SQL Database with elastic pool cannot ingest millions of events per second due to connection and transaction limits, and its cost for storing and querying high-volume time-series data would be excessive compared to purpose-built solutions.

675
MCQeasy

You need to design a storage solution for a data lake that will store petabytes of structured and unstructured data. The data must be accessible from Azure Databricks and Azure Machine Learning. The solution must optimize costs by automatically moving data to cooler tiers when access frequency decreases. Which Azure storage solution should you use?

A.Azure Data Lake Storage Gen2
B.Azure Blob Storage (flat namespace)
C.Azure NetApp Files
D.Azure Files
AnswerA

Azure Data Lake Storage Gen2 is the correct choice because it combines blob-based, petabyte-scale object storage with a hierarchical namespace that mirrors a file system. This enables POSIX-style access controls, atomic directory rename, and efficient path-based operations, which are critical for Databricks and machine learning workloads that enumerate directory trees. It also supports lifecycle management policies to tier data across hot, cool, and archive tiers, reducing cost while preserving analytical performance.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with Blob Storage's tiered lifecycle management, enabling petabyte-scale storage for both structured and unstructured data. It integrates natively with Azure Databricks and Azure Machine Learning via the ABFS driver, and its lifecycle policies automatically move data to cooler tiers (cool, archive) based on access frequency, optimizing costs.

Exam trap

The trap here is that candidates confuse Azure Blob Storage (flat namespace) with ADLS Gen2, assuming both support data lake workloads equally, but the hierarchical namespace is a critical differentiator for performance and security in petabyte-scale analytics.

How to eliminate wrong answers

Option B (Azure Blob Storage with flat namespace) is wrong because it lacks a hierarchical namespace, which is essential for efficient directory-level operations and ACL-based security in data lake scenarios; while it supports lifecycle management, the flat namespace makes it suboptimal for large-scale analytics workloads. Option C (Azure NetApp Files) is wrong because it is designed for high-performance, low-latency NFS/SMB workloads (e.g., enterprise applications, VDI) and does not support automatic tiering to cooler storage tiers; it also incurs higher costs for petabyte-scale data lakes. Option D (Azure Files) is wrong because it provides SMB file shares for lift-and-shift scenarios, not the object storage or hierarchical namespace needed for data lake analytics, and it lacks lifecycle management for cost optimization across tiers.

Page 8

Page 9 of 11

Page 10

All pages