Courseiva

CCNA Design business continuity solutions Questions

75 of 152 questions · Page 2/3 · Design business continuity solutions · Answers revealed

76
Multi-Selectmedium

Which TWO of the following Azure services can be used to enable automatic failover of a web application across Azure regions?

Select 2 answers
A.Azure DNS
B.Azure Load Balancer
C.Azure Front Door
D.Azure Traffic Manager
E.Azure Application Gateway
AnswersC, D

Azure Front Door is a global Layer 7 anycast service that continuously health-checks each backend or origin and uses that status to steer traffic to the nearest healthy region. When a region fails, Front Door quickly removes that origin from its active routing set, causing users to be redirected to another region with minimal disruption. It also provides TLS termination, URL-based routing, and a web application firewall, making it a robust choice for global web applications.

Why this answer

Azure Front Door is a global, scalable entry point that provides built-in automatic failover across regions using anycast-based routing and health probes. When a primary region becomes unhealthy, Front Door instantly routes traffic to the next available healthy backend, enabling seamless multi-region failover for web applications.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager (DNS-based) with Azure Front Door (anycast-based), assuming both provide identical failover speed, but Front Door offers faster, more granular failover due to its anycast architecture and Layer 7 capabilities.

77
MCQhard

A company runs a critical application using Azure SQL Database in the West US region. They need a disaster recovery solution that automatically fails over to a secondary region (East US) with a recovery point objective (RPO) of 5 seconds and a recovery time objective (RTO) of 1 minute. The secondary region must also be able to serve read-only queries for reporting purposes. Which Azure SQL Database feature should they implement?

A.Azure SQL Database active geo-replication with auto-failover group
B.Azure SQL Database geo-restore
C.Azure SQL Database copy
D.Azure SQL Managed Instance failover group
AnswerA

For a critical application running on Azure SQL Database, active geo-replication with an auto-failover group provides the most suitable business continuity. The replication is asynchronous, keeping a second readable database in a different Azure region with an RPO of up to 5 seconds. The auto-failover group continuously monitors health and initiates automatic failover with a target RTO of 1 minute, minimizing downtime. This combination meets the strict RPO/RTO requirements while also allowing the secondary to serve read-only queries.

Why this answer

Active geo-replication with auto-failover groups is the correct choice because it provides automatic, synchronous failover to a secondary region with an RPO of 5 seconds and an RTO of 1 minute. Additionally, the secondary database can be used for read-only reporting by connecting with the 'ApplicationIntent=ReadOnly' connection string, meeting both the disaster recovery and reporting requirements.

Exam trap

The trap here is that candidates often confuse geo-restore (which is manual and has high RPO/RTO) with active geo-replication, or they mistakenly think that SQL Managed Instance failover groups support read-only secondaries for Azure SQL Database, when in fact they are for Managed Instance only.

How to eliminate wrong answers

Option B (geo-restore) is wrong because it is a manual recovery process that restores a database from geo-replicated backups, resulting in an RPO of 1 hour and an RTO of several hours, far exceeding the required 5-second RPO and 1-minute RTO. Option C (copy) is wrong because it creates a point-in-time snapshot copy of the database, which is not a continuous replication solution and cannot provide automatic failover or meet the low RPO/RTO requirements. Option D (Azure SQL Managed Instance failover group) is wrong because it applies to Azure SQL Managed Instance, not Azure SQL Database, and while it supports auto-failover, it does not natively allow the secondary to serve read-only queries for reporting without additional configuration.

78
Multi-Selectmedium

You are designing a disaster recovery plan for an Azure virtual machine running a critical application. The solution must meet an RPO of 1 hour and an RTO of 4 hours. Which TWO actions should you take? (Choose TWO.)

Select 2 answers
A.Deploy the VM in an Availability Set and use premium storage.
B.Configure Azure Backup with daily snapshots stored in a Recovery Services vault.
C.Enable Azure Site Recovery for the VM with replication to a secondary region.
D.Create a Recovery Services vault in the secondary region with geo-redundant storage (GRS).
E.Use Azure Front Door to distribute traffic between the primary and secondary regions.
AnswersC, D

Azure Site Recovery is the native DR service for Azure VMs. It continuously replicates the VM's disks to the target region using an asynchronous, near-synchronous process that delivers an RPO of a few seconds, and it supports planned and unplanned failover with a predetermined RTO. By orchestrating replication, failover, and failback, ASR is purpose-built to meet a 1-hour RPO/RTO for disaster recovery.

Why this answer

Azure Site Recovery (ASR) replicates VMs to a secondary region with configurable recovery point objectives (RPO) as low as 30 seconds, easily meeting the 1-hour RPO. Combined with a Recovery Services vault in the secondary region using geo-redundant storage (GRS), you ensure replicated data is stored durably and can be failed over within the 4-hour RTO, as ASR automates orchestration and failover.

Exam trap

The trap here is confusing high availability (Availability Sets) with disaster recovery (cross-region replication), and assuming that backup (Azure Backup) can meet low RPO/RTO requirements when it is designed for long-term retention, not rapid failover.

79
MCQhard

You are reviewing a Bicep template that deploys two App Service Environments (ASE) and an Azure Traffic Manager profile. The exhibit shows the template snippet. What is the expected behavior when the primary ASE becomes unhealthy?

A.Traffic is stopped until an administrator updates the DNS manually.
B.Traffic is load-balanced between both ASEs based on performance.
C.Traffic is automatically routed to the secondary ASE with priority 2.
D.Traffic continues to be sent to the primary ASE because priority routing only uses the primary.
AnswerC

When the primary ASE becomes unhealthy, Traffic Manager's health probe marks it as unavailable and automatically returns the secondary ASE's DNS name (the endpoint with Priority 2) in response to new client DNS queries. This failover happens without any manual intervention, and the redirection remains in effect while the primary endpoint is unhealthy. Because Traffic Manager continuously re-probes endpoints, the secondary ASE continues to receive traffic until the primary is healthy again and can regain Priority 1 status.

Why this answer

Azure Traffic Manager uses priority routing, which directs all traffic to the primary endpoint (priority 1) as long as it is healthy. When the primary ASE becomes unhealthy, Traffic Manager automatically fails over to the next priority endpoint (priority 2), ensuring continuous availability without manual intervention.

Exam trap

The trap here is that candidates may confuse priority routing with performance routing or assume that Traffic Manager requires manual DNS changes for failover, when in fact it automatically handles failover based on endpoint health probes.

How to eliminate wrong answers

Option A is wrong because Traffic Manager automatically handles DNS-level failover; manual DNS updates are not required. Option B is wrong because priority routing does not load-balance based on performance; it sends all traffic to the highest-priority healthy endpoint. Option D is wrong because priority routing does not ignore unhealthy endpoints; it automatically routes traffic away from an unhealthy primary to the next priority endpoint.

80
Multi-Selectmedium

Which TWO actions should you take to ensure business continuity for an Azure SQL Managed Instance? (Choose two.)

Select 2 answers
A.Use Azure Site Recovery to replicate the instance to another region
B.Configure a readable secondary replica in the same region
C.Enable automated backups with a retention period that meets your RPO
D.Configure a failover group with a secondary instance in a different region
E.Enable long-term retention (LTR) for backups
AnswersC, D

Automated backups for SQL Managed Instance enable point-in-time restore (PITR) to any point within the configured retention period, making them the foundational mechanism to meet a specified RPO. Because backups are stored in geo-redundant storage (RA-GRS) by default, they also provide a cross-region restore option if the primary region is lost. Choosing a retention period that at least matches your RPO ensures you can recover to a state no older than your recovery target.

Why this answer

Automated backups are a fundamental component of business continuity for Azure SQL Managed Instance. They provide point-in-time restore capabilities within a configurable retention period (7-35 days), directly supporting your Recovery Point Objective (RPO) by allowing you to restore to any point within that window. This ensures that data loss is minimized to the backup frequency, which is typically every 5-10 minutes for transaction log backups.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (which works for IaaS VMs) with the native geo-replication and failover group capabilities of Azure SQL Managed Instance, or they mistakenly think that a same-region readable secondary or long-term retention alone satisfies business continuity requirements for a regional disaster.

81
MCQhard

A financial services company runs a critical SQL Server database on Azure VMs. They require a failover solution that provides automatic detection of database health issues and automatically fails over to a secondary replica in another Azure region with no data loss and sub-minute RPO. What should they use?

A.Azure SQL Database geo-replication
B.SQL Server Always On Availability Groups with automatic failover
C.Azure SQL Managed Instance failover groups
D.Azure Backup for SQL Server
AnswerB

Always On Availability Groups with automatic failover use synchronous-commit replicas to achieve a zero RPO, while the Windows Server Failover Clustering service triggers failover automatically within seconds if the primary loses connectivity. Since this feature is fully supported on SQL Server on Azure VMs, it directly protects the existing critical instance without converting to PaaS. The listener also enables applications to reconnect transparently after failover.

Why this answer

SQL Server Always On Availability Groups with automatic failover is the correct choice because it supports synchronous data replication between primary and secondary replicas, ensuring zero data loss (RPO=0) and sub-minute RPO. Automatic failover requires a quorum-based health detection mechanism (using Windows Server Failover Clustering) that monitors database health and triggers failover to a secondary replica in another Azure region without manual intervention, meeting the strict RPO and automatic failover requirements.

Exam trap

The trap here is that candidates confuse Azure SQL Database geo-replication (asynchronous, manual failover) with SQL Server Always On Availability Groups (synchronous, automatic failover), assuming all Azure SQL replication options provide automatic failover and zero data loss.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database geo-replication uses asynchronous replication, which cannot guarantee zero data loss (RPO>0) and does not support automatic failover; failover must be initiated manually or via a script. Option C is wrong because Azure SQL Managed Instance failover groups use asynchronous replication across regions, resulting in potential data loss (RPO up to 5 seconds) and do not provide automatic failover; failover requires manual initiation or a forced failover. Option D is wrong because Azure Backup for SQL Server is a backup and restore solution, not a real-time replication or failover mechanism; it cannot achieve sub-minute RPO or automatic failover.

82
MCQmedium

A company runs a stateless web application on Azure VMs. They need to ensure the application remains available in the event of an entire Azure datacenter failure. They want to achieve a 99.99% SLA. Which deployment option should they recommend?

A.A
B.B
C.C
D.D
AnswerB

Placing at least two VM instances across two or more Azure availability zones in the same region gives each zone independent power, cooling, and network paths, so a failure of one entire zone or datacenter leaves the other zone(s) serving traffic. This architecture satisfies the Azure Compute SLA of 99.99% connectivity to at least one instance during monthly uptime, and, because the application is stateless, traffic can be load-balanced between zones with no session-stickiness concerns.

Why this answer

To survive an entire Azure datacenter failure and achieve a 99.99% SLA, the stateless web application must be deployed across at least two Azure Availability Zones within a region. Availability Zones are physically separate datacenters within the same region, each with independent power, cooling, and networking. Deploying VMs in a zone-redundant configuration ensures that if one datacenter fails, the application continues running in another zone, meeting the 99.99% SLA (which requires a minimum of two zones).

Exam trap

The trap here is that candidates often confuse Availability Sets (which protect against rack failures) with Availability Zones (which protect against datacenter failures), leading them to choose an option that only provides 99.95% SLA instead of the required 99.99%.

How to eliminate wrong answers

Option A is wrong because deploying VMs in an Availability Set protects against rack-level failures within a single datacenter, not against an entire datacenter failure, and it offers only a 99.95% SLA. Option C is wrong because deploying VMs in a single Availability Zone still leaves the application vulnerable to a datacenter failure within that zone, and the SLA for a single zone is 99.95%. Option D is wrong because deploying VMs in a single region without zone redundancy does not protect against a full datacenter failure, and the SLA for a single VM is 99.9%.

83
MCQmedium

A company runs a critical application on Azure Kubernetes Service (AKS) in a single region. The application is stateless and uses an Azure SQL Database with active geo-replication for database DR. They need to ensure the AKS cluster can failover to a secondary region with an RTO of 15 minutes and an RPO of 5 seconds for the database. What should they recommend for the AKS cluster?

A.Deploy AKS clusters in two regions and use Azure Traffic Manager to route traffic.
B.Deploy a single AKS cluster with pods spread across availability zones within the region.
C.Use Azure Site Recovery to replicate the AKS cluster to another region.
D.Back up the AKS cluster configuration and container images to a geo-redundant storage account.
AnswerA

Traffic Manager provides DNS-based global load balancing. With AKS clusters in two regions, Traffic Manager can direct users to the healthy region, achieving the required RTO. The database DR is handled separately by active geo-replication.

Why this answer

Deploying AKS clusters in two regions with Azure Traffic Manager enables active-passive or active-active failover. Traffic Manager uses DNS-based routing to direct traffic to the secondary region when the primary fails, meeting the RTO of 15 minutes. The stateless application can be redeployed or scaled in the secondary cluster, while the Azure SQL Database with active geo-replication ensures an RPO of 5 seconds by continuously replicating transactions.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery as a solution for AKS DR, but Site Recovery only supports IaaS VMs, not managed Kubernetes services, making multi-region AKS clusters with Traffic Manager the correct approach.

How to eliminate wrong answers

Option B is wrong because spreading pods across availability zones within a single region protects against zonal failures but not against a regional outage, which is required for cross-region DR. Option C is wrong because Azure Site Recovery does not support replicating AKS clusters; it is designed for IaaS VMs, not managed Kubernetes services. Option D is wrong because backing up cluster configuration and container images to geo-redundant storage provides data backup but does not enable automated failover or meet the RTO of 15 minutes, as manual restoration would be required.

84
MCQeasy

A company runs a web application on Azure VMs in a single region. They need to ensure that if the region fails, the VMs are replicated to another region and can be started automatically. Which Azure service should they use?

A.Azure Site Recovery
B.Azure Backup
C.Azure Traffic Manager
D.Azure Load Balancer
AnswerA

Azure Site Recovery is the correct choice because it replicates Azure VM disks continuously from the primary region to a configured recovery region, enabling a recovery plan that automates failover and VM startup during a regional outage. It maintains near-synchronous RPO and flexible RTO, and you can test failover with isolated networks to validate readiness. It is a true disaster recovery service designed to bring the entire workload up in another region.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs from one region to another. It continuously replicates VM disks to the target region and, upon failover, automatically starts the replicated VMs, meeting the requirement for regional disaster recovery with automated startup.

Exam trap

The trap here is that candidates confuse Azure Backup (which provides point-in-time restores but not automated regional failover) with Azure Site Recovery (which provides continuous replication and automated VM startup), or they mistakenly think Traffic Manager or Load Balancer can handle VM replication and startup when they only manage traffic routing.

How to eliminate wrong answers

Option B (Azure Backup) is wrong because it is designed for backup and restore of VM data to a Recovery Services vault, not for continuous replication and automated startup of VMs in another region; it requires manual restore and does not provide automatic VM startup after failover. Option C (Azure Traffic Manager) is wrong because it is a DNS-based traffic load balancer that routes incoming traffic to healthy endpoints across regions, but it does not replicate VMs or start them automatically after a regional failure. Option D (Azure Load Balancer) is wrong because it distributes traffic within a single region at the transport layer (Layer 4) and does not provide cross-region replication or automated VM startup.

85
MCQmedium

A company runs several Azure virtual machines (VMs) that host SQL Server databases. The databases are stored on data disks attached to the VMs. The company needs to back up the databases and VMs separately. They require application-consistent backups for SQL Server to ensure transactional integrity. Additionally, they need to retain backups for up to 7 years to meet compliance requirements. The solution must minimize administrative overhead and support long-term retention of database backups. Which Azure service or feature should they use for the database backups?

A.Azure Backup for Azure VMs with application-consistent snapshots
B.Azure Backup for SQL Server in Azure VMs
C.Azure Site Recovery
D.Azure Files
AnswerB

Azure Backup for SQL Server in Azure VMs is a SQL-aware backup solution that leverages SQL Server's VDI and VSS integration to deliver true application-consistent backups for each database. It orchestrates full, differential, and transaction log backups, enabling point-in-time restore to any second within the retention window. The service supports granular database-level restore, so you can recover one database without affecting others, and offers retention up to 10 years using the archive tier, comfortably exceeding the 7-year requirement. Its built-in management of backup schedules, retention ranges, and restore operations makes it the only option that fully satisfies the database-specific backup needs.

Why this answer

Azure Backup for SQL Server in Azure VMs is the correct choice because it provides native, application-consistent backups specifically for SQL Server databases running on Azure VMs. It integrates directly with SQL Server VSS writer to ensure transactional integrity, supports long-term retention up to 10 years (exceeding the 7-year requirement), and minimizes administrative overhead by automating backup scheduling, retention management, and point-in-time restore. This service is purpose-built for SQL Server database backups, separate from VM-level backups.

Exam trap

The trap here is that candidates often confuse 'application-consistent snapshots' at the VM level with true SQL Server–aware database backups, overlooking that VM-level backups do not guarantee SQL Server transactional integrity or support database-level restore and long-term retention policies.

How to eliminate wrong answers

Option A is wrong because Azure Backup for Azure VMs with application-consistent snapshots backs up the entire VM (including OS and data disks) but does not provide SQL Server–aware, database-level backup granularity or transactional integrity for SQL Server databases; it only ensures file-system consistency, not application consistency for SQL Server. Option C is wrong because Azure Site Recovery is a disaster recovery solution focused on replication and failover for business continuity, not a backup service for long-term retention or application-consistent database backups. Option D is wrong because Azure Files is a managed file share service for storing files, not a backup solution; it lacks SQL Server–aware backup capabilities, application-consistent snapshot support, and long-term retention policies for databases.

86
Multi-Selectmedium

Your organization has a critical application running on Azure Virtual Machines. You need to design a backup and disaster recovery strategy. Which TWO options should you include in your design to meet a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour? (Choose two.)

Select 2 answers
A.Store data in Azure Files and use Azure File Sync for replication.
B.Implement Azure Site Recovery with replication to a secondary region.
C.Use Azure Traffic Manager to distribute traffic between regions.
D.Configure Azure Backup for daily backups with geo-redundant storage.
E.Enable application-consistent snapshots for the VMs within the replication policy.
AnswersB, E

Azure Site Recovery (ASR) continuously replicates Azure VMs to a secondary region using the Mobility service, capturing data changes at near-synchronous intervals. ASR supports recovery point objectives (RPO) as low as 15 seconds (and up to 15 minutes depending on workload), with recovery time objectives (RTO) of minutes when using Azure's orchestrated failover and recovery plans. This directly satisfies the stated 15-minute RPO and fast RTO, making it the correct primary disaster recovery solution for critical VMs.

Why this answer

Azure Site Recovery (ASR) replicates Azure VMs to a secondary region with configurable recovery points. By enabling application-consistent snapshots within the replication policy, you can achieve an RPO of 15 minutes (snapshot frequency) and an RTO of 1 hour (failover time), meeting the stated requirements.

Exam trap

The trap here is that candidates often confuse Azure Backup (daily snapshots) with Azure Site Recovery (continuous replication), or assume that geo-redundant storage alone satisfies the RPO, when in fact the 15-minute RPO requires near-continuous replication and application-consistent snapshots.

87
MCQeasy

Your company has a hybrid infrastructure with on-premises servers and Azure virtual machines. You need to design a backup strategy that includes on-premises file servers and Azure VMs. The solution must support long-term retention for compliance (7 years) and provide immediate recovery for recent versions. What should you include in the design?

A.Use Azure Storage account snapshots for on-premises files and Azure VM snapshots for VMs.
B.Deploy Azure Backup with the Microsoft Azure Recovery Services (MARS) agent for on-premises and the Azure Backup extension for VMs.
C.Set up Azure File Sync to sync on-premises files to Azure Files, then back up the Azure file shares.
D.Use Azure Site Recovery for both on-premises servers and Azure VMs.
AnswerB

Azure Backup is the correct service because it unifies protection for both sides of the hybrid infrastructure in a single Recovery Services vault. For on-premises files and system state, the MARS agent runs on Windows servers and sends encrypted backups to the vault; for Azure VMs, the Azure Backup extension coordinates with the VM's guest OS to create application-consistent snapshots. Backup policies in Azure Backup allow configurable retention up to 99 years, which easily satisfies the 7-year compliance mandate, and the vault provides centralized monitoring, alerting, and long-term archival across all protected workloads.

Why this answer

Azure Backup with the MARS agent provides long-term retention (up to 99 years) and supports on-premises file servers, while the Azure Backup extension for Azure VMs offers application-consistent snapshots and instant recovery for recent versions. This combination meets the 7-year compliance requirement and immediate recovery needs without additional infrastructure.

Exam trap

The trap here is confusing synchronization (Azure File Sync) or disaster recovery (Azure Site Recovery) with backup, leading candidates to overlook Azure Backup's native support for both on-premises and Azure VMs with long-term retention.

How to eliminate wrong answers

Option A is wrong because Azure Storage account snapshots are not a backup solution; they lack granular file-level recovery, long-term retention policies, and cannot protect on-premises file servers directly. Option C is wrong because Azure File Sync is a synchronization tool, not a backup service; it does not provide point-in-time recovery or retention policies for compliance, and backing up Azure file shares separately still requires a backup solution like Azure Backup. Option D is wrong because Azure Site Recovery is designed for disaster recovery (replication and failover) with short retention (typically up to 72 hours), not for long-term backup retention of 7 years or immediate file-level recovery.

88
MCQhard

A company uses Azure Cosmos DB with a single write region. They need to ensure business continuity with an RPO of 5 seconds and RTO of 1 minute in case of a regional outage. What configuration should they use?

A.Enable multi-region writes with automatic failover
B.Enable automatic failover from a single write region to a read region
C.Deploy Cosmos DB in an availability zone-enabled region
D.Use manual failover to a secondary read region
AnswerA

Enabling multi-region writes with automatic failover makes every participating region a writable replica, so writes can be served by any region and replicated asynchronously with conflict resolution based on LSNs. Because no region is a passive secondary that must be promoted, automatic failover simply redirects traffic without waiting for data catch-up, achieving an RPO of 0 and an RTO of seconds. This is the only option that fully satisfies the requirement for near-zero data loss and automatic cross-region failover.

Why this answer

Multi-region writes with automatic failover allows any Azure Cosmos DB region to accept writes, and if the primary region fails, the SDK automatically routes write requests to the next nearest region. This configuration can achieve an RPO of 0 (no data loss) and an RTO of less than a minute, which exceeds the required RPO of 5 seconds and RTO of 1 minute. The key is that with multi-region writes, there is no need to promote a read region to a write region, eliminating the failover delay and potential data loss.

Exam trap

The trap here is that candidates often assume automatic failover from a single write region is sufficient, but they overlook that the default replication lag guarantee is 5 minutes, which fails the strict RPO requirement, and that multi-region writes are the only way to achieve sub-minute RTO and near-zero RPO for regional outages.

How to eliminate wrong answers

Option B is wrong because enabling automatic failover from a single write region to a read region can result in an RPO of up to 5 minutes (due to the 5-minute replication lag guarantee) and an RTO of up to 15 minutes, which does not meet the required 5-second RPO and 1-minute RTO. Option C is wrong because deploying Cosmos DB in an availability zone-enabled region provides high availability within a single region but does not protect against a full regional outage, so it cannot meet the RPO/RTO requirements for a regional disaster. Option D is wrong because manual failover to a secondary read region requires human intervention, leading to an RTO that is typically minutes to hours, far exceeding the 1-minute RTO, and the RPO can be up to 5 minutes due to replication lag.

89
MCQmedium

A financial services company runs a critical SQL Server database on Azure Virtual Machines. They require a disaster recovery solution with an RPO of less than 15 seconds and an RTO of less than 1 hour. Which technology should they implement?

A.Azure Site Recovery
B.SQL Server Always On Availability Groups
C.Azure Backup for SQL Server
D.Geo-redundant backups
AnswerB

SQL Server Always On Availability Groups is correct because, with synchronous-commit mode, every transaction committed on the primary replica is hardened on a secondary replica before acknowledgment, yielding an RPO of zero. The secondary is kept in a continuously recovered state, and automatic failover with a listener can be completed within seconds to minutes, comfortably satisfying both sub-15-second RPO and sub-1-hour RTO. This is a database-level, application-aware solution that maintains transaction consistency, unlike storage or VM-level alternatives.

Why this answer

SQL Server Always On Availability Groups provide synchronous data replication at the database level, enabling an RPO of less than 15 seconds by committing transactions on both primary and secondary replicas simultaneously. With automatic failover and a secondary replica in a different Azure region, the RTO can be under 1 hour, meeting the critical requirements for a SQL Server workload on Azure VMs.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery's VM-level replication with database-level replication, assuming it can meet low RPO/RTO for SQL Server, but it cannot achieve sub-15-second RPO because it replicates at the hypervisor level with inherent lag.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery replicates entire VMs at the hypervisor level, not the database level, and its typical RPO is around 30 seconds to several minutes, failing to meet the sub-15-second requirement. Option C is wrong because Azure Backup for SQL Server is a backup solution, not a real-time replication or disaster recovery technology; it provides point-in-time restores with RPOs measured in minutes or hours, not seconds. Option D is wrong because geo-redundant backups (e.g., GRS) offer recovery points that are typically hours old (due to backup schedules and replication lag), and they require a full restore process, resulting in RTOs far exceeding 1 hour.

90
MCQhard

Refer to the exhibit. You are reviewing an Azure Site Recovery replicated item for a VM. The replication health is Normal, and the last recovery point is at 10:30 AM. The primary region experiences a failure at 10:35 AM. You initiate a failover at 10:40 AM. What is the maximum potential data loss?

A.5 minutes of data
B.15 minutes of data
C.0 minutes of data
D.10 minutes of data
AnswerA

The recovery point created at 10:30 is the most recent point that can be used for failover. Since the failure occurred at 10:35, all changes made between 10:30 and 10:35 are not replicated to the recovery point and are therefore lost. This matches Azure Site Recovery's typical 5-minute Recovery Point Objective (RPO) for asynchronous replication, so the maximum data loss is exactly the 5-minute gap between the last consistent recovery point and the failure time.

Why this answer

The last recovery point was at 10:30 AM, and the failover was initiated at 10:40 AM. Since the failure occurred at 10:35 AM, any data written between 10:30 AM and 10:35 AM (5 minutes) that was not yet replicated to the recovery point is lost. Azure Site Recovery replicates asynchronously, so the maximum potential data loss equals the time between the last successful recovery point and the failure event.

Exam trap

The trap here is confusing the time between the last recovery point and the failover initiation (10 minutes) with the actual data loss window, which is bounded by the failure time, not the failover time.

How to eliminate wrong answers

Option B (15 minutes) is wrong because it incorrectly assumes data loss from the last recovery point at 10:30 AM to the failover at 10:40 AM, but the failure at 10:35 AM stops new writes, so only 5 minutes of unreplicated data exists. Option C (0 minutes) is wrong because Azure Site Recovery uses asynchronous replication, not synchronous, so there is always a potential for data loss between recovery points. Option D (10 minutes) is wrong because it miscalculates the window as the time from the last recovery point (10:30 AM) to the failover initiation (10:40 AM), ignoring that the failure at 10:35 AM halts data generation.

91
MCQhard

An Azure SQL Database supports a customer-facing application. The company requires automatic failover to a paired region with minimal administrative action. Which feature should be recommended?

A.Zone-redundant storage only
B.Auto-failover group
C.SQL elastic pool only
D.Azure Backup vault only
AnswerB

Auto-failover groups are the correct solution because they implement geo-replication between an Azure SQL Database in a primary region and a readable secondary replica in a different Azure region. Through a logical DNS-based listener endpoint, the service automatically redirects application connections to the secondary during a regional outage, enabling seamless failover with minimal downtime. This directly satisfies the cross-region availability requirement.

Why this answer

Auto-failover groups in Azure SQL Database enable automatic, synchronous or asynchronous replication of databases to a paired region, with a built-in listener endpoint that handles transparent failover. This meets the requirement for minimal administrative action because failover can be triggered automatically based on the built-in grace period and health monitoring, without manual intervention.

Exam trap

The trap here is that candidates often confuse zone-redundant storage (which protects against zone failures within a region) with cross-region failover, or mistakenly think an elastic pool provides disaster recovery capabilities when it is only a management unit for performance and cost.

How to eliminate wrong answers

Option A is wrong because zone-redundant storage only protects against an availability zone failure within a single region, not a full regional outage, and does not provide automatic failover to a paired region. Option C is wrong because an SQL elastic pool is a resource management construct for scaling and managing multiple databases within a single server, not a disaster recovery or failover feature. Option D is wrong because Azure Backup vault is used for long-term backup retention and point-in-time restore, not for automatic failover or continuous replication to a paired region.

92
MCQmedium

A company runs a critical SQL Server database on Azure Virtual Machines in a single region. They need a disaster recovery solution across regions with a recovery point objective (RPO) of zero. The database is update-intensive with frequent writes. Which configuration should they implement?

A.SQL Server Always On Availability Group with asynchronous commit.
B.SQL Server Always On Availability Group with synchronous commit across regions.
C.Azure Site Recovery to another region.
D.Deploy the VMs in a different availability zone within the same region.
AnswerB

Synchronous commit ensures all transactions are committed on both the primary and secondary replicas before acknowledging the commit to the application. If configured across regions, this provides zero data loss (RPO=0). But network latency can affect write performance.

Why this answer

SQL Server Always On Availability Group with synchronous commit across regions ensures zero data loss because transactions are committed on both the primary and secondary replicas before the primary acknowledges the commit. This meets the RPO of zero, even though it introduces latency due to cross-region synchronization. For an update-intensive workload, synchronous commit is the only option that guarantees no data loss at the cost of increased write latency.

Exam trap

The trap here is that candidates often choose asynchronous commit (Option A) thinking it is sufficient for DR, but the RPO of zero explicitly requires synchronous commit, despite the performance trade-off.

How to eliminate wrong answers

Option A is wrong because asynchronous commit does not guarantee zero data loss; it allows transactions to be committed on the primary without waiting for the secondary, so the secondary can lag behind, violating the RPO of zero. Option C is wrong because Azure Site Recovery replicates at the VM level using crash-consistent or app-consistent snapshots, which cannot achieve an RPO of zero for a high-write database due to replication intervals and potential data loss between snapshots. Option D is wrong because deploying in different availability zones within the same region does not provide cross-region disaster recovery; it only protects against zonal failures within the same region, not a regional outage.

93
MCQhard

A company runs a critical application on Azure VMs in a single region. They need to implement disaster recovery using Azure Site Recovery (ASR) with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The database VMs have a very high data change rate, and the company wants to minimize replication costs. They also need to ensure that in the recovery plan, database VMs start before application VMs, and a script updates DNS records after failover. Which combination of ASR configurations should they use?

A.Enable multi-VM consistency groups and use recovery plans with manual ordering.
B.Enable app-consistent replication and use deployment plans with pre- and post-actions.
C.Enable replication with high churn protection and use recovery plans with availability groups.
D.Enable crash-consistent replication and use recovery plans with pre- and post-actions.
AnswerD

Crash-consistent replication in Azure Site Recovery copies all disks without invoking VSS, avoiding application-level snapshot overhead while still generating recovery points at the OS level; for this critical workload, those recovery points meet the stipulated RPO and reduce storage and I/O costs. A recovery plan groups VMs into ordered clauses, and you add pre-actions to enforce startup order — for example, starting the database VM before the web VM — and post-actions to run PowerShell scripts after failover to complete application configuration. This combination provides the required automation with the least expensive replication mode, so it is the correct answer.

Why this answer

Crash-consistent replication is the most cost-effective ASR option for VMs with high data change rates, as it replicates only the data that has changed since the last snapshot without requiring application-level consistency. The RPO of 15 minutes and RTO of 2 hours can be met with crash-consistent replication, and recovery plans with pre- and post-actions allow you to specify that database VMs start before application VMs and run a script to update DNS records after failover.

Exam trap

The trap here is that candidates often assume app-consistent replication is always required for database VMs, but the question explicitly prioritizes minimizing replication costs and only requires a 15-minute RPO, making crash-consistent replication the correct choice despite the high data change rate.

How to eliminate wrong answers

Option A is wrong because multi-VM consistency groups are used to ensure crash-consistent or app-consistent replication across multiple VMs, but they do not address the need to minimize replication costs for high-churn VMs; they also do not provide the ability to run scripts after failover. Option B is wrong because app-consistent replication requires application-level snapshots (e.g., using VSS on Windows), which increases replication overhead and cost, and is not necessary for meeting a 15-minute RPO with high data change rates; deployment plans are not a valid ASR feature. Option C is wrong because 'high churn protection' is not a standard ASR configuration; ASR does not have a specific setting for high churn, and availability groups are a SQL Server feature, not an ASR recovery plan feature.

94
MCQeasy

Your company has an Azure subscription with a single virtual network. You need to design a solution to back up Azure VMs to meet a 7-day retention policy. The backup data must be stored in a separate region for compliance. What should you use?

A.Azure Backup with cross-region restore (CRR) enabled
B.Azure Site Recovery with replication to a secondary region
C.Azure File Share snapshots stored in a different region
D.Azure Backup with default geo-redundant storage (GRS) in the same region
AnswerA

Azure Backup with cross-region restore (CRR) enabled is the correct choice because it explicitly copies backup snapshots and vault-tier recovery points to a paired secondary region. With CRR, you can restore a VM from the secondary region's copy even if the entire primary region is inaccessible, providing true geo-resiliency. This feature must be enabled during the Azure Recovery Services vault creation and works alongside GRS, granting independent read access to the replicated backup data in the paired region.

Why this answer

Azure Backup with cross-region restore (CRR) enabled is the correct solution because it allows you to store backup data in a secondary Azure paired region, meeting the compliance requirement for separate region storage. CRR works by replicating the backup data from the default geo-redundant storage (GRS) in the primary region to the paired region, and then enabling you to restore VMs in that secondary region. With a 7-day retention policy, CRR supports restoring from the recovery point within that window, ensuring compliance without additional infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Backup's default GRS with cross-region restore, assuming that GRS alone allows restoring in the secondary region, but without CRR enabled, the secondary region copy is only for durability and cannot be used for restore operations.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery is a disaster recovery solution designed for replication and failover of VMs to a secondary region, not for backup with retention policies; it does not provide point-in-time restore capabilities for a 7-day retention window. Option C is wrong because Azure File Share snapshots are for file-level backup and are stored within the same region as the file share; they cannot be natively stored in a different region without manual copying, which violates the compliance requirement. Option D is wrong because default geo-redundant storage (GRS) in the same region stores backup data in the same primary region with replication to a secondary region only for durability, but cross-region restore (CRR) is not enabled by default; without CRR, you cannot restore VMs in the secondary region, failing the compliance requirement.

95
MCQeasy

A company runs a critical application on Azure virtual machines (VMs) in the West US region. They need a disaster recovery solution that replicates the VMs to East US with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The application consists of multiple VMs, and the company needs to be able to fail over a single VM without impacting others during an actual disaster. They also want to periodically test the recovery process without affecting the production environment. Which Azure Site Recovery feature should they use to enable non-disruptive testing?

A.Recovery Plans
B.Planned failover
C.Test failover
D.Network mapping
AnswerC

Test failover performs a full validation of replicated VM images by booting them in an isolated virtual network using a selectable recovery point, without disturbing ongoing replication or production traffic. It requires no source VM shutdown and can be run repeatedly for compliance and disaster-recovery drills. This isolated copy allows you to verify application startup and network dependencies exactly as they would behave in a real failover, making it the correct feature for non-disruptive testing.

Why this answer

Test failover (Option C) is the correct feature because it allows you to validate your disaster recovery process by creating an isolated copy of your replicated VMs in a separate test network, without impacting the ongoing replication or the production environment. This directly meets the requirement for periodic, non-disruptive testing while maintaining the RPO of 15 minutes and RTO of 2 hours.

Exam trap

The trap here is that candidates often confuse 'Test failover' with 'Planned failover' or 'Recovery Plans,' mistakenly thinking that any failover action must impact production, when in fact Test failover is specifically designed to be isolated and non-disruptive.

How to eliminate wrong answers

Option A is wrong because Recovery Plans are used to orchestrate the failover sequence of multiple VMs and run custom scripts, but they do not provide a mechanism for non-disruptive testing; they are executed during actual failover or test failover, not as a testing feature themselves. Option B is wrong because Planned failover is designed for zero-data-loss migration or maintenance scenarios where both sites are healthy and no data loss is tolerated, but it requires stopping production VMs and is not a testing mechanism—it disrupts production. Option D is wrong because Network mapping defines how source and target networks correspond for failover, but it is a configuration prerequisite, not a feature for executing a non-disruptive test.

96
MCQmedium

A company runs a file server on Azure VMs using Windows Server. The server stores business-critical documents. You need to design a backup strategy that meets a recovery point objective (RPO) of 1 hour and recovery time objective (RTO) of 4 hours. The solution must be cost-effective. Which backup solution should you use?

A.Azure Site Recovery
B.Azure Backup for Azure Blobs
C.Azure Backup for Azure VMs
D.Azure File Sync
AnswerC

Azure Backup for Azure VMs is the correct choice because it provides true backup functionality at the VM level, with policy-based scheduling (e.g., once or twice daily) and customizable retention for long-term archival. It leverages the Volume Shadow Copy Service (VSS) for Windows VMs to produce application-consistent snapshots, and also takes crash-consistent snapshots, enabling reliable restore of the entire VM or individual files. This directly covers the file server's data and system state, meeting the requirement for backup with a recovery point objective.

Why this answer

Azure Backup for Azure VMs provides application-consistent backups for Windows Server VMs, supporting RPOs as low as 1 hour with frequent backup policies and RTOs within 4 hours by restoring to a new VM or using instant restore. It is cost-effective because it uses incremental backups and only charges for storage consumed, without the replication overhead of Site Recovery.

Exam trap

The trap here is that candidates confuse Azure Site Recovery (a replication/DR tool) with Azure Backup (a backup tool), leading them to choose Site Recovery for a simple backup requirement, which is cost-prohibitive and not designed for point-in-time recovery with hourly RPOs.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery is a disaster recovery solution designed for replication and failover with RPOs of seconds to minutes and RTOs of minutes, which is overkill and more expensive for a backup-only requirement. Option B is wrong because Azure Backup for Azure Blobs is designed for protecting blob data (e.g., block blobs, append blobs) and cannot back up a Windows Server VM running a file server. Option D is wrong because Azure File Sync is a synchronization tool that keeps on-premises file servers in sync with Azure file shares, not a backup solution; it does not provide point-in-time recovery or meet RPO/RTO requirements.

97
MCQmedium

You are reviewing a PowerShell script for Azure SQL Database. The exhibit shows the script that sets backup retention. What is the effect of running this script?

A.It sets the short-term backup retention to 7 days, enabling point-in-time restore within that period.
B.It enables geo-redundant backups for the database.
C.It sets the long-term retention (LTR) backup policy to 7 days.
D.It increases the backup retention from 7 to 35 days.
AnswerA

This is the correct interpretation: the cmdlet being reviewed is Set-AzSqlDatabaseBackupShortTermRetentionPolicy (or equivalent), which explicitly configures the short-term backup retention policy for an Azure SQL database. Setting the property to 7 days means automated backups (full, differential, and transactional log backups) are retained for 7 days, and point-in-time restore (PITR) can be performed to any point within that window. The default is 7 days, so this is a direct, deliberate setting of the PITR window. The parameter range for short-term retention is 1–35 days, and 7 is within that range.

Why this answer

The script uses the `Set-AzSqlDatabaseBackupShortTermRetentionPolicy` cmdlet with `-RetentionDays 7`, which configures the short-term backup retention period for point-in-time restore (PITR) to 7 days. This allows restoring the database to any point within the last 7 days, as automated backups are retained for that duration.

Exam trap

The trap here is confusing short-term retention (PITR) with long-term retention (LTR) or geo-redundancy, as candidates may misread the cmdlet name or assume any retention setting applies to all backup types.

How to eliminate wrong answers

Option B is wrong because geo-redundant backups are enabled via the `-BackupStorageRedundancy` parameter (e.g., `Geo`) in the database creation or update cmdlet, not through the short-term retention policy cmdlet. Option C is wrong because long-term retention (LTR) backup policy is configured using the `Set-AzSqlDatabaseBackupLongTermRetentionPolicy` cmdlet, not the short-term retention cmdlet shown. Option D is wrong because the script sets retention to 7 days, not increases it from 7 to 35 days; the value 7 is the target retention, not a delta.

98
MCQeasy

A company has a disaster recovery plan that requires testing failover of Azure VMs regularly without impacting the production environment. Which feature of Azure Site Recovery should they use?

A.Planned failover
B.Test failover
C.Unplanned failover
D.Failback
AnswerB

Test failover is the correct choice because it creates an isolated, non-production replica of the protected environment, allowing validation of recovery procedures without impacting live systems. It provides a safe, reversible mechanism to verify that recovery points and recovery time objectives can be met, making it the standard method for disaster recovery testing.

Why this answer

Test failover (Option B) is the correct feature for validating disaster recovery readiness without affecting the production environment. Azure Site Recovery's test failover creates an isolated copy of the replicated VMs in a separate virtual network, allowing you to run validation exercises, perform application testing, and verify recovery plans without any impact on the production VMs or ongoing replication. This ensures that the failover process works correctly while maintaining production continuity.

Exam trap

The trap here is that candidates often confuse 'test failover' with 'planned failover' because both involve controlled processes, but planned failover is intended for actual migration or maintenance and does impact production by shutting down source VMs, whereas test failover is purely for validation with zero production impact.

How to eliminate wrong answers

Option A (Planned failover) is wrong because it is used for migrating VMs from a primary to a secondary region with zero data loss, typically during planned maintenance or migration, and it does impact the production environment by shutting down source VMs. Option C (Unplanned failover) is wrong because it is designed for actual disaster scenarios where the primary site is unavailable; it initiates failover without prior synchronization and directly affects production by making the replica VMs the new primary, which would disrupt operations. Option D (Failback) is wrong because it is the process of returning workloads to the primary site after a failover has occurred, and it assumes the production environment has already been impacted by a previous failover event.

99
MCQeasy

A company wants to ensure that their Azure SQL Database can continue to serve read-write traffic if the primary region becomes unavailable. They require minimal data loss. What should they implement?

A.Use Azure Backup with cross-region restore
B.Deploy the database across two Availability Zones
C.Configure an auto-failover group with a secondary in another region
D.Read-scale replicas in the same region
AnswerC

An auto-failover group pairs a read-write primary database with a readable secondary server in another Azure region and exposes a single listener endpoint that automatically points to the current primary. The service continuously replicates data via active geo-replication and can automatically initiate failover when the primary becomes unhealthy, with a configurationurable grace period and forced/failover options. Because the secondary can be promoted to primary, this option preserves database availability even during a full regional outage.

Why this answer

An auto-failover group with a secondary in another region provides continuous read-write traffic capability during a regional outage with minimal data loss. The failover group uses asynchronous replication with a configurable grace period (default 1 hour) to balance performance and data loss, and upon failover, the secondary becomes the new primary with the same connection string, ensuring application transparency.

Exam trap

The trap here is that candidates confuse high availability within a region (Availability Zones) with disaster recovery across regions (geo-replication), or they mistakenly think read-scale replicas can handle write traffic during failover.

How to eliminate wrong answers

Option A is wrong because Azure Backup with cross-region restore is designed for point-in-time recovery of a database, not for real-time failover; it involves hours of recovery time and does not serve live read-write traffic during an outage. Option B is wrong because deploying across two Availability Zones protects only against zonal failures within the same region, not against a full regional outage; it cannot serve traffic if the entire primary region becomes unavailable. Option D is wrong because read-scale replicas in the same region are read-only and cannot accept write traffic; they are used for offloading read workloads, not for failover or write continuity.

100
Drag & Dropmedium

Drag and drop the steps to implement Azure Backup for an Azure virtual machine into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for implementing Azure Backup for an Azure VM is: first create a Recovery Services vault, then define a backup policy that specifies the backup schedule and retention, then assign the VM to the vault (which associates the VM with the vault and policy), then enable backup (which starts the protection), and finally test the backup to ensure it works correctly. This order ensures that each step has the necessary prerequisites completed before moving forward.

101
MCQeasy

A company deploys a critical multi-tier application on Azure VMs. The application includes a database tier that must be recovered to the same point in time as the application tier after a disaster. They use Azure Site Recovery (ASR) for disaster recovery to a secondary region. They also need to run a custom script after failover to update connection strings. Which ASR feature should they use?

A.Recovery plans with pre-actions and post-actions
B.Replication policies with application-consistent snapshots
C.Multi-VM consistency groups
D.Azure Backup with cross-region restore
AnswerA

Recovery plans with pre-actions and post-actions are the correct answer because Azure Site Recovery's recovery plans provide orchestrated failover beyond simple replication. They allow you to group VMs into fault domains and specify a sequence for failover, ensuring critical tiers come online before dependent ones. Pre-actions and post-actions execute custom scripts or Azure Automation runbooks automatically at specific points in the sequence, enabling tasks such as changing connection strings, updating DNS, or health checks. This combination of ordering and automated script execution is exactly what the company needs to recover a multi-tier application cohesively.

Why this answer

Recovery plans in Azure Site Recovery allow you to define pre-actions and post-actions, which can run custom scripts (e.g., PowerShell) after failover to update connection strings. This ensures the application tier can connect to the recovered database tier, meeting the requirement for a custom script execution after failover. The other options do not provide the ability to run custom scripts as part of the failover sequence.

Exam trap

The trap here is that candidates often confuse multi-VM consistency groups (which ensure crash-consistent recovery across VMs) with the ability to run post-failover scripts, but only recovery plans provide the orchestration layer for custom actions like updating connection strings.

How to eliminate wrong answers

Option B is wrong because replication policies with application-consistent snapshots ensure data consistency for crash-consistent recovery but do not allow running custom scripts after failover. Option C is wrong because multi-VM consistency groups ensure all VMs in a group fail over to a consistent point in time, but they do not provide a mechanism to execute post-failover scripts. Option D is wrong because Azure Backup with cross-region restore provides backup-based recovery, not real-time replication, and does not support custom script execution as part of a failover orchestration.

102
MCQhard

You manage a globally distributed application using Azure Cosmos DB. You need to design a business continuity strategy that ensures zero data loss and automatic failover in case of a regional outage. The application must continue to serve reads and writes during a region failure. What should you recommend?

A.Use Azure Cosmos DB accounts with a single write region and enable service-managed failover.
B.Use Azure Cosmos DB accounts with multi-region writes but disable automatic failover and rely on manual failover.
C.Configure single-region writes with strong consistency and enable automatic failover.
D.Configure multi-region writes with eventual consistency and enable automatic failover.
AnswerD

Multi-region writes with automatic failover provide zero data loss and continuous availability for both reads and writes.

Why this answer

Azure Cosmos DB multi-region writes with automatic failover ensure zero data loss and continuous availability for both reads and writes during a regional outage. Writes are accepted in multiple regions and asynchronously replicated, eliminating a single point of failure. Option A is incorrect because a single write region with service-managed failover may lose writes that were not replicated before the failover.

Option B is incorrect because disabling automatic failover requires manual intervention, which does not meet the automatic failover requirement and can still result in data loss. Option C is incorrect because single-region writes, even with strong consistency, will lose writes if the region fails before replication completes.

103
Multi-Selectmedium

You are designing a disaster recovery solution for a multi-tier web application on Azure VMs. The solution must meet an RPO of 15 minutes and an RTO of 1 hour. The application includes a SQL Server database. Which THREE actions should you take? (Choose THREE.)

Select 3 answers
A.Use Azure Backup for the SQL Server database with 1-hour backup frequency.
B.Use Azure Premium SSD managed disks for the VMs to ensure low latency replication.
C.Configure SQL Server Always On Availability Groups with synchronous commit between regions.
D.Deploy read-scale replicas of the SQL Server in the secondary region.
E.Configure Azure Site Recovery to replicate the web and app tier VMs to a secondary region.
AnswersB, C, E

Azure Premium SSD managed disks deliver single-digit millisecond latencies and high IOPS, which are essential for sustaining synchronous or continuous replication traffic between the primary and secondary regions without storage-level bottlenecks. When VMs are replicated via Azure Site Recovery or contain SQL Server transaction log replicas, the underlying disk performance directly influences replication lag; Premium SSD ensures that I/O operations are not throttled, helping maintain an RPO below 15 minutes. This makes Premium SSD a supported and recommended configuration for I/O-sensitive replication workloads.

Why this answer

Azure Premium SSD managed disks provide low-latency, high-throughput storage that is essential for synchronous replication in SQL Server Always On Availability Groups. The synchronous commit mode requires fast disk I/O to avoid transaction delays, and Premium SSDs meet the sub-millisecond latency needed to achieve an RPO of 15 minutes and RTO of 1 hour across regions.

Exam trap

The trap here is that candidates often confuse Azure Backup's 1-hour backup frequency with the ability to meet a 15-minute RPO, not realizing that backup frequency is the interval between backups, not the recovery point granularity, and that synchronous replication (Always On) is required for sub-hour RPOs.

104
MCQhard

Refer to the exhibit. You are deploying an ARM template to configure backup for an Azure Web App. The deployment fails with an error: 'The resource 'Microsoft.Web/sites/config' cannot be nested under a parent resource that is not deployed.' What is the MOST LIKELY cause?

A.The parent web app resource is not defined in the template
B.The storageAccountUrl property uses a reference() that cannot be resolved
C.The apiVersion '2022-03-01' is not supported for this resource type
D.The backup schedule frequency interval is invalid
AnswerA

In an ARM template, a child resource such as Microsoft.Web/sites/config/backup cannot be deployed unless its parent web app resource (Microsoft.Web/sites) is either defined in the same template or already exists in the resource group. Since the template omits the parent web app resource, Azure Resource Manager cannot resolve the resource identifier and the deployment fails with a validation error. To fix it, you must include the web app in the template and add a dependsOn relationship, or use an existing resource reference with the proper scope.

Why this answer

The error indicates that the ARM template is trying to define a child resource (Microsoft.Web/sites/config) under a parent web app that has not been deployed within the same template. In ARM templates, nested resources require the parent resource to be defined in the same template, typically with a dependsOn element or by nesting the child resource inside the parent's resources array. Since the parent web app is missing from the template, the deployment fails because the resource manager cannot resolve the parent scope.

Exam trap

The trap here is that candidates may confuse a missing parent resource with other common ARM deployment errors, such as invalid API versions or function resolution issues, rather than recognizing the specific nesting constraint error message.

How to eliminate wrong answers

Option B is wrong because a reference() function that cannot be resolved would produce a different error, such as 'Unable to evaluate the template function', not a nesting error. Option C is wrong because apiVersion '2022-03-01' is a valid and supported version for Microsoft.Web/sites/config; the error is unrelated to API version support. Option D is wrong because an invalid backup schedule frequency interval would cause a validation error on the backup configuration itself, not a parent-child nesting error.

105
MCQhard

A company runs a critical SQL Server database on an Azure virtual machine. They need a high-availability solution within a single region that provides automatic failover, zero data loss (synchronous replication), and support read-only routing for reporting workloads. Which solution should they implement?

A.SQL Server Always On Availability Group with synchronous replication across availability zones
B.SQL Server Always On Failover Cluster Instance (FCI) with shared disks
C.Azure SQL Database Managed Instance with active geo-replication
D.Azure SQL Database with active geo-replication
AnswerA

An Always On Availability Group is correct because it replicates the database at the data-page level to a secondary replica using synchronous commit, so every transaction is hardened on both replicas before being acknowledged and automatic failover can occur with zero data loss. Because the secondary replica maintains a separate copy of the database, it can be configured as readable, allowing reporting and backup workloads to be offloaded from the primary. Deployed across availability zones, this protects against complete zone failure while remaining fully compatible with SQL Server on Azure VMs.

Why this answer

SQL Server Always On Availability Group with synchronous replication across availability zones meets all requirements: it provides automatic failover, zero data loss through synchronous commit mode, and supports read-only routing by directing reporting workloads to readable secondary replicas. This solution operates within a single Azure region using availability zones for high availability.

Exam trap

The trap here is that candidates confuse synchronous replication (used in Always On Availability Groups) with asynchronous replication (used in geo-replication), and fail to recognize that read-only routing is a feature exclusive to Availability Groups, not Failover Cluster Instances or geo-replication solutions.

How to eliminate wrong answers

Option B is wrong because a Failover Cluster Instance (FCI) with shared disks does not support read-only routing for reporting workloads; FCI provides a single instance with no readable secondary replicas. Option C is wrong because Azure SQL Database Managed Instance with active geo-replication uses asynchronous replication, which cannot guarantee zero data loss, and it is designed for cross-region disaster recovery, not single-region high availability. Option D is wrong because Azure SQL Database with active geo-replication also uses asynchronous replication, resulting in potential data loss, and it is a cross-region solution, not a single-region high-availability solution.

106
MCQmedium

A company runs a critical SQL Server database on an Azure virtual machine. They need a backup strategy that supports point-in-time restore down to the second and long-term retention of backups for 7 years to meet compliance. They want to offload backup management to Azure. Which backup solution should they use?

A.Azure Backup for SQL Server on Azure VM
B.Azure Site Recovery
C.SQL Server managed backup to Azure
D.Azure Disk Backup
AnswerA

Azure Backup for SQL Server on Azure VM is a fully managed backup service that integrates with the SQL Server IaaS Agent Extension, automating full, differential, and transaction log backups. It supports point-in-time restore with log backups taken every 15 minutes, and offers long-term retention policies for up to 10 years, meeting both operational recovery and compliance requirements. The centralized monitoring, alerting, and cross-subscription management capabilities make it the ideal choice for a critical SQL database.

Why this answer

Azure Backup for SQL Server on Azure VM provides native integration that supports point-in-time restore down to the second for SQL Server databases and allows configuring long-term retention (LTR) for up to 10 years, meeting the 7-year compliance requirement. It offloads backup management to Azure by automating backup schedules, retention policies, and restore operations without requiring manual scripting or third-party tools.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with backup, or assume SQL Server managed backup to Azure provides the same integrated point-in-time and long-term retention capabilities as Azure Backup, when in fact Azure Backup offers a fully managed, portal-integrated solution with native SQL Server awareness.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery is a disaster recovery solution that replicates entire VMs for failover, not a backup service; it does not support point-in-time restore for SQL Server databases or long-term retention for compliance. Option C is wrong because SQL Server managed backup to Azure is a feature that manages backups to Azure Blob storage but requires manual configuration of retention policies and does not offer native point-in-time restore down to the second or integrated long-term retention management within the Azure portal. Option D is wrong because Azure Disk Backup provides crash-consistent backups of managed disks at the VM level, not application-consistent backups for SQL Server, and cannot perform point-in-time restore for database transactions or log backups.

107
MCQmedium

A company has an on-premises Hyper-V environment with 20 virtual machines running various workloads. They want to use Azure as a disaster recovery site. The required recovery point objective (RPO) is 15 minutes, and the recovery time objective (RTO) is 2 hours. They want to automate failover and failback. Which Azure service should they use?

A.Azure Site Recovery
B.Azure Migrate
C.Azure Backup
D.Azure Recovery Services Vault
AnswerA

Azure Site Recovery is the only option that provides continuous, near-synchronous replication of Hyper-V VMs to Azure, with RPOs as low as 30 seconds and the ability to meet a 15-minute RPO. It uses the Azure Site Recovery Provider installed on the Hyper-V host and the Microsoft Recovery Services Agent, replicating VHDs to Azure storage while enabling orchestrated test failovers, planned/unplanned failovers, and failback. This is true disaster recovery, not backup or migration.

Why this answer

Azure Site Recovery (ASR) is the correct service because it provides orchestrated replication, failover, and failback for Hyper-V VMs to Azure as a DR site. It supports the required RPO of 15 minutes (using near-synchronous replication with change tracking) and RTO of 2 hours (via automated recovery plans), and it natively automates both failover and failback processes without additional scripting.

Exam trap

The trap here is that candidates confuse the Recovery Services Vault (a storage container) with the actual DR service (Azure Site Recovery), or they mistakenly think Azure Backup can meet low RPO/RTO requirements for disaster recovery when it is designed for backup, not replication with automated failover.

How to eliminate wrong answers

Option B (Azure Migrate) is wrong because it is designed for discovery, assessment, and migration of on-premises workloads to Azure, not for ongoing disaster recovery replication or automated failover/failback. Option C (Azure Backup) is wrong because it provides backup-based recovery with typical RPOs of 12-24 hours and RTOs measured in hours to days, and it does not support automated failover or failback orchestration. Option D (Azure Recovery Services Vault) is wrong because it is a storage container that holds backup data and replication settings, not a service that performs replication, failover, or failback; it is the underlying vault used by both Azure Backup and Azure Site Recovery, but the question asks for the service that automates DR, which is ASR.

108
MCQmedium

A company uses Azure Kubernetes Service (AKS) to run a containerized microservices application. They need a disaster recovery solution that can automatically fail over to a secondary region if the primary region fails. The solution must minimize data loss for stateful workloads. What should they implement?

A.Azure Backup for AKS
B.Azure Front Door
C.Azure Traffic Manager
D.Azure Site Recovery
AnswerD

Azure Site Recovery provides continuous replication of virtual machines and their associated data disks across Azure regions. This technical mechanism ensures a low Recovery Point Objective (RPO), directly addressing the need to minimise data loss for stateful workloads running within AKS by replicating their underlying persistent storage. Furthermore, Site Recovery orchestrates automated failover to a secondary region, satisfying the requirement for automatic disaster recovery.

Why this answer

Azure Site Recovery (ASR) is the correct choice because it provides orchestrated replication and failover for Azure VMs and physical workloads, including stateful containers running on AKS. ASR can replicate persistent volumes and application data to a secondary region, enabling automated failover with minimal data loss by using crash-consistent or app-consistent recovery points.

Exam trap

The trap here is that candidates often confuse traffic routing services (Azure Front Door or Traffic Manager) with actual disaster recovery replication, overlooking that stateful workloads require data replication, not just traffic redirection.

How to eliminate wrong answers

Option A is wrong because Azure Backup for AKS only provides backup and restore capabilities, not automated failover to a secondary region; it is designed for point-in-time recovery, not continuous replication. Option B is wrong because Azure Front Door is a global load balancer and application delivery controller that routes HTTP/HTTPS traffic, but it does not replicate or fail over stateful workloads or persistent data. Option C is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that can redirect traffic to a secondary region, but it does not handle data replication or stateful workload failover; it only manages traffic routing at the DNS level.

109
MCQmedium

A company has several Azure Virtual Machines running Windows Server with critical applications. They need to back up these VMs to a secondary Azure region to protect against regional disasters. The backup must be application-consistent and support file-level restore. Which solution should they implement?

A.Azure Backup with geo-redundant storage (GRS) in a Recovery Services vault
B.Azure Site Recovery
C.Azure Snapshot of managed disks stored in a different region
D.Azure Managed Disk with incremental snapshots and manual cross-region copy
AnswerA

Azure Backup with GRS replicates backup data to a paired secondary region, satisfying the regional disaster requirement. Volume Shadow Copy Service (VSS) provides application-consistent snapshots of Windows Server workloads, and the Recovery Services vault supports file-level recovery from those snapshots.

Why this answer

Azure Backup with geo-redundant storage (GRS) in a Recovery Services vault is the correct solution because it provides application-consistent backups of Windows Server VMs using the Volume Shadow Copy Service (VSS) to ensure data integrity, and it supports file-level restore by allowing you to mount the backup as a drive to recover individual files. The GRS option replicates backup data to a paired secondary region, meeting the disaster recovery requirement without additional manual steps.

Exam trap

The trap here is that candidates confuse Azure Site Recovery (a replication/failover tool) with Azure Backup (a backup/restore tool), or assume that crash-consistent snapshots (Options C and D) are sufficient for application consistency and file-level restore, which they are not.

How to eliminate wrong answers

Option B (Azure Site Recovery) is wrong because it is designed for replication and failover of VMs for disaster recovery, not for backup—it does not support file-level restore from backup snapshots and is not a backup solution. Option C (Azure Snapshot of managed disks stored in a different region) is wrong because snapshots are crash-consistent, not application-consistent, and they do not support file-level restore natively; you would need to create a new disk from the snapshot to access files. Option D (Azure Managed Disk with incremental snapshots and manual cross-region copy) is wrong because incremental snapshots are also crash-consistent and require manual cross-region copy, which adds complexity and does not guarantee application consistency or built-in file-level restore capabilities.

110
MCQhard

A company runs a critical application on Azure VMs in the West US region. They want to protect against a regional disaster by replicating VMs to East US using Azure Site Recovery. They have both managed and unmanaged disks. They need to ensure that after failover, the recovery VMs are automatically placed in a specific availability set to support the application's multi-tier architecture. Additionally, they want to minimize downtime during planned failover. Which configuration should they use?

A.Configure a recovery plan that includes the VMs and specifies the target availability set and failover order
B.Set the target availability set in each VM's replication settings individually without a recovery plan
C.Use Azure Traffic Manager to route traffic to the secondary region after manual failover
D.Enable consistency groups across the VMs using a replication policy
AnswerA

A recovery plan in Azure Site Recovery groups all VMs into a single orchestrated failover unit, letting you specify the target availability set in the secondary region and defining the exact failover order. You can add pre/post-action runbooks to automate scripted steps, which minimizes downtime and ensures application-consistent startup during planned failover. Setting availability sets and boot order individually in VM replication settings lacks this coordinated sequencing, so the recovery plan is the appropriate DR orchestration mechanism.

Why this answer

A recovery plan in Azure Site Recovery allows you to group VMs, specify the target availability set, and define the failover order. This ensures that after failover, the recovery VMs are automatically placed in the specified availability set, supporting the application's multi-tier architecture. Additionally, recovery plans enable you to automate and sequence failover steps, minimizing downtime during planned failover by orchestrating the process efficiently.

Exam trap

The trap here is that candidates often confuse replication settings (like target availability set per VM) with recovery plans, not realizing that only recovery plans can enforce failover order and group-level placement, which is critical for multi-tier applications.

How to eliminate wrong answers

Option B is wrong because setting the target availability set in each VM's replication settings individually does not allow you to define a failover order or group VMs into a recovery plan, which is necessary for multi-tier application consistency and minimizing downtime. Option C is wrong because Azure Traffic Manager is a DNS-based traffic routing service that does not handle VM placement into availability sets or orchestrate failover sequencing; it only redirects traffic after failover is manually completed. Option D is wrong because consistency groups (multi-VM consistency) ensure crash-consistent or app-consistent recovery points across VMs but do not control target availability set placement or failover order; they are a replication policy feature, not a recovery plan substitute.

111
MCQhard

Refer to the exhibit. You deploy this ARM template to create a storage account in the West US region. The business continuity requirement states that if the primary region becomes unavailable, the storage account must be readable within 1 hour. What is the most important limitation of this configuration?

A.The storage account does not support read access in the secondary region, so manual failover is required, which may exceed the 1-hour RTO
B.The storage account uses GRS, which replicates data only to a secondary region within the same geography, not to a different region
C.The storage account only supports HTTPS traffic, which blocks replication
D.The storage account is configured with the Hot access tier, which prevents failover
AnswerA

This is correct because the ARM template likely creates an Azure Storage account with GRS (Geo-Redundant Storage), which does not provide read access to the secondary region—that capability requires RA-GRS (Read-Access Geo-Redundant Storage). GRS only asynchronously replicates data to the paired secondary region, so you must perform a manual account failover to promote the secondary to primary. This manual failover can take several hours (often 2–3+ hours) depending on Azure's workload, exceeding the 1-hour RTO specified. Since the secondary is not readable before failover, you cannot meet recovery objectives without a separate, active second-region copy.

Why this answer

The ARM template configures GRS (Geo-Redundant Storage), which replicates data to a secondary region but does not provide read access to that data unless a manual failover is initiated. Without read-access geo-redundant storage (RA-GRS), the storage account cannot be read in the secondary region within 1 hour of a primary region outage, as manual failover requires user intervention and may take longer than the RTO. The business continuity requirement demands readability within 1 hour, which is not guaranteed with standard GRS.

Exam trap

The trap here is that candidates often confuse GRS with RA-GRS, assuming that geo-redundant replication automatically provides read access to the secondary region, when in fact only RA-GRS offers that capability without manual failover.

How to eliminate wrong answers

Option B is wrong because GRS does replicate data to a secondary region within the same geography (e.g., paired region), which is a different region from the primary (West US), so this statement is factually incorrect. Option C is wrong because HTTPS traffic does not block replication; Azure Storage replication uses HTTPS for secure data transfer, and this setting is unrelated to replication functionality. Option D is wrong because the Hot access tier does not prevent failover; access tiers (Hot, Cool, Archive) affect storage costs and retrieval latency, not the ability to perform a failover or read from the secondary region.

112
MCQhard

Refer to the exhibit. An administrator runs the PowerShell script to enable replication for a VM. The script fails with an error that the VM is not found. What is the most likely cause?

A.The Recovery Services vault does not exist.
B.The protection container is not available.
C.The replication policy is not valid.
D.The Azure PowerShell context is not set to the subscription that contains the VM.
AnswerD

The script uses Get-AzVM to locate the virtual machine, and this cmdlet depends on the active Azure context — the subscription set by Set-AzContext or Select-AzSubscription. If the context points to a different subscription than the one holding the target VM, Get-AzVM returns no matching VM, causing the backup protection command to fail with 'VM not found' even though the vault, container, and policy are all visible in the current context. The solution is to explicitly set the context (e.g., Set-AzContext -SubscriptionId '...') before running the script.

Why this answer

The PowerShell script uses `Get-AzRecoveryServicesBackupItem` and `Enable-AzRecoveryServicesBackupProtection` to enable replication for a VM. If the Azure PowerShell context (set via `Set-AzContext` or `Connect-AzAccount`) is not targeting the subscription containing the VM, the cmdlets will not find the VM resource, resulting in a 'VM not found' error. This is the most likely cause because the script otherwise references a valid vault, container, and policy.

Exam trap

The trap here is that candidates may assume the error is due to a missing vault or policy, but the 'VM not found' error specifically points to a subscription context mismatch, not a resource existence issue.

How to eliminate wrong answers

Option A is wrong because if the Recovery Services vault did not exist, the error would be 'vault not found' or a resource-not-found exception, not 'VM not found'. Option B is wrong because the protection container is derived from the vault and VM discovery; if it were unavailable, the error would indicate container retrieval failure, not a missing VM. Option C is wrong because the replication policy is validated when enabling protection; an invalid policy would produce a policy-specific error, not a 'VM not found' error.

113
MCQmedium

A company runs a critical line-of-business application on Azure VMs within a single region. The application tier is deployed across multiple VMs. They need to protect against a failure of an entire Azure datacenter within that region. The solution should automatically distribute the VMs across physically separate locations with independent power, cooling, and networking. The company also requires the lowest possible latency between application and database tiers within the same location. Which deployment strategy should they use?

A.Deploy the VMs across multiple availability zones
B.Deploy the VMs in an availability set
C.Use Azure Site Recovery to replicate VMs to a paired region
D.Use Azure Proximity Placement Groups
AnswerA

Availability zones provide datacenter-level redundancy within a region. By placing VMs in different zones, the application can survive a single datacenter failure. This also allows low latency within the same zone for the database tier.

Why this answer

Availability zones are physically separate datacenters within an Azure region, each with independent power, cooling, and networking. Deploying the application tier VMs across multiple zones protects against an entire datacenter failure while keeping all resources within the same region, ensuring the lowest possible latency between application and database tiers when they are placed in the same zone.

Exam trap

The trap here is that candidates often confuse availability sets (which protect against rack failures) with availability zones (which protect against datacenter failures), or they incorrectly assume that cross-region replication via Site Recovery is the only way to achieve datacenter fault tolerance, ignoring the lower-latency option of multiple zones within the same region.

How to eliminate wrong answers

Option B is wrong because an availability set only protects against rack-level failures within a single datacenter, not against the failure of an entire datacenter. Option C is wrong because Azure Site Recovery to a paired region introduces cross-region latency, which does not meet the requirement for the lowest possible latency within the same location. Option D is wrong because Proximity Placement Groups are designed to reduce latency by co-locating VMs, but they do not provide protection against a full datacenter failure.

114
MCQmedium

Refer to the exhibit. An administrator reviews the backup status of a VM. The last backup failed. What is the most likely cause?

A.The Recovery Services vault is in a different region.
B.The backup policy does not exist.
C.The source resource ID is missing.
D.The VM was deallocated at the time of backup.
AnswerD

Azure Backup cannot take a snapshot of a VM that is in the Deallocated (stopped) state, because the in-guest backup extension is not running and the VM's disks are not guaranteed to be in a consistent, attached state. When a backup job is initiated for a deallocated VM, the job is marked as failed with a warning, or in some cases it is skipped entirely, without affecting the policy or vault configuration. This is a well-known limitation, and the correct explanation for the failure shown in the exhibit.

Why this answer

When a VM is deallocated (stopped and deallocated in Azure), the Azure Backup service cannot create a VM-consistent snapshot because the VM is not running. Backup attempts for deallocated VMs will fail with an error indicating that the VM is not in a running state. This is a common cause of backup failures in Azure.

Exam trap

The trap here is that candidates may think a deallocated VM can still be backed up (since it still exists in Azure), but Azure Backup requires the VM to be in a running state to perform a successful backup.

How to eliminate wrong answers

Option A is wrong because Recovery Services vaults can back up VMs in any region; the vault and VM do not need to be in the same region for backup to work. Option B is wrong because if the backup policy did not exist, the backup would not have been scheduled at all, and the status would show 'No backup policy assigned' rather than a failed backup. Option C is wrong because the source resource ID is a required field for the backup job; if it were missing, the backup job would not have been created or would fail with a different error, not a generic failure.

115
MCQmedium

A company runs a critical application on Azure VMs in a single region. They need to ensure business continuity with an RPO of 1 hour and RTO of 4 hours. The application has dependencies on virtual networks, storage accounts, and other Azure resources. They want to use Azure Backup as the primary disaster recovery tool and must be able to restore the entire application in a secondary region if the primary region fails. Which backup strategy should they recommend?

A.Azure Backup for VMs with daily backups and cross-region restore
B.Azure Site Recovery with replication to a secondary region
C.Azure Backup for VMs with hourly backups and cross-region restore
D.Azure Backup for files with daily backups and geo-redundant storage
AnswerB

Correct. Azure Site Recovery provides continuous replication with low RPO and can orchestrate recovery of entire applications with dependencies.

Why this answer

Azure Site Recovery can replicate Azure VMs to a secondary region with an RPO as low as 15 minutes and an RTO of a few hours, meeting the 1-hour RPO and 4-hour RTO requirements. It also supports recovery plans that include virtual networks, storage accounts, and other dependencies, enabling restore of the entire application. Option C is incorrect because Azure Backup for VMs has a minimum backup frequency of every 4 hours for VM backups, not hourly, so it cannot achieve the required 1-hour RPO.

Exam trap

The trap is that candidates assume Azure Backup can achieve hourly backups for VMs, but the minimum backup frequency for VM backups is every 4 hours. Thus, for a 1-hour RPO, Azure Site Recovery (not Azure Backup) is required.

How to eliminate wrong answers

Option A is wrong because daily backups cannot achieve an RPO of 1 hour; the maximum backup frequency for daily backups is once per day, which would result in an RPO of up to 24 hours. Option B is wrong because Azure Site Recovery is a separate disaster recovery tool, not Azure Backup, and the question explicitly states they want to use Azure Backup as the primary disaster recovery tool. Option D is wrong because Azure Backup for files only protects file-level data, not the entire application including VMs, virtual networks, and storage accounts, and daily backups cannot meet the 1-hour RPO requirement.

116
MCQmedium

A company deploys a multi-tier application on Azure virtual machines. They need to implement disaster recovery using Azure Site Recovery. The recovery plan must ensure that the database VMs are started before the application VMs, and the application VMs before the web VMs. They also need to run a script after failover to update DNS records. Which ASR feature should they use?

A.Recovery Plan with manual steps
B.Recovery Plan with custom groups and script actions
C.Replication policy with crash-consistent snapshots
D.Azure Automation runbook
AnswerB

Custom groups in an Azure Site Recovery recovery plan provide strict ordering by letting you assign VMs to sequential groups; the plan starts each group only after the previous group completes. Script actions, implemented as Azure Automation runbooks or PowerShell commands, can be attached to each group to run post-failover steps such as waiting for the database tier to be ready or updating application configuration. This combination gives you automated, deterministic tier-by-tier startup without human intervention.

Why this answer

Azure Site Recovery (ASR) Recovery Plans allow you to orchestrate the order of VM failover by grouping VMs into custom groups and adding pre- and post-actions. By placing database VMs in Group 1, application VMs in Group 2, and web VMs in Group 3, you enforce the required startup sequence. Script actions (e.g., Azure Automation runbooks or PowerShell scripts) can be inserted at specific points in the plan to update DNS records after failover, making option B the correct choice.

Exam trap

The trap here is that candidates confuse a standalone Azure Automation runbook (which can run scripts but cannot enforce VM startup order) with a script action embedded in a Recovery Plan (which combines both ordering and script execution).

How to eliminate wrong answers

Option A is wrong because manual steps require human intervention during failover, which contradicts the need for an automated, reliable recovery plan that runs scripts to update DNS records. Option C is wrong because a replication policy with crash-consistent snapshots only controls the consistency of replicated data (ensuring crash-consistent recovery points) and does not provide any orchestration of VM startup order or post-failover scripting. Option D is wrong because an Azure Automation runbook is a script execution tool, but by itself it cannot define the multi-group startup sequence; it must be used as a script action within a Recovery Plan to achieve both ordering and automation.

117
Multi-Selecthard

A company runs an application on Azure VMs that uses Azure SQL Database. They need a disaster recovery solution that ensures the application can fail over to a secondary region with minimal data loss. The solution must include automatic failover for the database and manual failover for the VMs. Which TWO Azure services should they use? (Choose two.)

Select 2 answers
A.Azure SQL Database auto-failover groups
B.Azure Traffic Manager
C.Azure Front Door
D.Azure Site Recovery
E.Azure SQL Database active geo-replication
AnswersA, D

Auto-failover groups provide automatic, policy-driven failover for Azure SQL Database to a secondary region, with asynchronous replication giving minimal data loss. This directly satisfies the stem's requirement for automatic database failover, while VMs are handled separately by manual failover.

Why this answer

Azure SQL Database auto-failover groups (option A) are correct because they provide automatic failover of the database to a secondary region with a defined RPO/RTO, satisfying the requirement for automatic database failover with minimal data loss. Azure Site Recovery (option D) is correct because it orchestrates replication and recovery of Azure VMs to a secondary region, and it supports manual (planned/unplanned) failover, matching the requirement for manual VM failover. Azure Traffic Manager (option B) and Azure Front Door (option C) are traffic-routing and load-balancing services that can direct users to a healthy endpoint, but they do not themselves provide database failover or VM replication/recovery.

Azure SQL Database active geo-replication (option E) enables replicas and manual failover of the database, but it does not provide the automatic failover capability required, so it does not meet the scenario.

118
MCQmedium

A company runs a critical application on Azure VMs in the West US region. They need to protect against a regional disaster using Azure Site Recovery. The VMs use unmanaged disks. The recovery point objective (RPO) must be 15 minutes and the recovery time objective (RTO) must be 1 hour. Additionally, they must be able to perform quarterly disaster recovery drills that do not affect the production environment. Which configuration should they use in Azure Site Recovery?

A.Set up replication with a 15-minute snapshot frequency and perform test failover for drills.
B.Use Azure Backup for VM replication and perform restore drills.
C.Configure a recovery plan with a pre-script to take a snapshot every 15 minutes.
D.Enable multi-VM consistency group with a 15-minute consistency frequency.
AnswerA

Azure Site Recovery's replication policy allows configuring a recovery point objective (RPO) of 15 minutes by setting the snapshot frequency, so you can cap data loss at 15 minutes. The built-in test failover feature launches your replicated VMs in an isolated Azure network, letting you run non-disruptive failover drills without affecting production or incurring downtime. This is the only option that directly delivers both the required RPO and a documented, low-risk drill methodology.

Why this answer

Azure Site Recovery supports replication of Azure VMs with unmanaged disks, and a 15-minute snapshot frequency meets the RPO requirement. Test failover allows quarterly disaster recovery drills without impacting the production environment, as it creates isolated copies of VMs in a separate network for validation.

Exam trap

The trap here is confusing Azure Backup (long-term backup) with Azure Site Recovery (replication for disaster recovery), as both can restore VMs but only Site Recovery supports low RPOs and non-disruptive test failovers.

How to eliminate wrong answers

Option B is wrong because Azure Backup is designed for long-term backup retention and restore, not for low-RPO replication (typically 1-2 snapshots per day) and does not support the 15-minute RPO or test failover drills without affecting production. Option C is wrong because recovery plans with pre-scripts cannot take snapshots at a fixed frequency; snapshot frequency is configured at the replication policy level, not via scripts in a recovery plan. Option D is wrong because multi-VM consistency groups ensure crash-consistent or app-consistent snapshots across multiple VMs, but they do not directly set the snapshot frequency; the consistency frequency is separate from the replication frequency, and this option does not address the drill requirement.

119
MCQmedium

A company uses Azure Site Recovery to replicate critical Azure virtual machines (VMs) to a secondary Azure region for disaster recovery. The VMs use managed disks and are part of a multi-tier application. After a failover, the recovery VMs must be automatically placed into a specific availability set to maintain the application architecture. How should the administrator configure this in Azure Site Recovery?

A.Configure the target availability set in the VM replication settings in the Recovery Services vault
B.Create a recovery plan and add a manual step or script to move VMs to the availability set after failover
C.Convert the managed disks to unmanaged disks for replication, then specify the availability set
D.Azure Site Recovery does not support placing VMs into an availability set in the target region
AnswerA

In Azure Site Recovery, when you enable Azure-to-Azure replication for a VM with managed disks, the 'Compute and Network' settings under the replication configuration include an explicit 'Target availability set' field. Selecting the desired target availability set there causes the failed-over VM to be automatically created within that set as part of the failover process. This is the native and supported mechanism to satisfy the requirement of automatic placement in the target region, and no post-failover scripting or disk conversion is needed.

Why this answer

Azure Site Recovery (ASR) allows you to configure the target availability set directly in the replication settings for each VM. When you enable replication for a VM, under the 'Target availability set' setting, you can select an existing availability set in the target region. ASR will then automatically place the recovered VM into that availability set during failover, ensuring the multi-tier application architecture is maintained without manual intervention.

Exam trap

The trap here is that candidates may assume ASR lacks native support for availability sets and default to manual recovery plans or unnecessary disk conversions, overlooking the straightforward configuration option in the replication settings.

How to eliminate wrong answers

Option B is wrong because while recovery plans can include manual steps or scripts, this approach is inefficient and error-prone; ASR natively supports specifying the target availability set in the replication settings, eliminating the need for post-failover manual steps. Option C is wrong because converting managed disks to unmanaged disks is unnecessary and not a supported method for specifying availability sets; ASR works with managed disks and the availability set is configured independently in the replication settings. Option D is wrong because Azure Site Recovery does support placing VMs into an availability set in the target region, as demonstrated by the correct configuration in Option A.

120
MCQmedium

A company runs a critical web application on Azure VMs in two availability zones. They need to ensure the application remains available during a regional outage with an RPO of 5 minutes and an RTO of 15 minutes. What should they implement?

A.Azure Backup
B.Azure Traffic Manager
C.Azure Site Recovery
D.Azure Front Door
AnswerC

Azure Site Recovery is the correct service for this requirement because it provides continuous replication of Azure VMs from the primary region to a secondary region, with an RPO as low as 5 minutes and a typical RTO of 15 minutes for web workloads. It orchestrates failover and failback, enabling the application to be brought up in the secondary region with minimal data loss and downtime. Site Recovery also supports test failover to validate a DR plan without impacting production. Therefore, it meets the critical web application's replication and recovery requirements.

Why this answer

Azure Site Recovery (ASR) is the correct choice because it provides automated replication of Azure VMs from one region to another, enabling failover during a regional outage. With continuous replication, ASR can achieve an RPO of as low as 30 seconds (well within the 5-minute requirement) and, when combined with a well-tested recovery plan, can meet the 15-minute RTO by orchestrating the startup of replicated VMs in the secondary region.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (which handles full VM replication and failover) with Azure Backup (which only handles data backup and restore), or they assume that a traffic manager like Traffic Manager or Front Door alone can provide disaster recovery without the underlying compute replication.

How to eliminate wrong answers

Option A is wrong because Azure Backup is designed for long-term data retention and point-in-time restore (typically with an RPO of 12-24 hours for VM backups), not for rapid, automated failover with a 5-minute RPO and 15-minute RTO. Option B is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that distributes traffic across endpoints but does not replicate VM data or provide automated failover of compute resources; it requires the application to already be running in the secondary region. Option D is wrong because Azure Front Door is a global HTTP/HTTPS load balancer and application delivery controller that provides traffic routing and acceleration, but it does not replicate or fail over underlying VM infrastructure; it assumes the backend is already active.

121
MCQmedium

A company runs multiple on-premises workloads that are critical. They need a disaster recovery solution that can replicate workloads to Azure and enable failover in the event of an on-premises outage. The solution must support non-VMware and non-Hyper-V physical servers. Which Azure service should they use?

A.Azure Backup
B.Azure Site Recovery
C.Azure Migrate
D.Azure Disaster Recovery
AnswerB

Azure Site Recovery is the correct DRaaS solution for this scenario. It performs continuous replication of on-premises VMware VMs, Hyper-V VMs, and physical servers to Azure storage, and it tracks application state so that a failover can start a replica in Azure. Site Recovery supports orchestrated failover and test failover through recovery plans that sequence application dependencies, and it provides precise RPO/RPO control. This makes it the only option that actively replicates on-premises workloads for automated disaster recovery rather than just protecting data or migrating once.

Why this answer

Azure Site Recovery (ASR) is the correct service because it provides orchestrated replication and failover for on-premises physical servers (including non-VMware, non-Hyper-V) to Azure. It supports physical-to-Azure (P2A) replication using the Mobility service installed on the source server, enabling automated failover during an outage. This directly meets the requirement for critical workload disaster recovery with failover capability.

Exam trap

The trap here is that candidates often confuse Azure Backup (data protection) with Azure Site Recovery (disaster recovery with failover), or assume that 'Azure Disaster Recovery' is a valid service name, when in fact the correct service is Azure Site Recovery.

How to eliminate wrong answers

Option A is wrong because Azure Backup is designed for backup and restore of data (files, folders, VMs, databases) to a Recovery Services vault, not for continuous replication and automated failover orchestration required for disaster recovery. Option C is wrong because Azure Migrate is a tool for assessing and migrating on-premises workloads to Azure, not for ongoing replication and failover after migration. Option D is wrong because 'Azure Disaster Recovery' is not a standalone Azure service; the correct service name is Azure Site Recovery, and this option is a distractor that does not exist as a named service.

122
MCQhard

Your organization has a hybrid identity infrastructure using Microsoft Entra ID (formerly Azure AD) and Active Directory Domain Services (AD DS) on-premises. You plan to deploy a critical application on Azure VMs that must remain available even if the on-premises network connection fails. The application authenticates users via on-premises AD DS. You need to design an identity disaster recovery solution that works during a network outage. What should you implement?

A.Create a site-to-site VPN connection with a secondary on-premises data center.
B.Configure Azure AD Connect with password hash synchronization and enable seamless single sign-on.
C.Deploy Microsoft Entra Domain Services and join the Azure VMs to the managed domain.
D.Use Azure AD Application Proxy to publish the application and authenticate via Azure AD.
AnswerC

Microsoft Entra Domain Services provides a fully managed, Microsoft-owned Active Directory domain in the cloud that supports Kerberos, NTLM, LDAP, group policy, and domain join without any Azure-to-on-premises network dependency. User and group objects flow into the managed domain from your Azure AD tenant, which is populated from on-premises AD via Azure AD Connect, so existing domain users continue to authenticate. When you join Azure VMs to the Entra DS managed domain, the Azure VMs authenticate directly against the cloud managed domain, allowing them to keep working even if the primary data center and all on-premises domain controllers are offline.

Why this answer

Microsoft Entra Domain Services provides a managed domain that is synchronized from your on-premises AD DS via Azure AD Connect. By joining the Azure VMs to this managed domain, the application can authenticate users against the managed domain even when the on-premises network connection fails, ensuring local authentication within Azure without dependency on the on-premises AD DS.

Exam trap

The trap here is that candidates often confuse Azure AD (a cloud identity service) with a domain-joined environment; they may choose password hash synchronization (Option B) thinking it provides domain services, but it only enables cloud authentication, not a managed domain for VMs.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN to a secondary on-premises data center still relies on on-premises AD DS and does not address the requirement for availability during a network outage; if the primary connection fails, the secondary also depends on on-premises infrastructure. Option B is wrong because password hash synchronization with seamless single sign-on enables cloud authentication via Azure AD but does not provide a domain-joined environment for Azure VMs; the application requires on-premises AD DS authentication, and during an outage, Azure AD cannot authenticate against on-premises AD DS without network connectivity. Option D is wrong because Azure AD Application Proxy publishes applications for remote access and authenticates via Azure AD, but it does not provide a managed domain for Azure VMs to authenticate against on-premises AD DS during a network outage; it still requires the application to reach on-premises AD DS for authentication.

123
MCQmedium

A company has an on-premises application running on physical servers with various operating systems. They want to use Azure as a disaster recovery site with an RPO of less than 1 hour and an RTO of less than 4 hours. They need to replicate the servers to Azure and support failover and failback. Which Azure service should they use?

A.Azure Site Recovery
B.Azure Backup (MARS agent)
C.Azure Migrate
D.Azure File Sync
AnswerA

Azure Site Recovery (ASR) replicates physical servers to Azure using the Mobility service, which continuously writes data to a cache storage account and then to Azure-managed disks, achieving RPO as low as 30 seconds. It supports both crash-consistent and app-consistent snapshots for Windows and Linux, and enables orchestrated failover via recovery plans. With RTOs in hours, ASR meets the DR requirement for rapid recovery and offers failback to the original on-premises physical server or VMware VM.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback for physical servers and VMs to Azure, meeting the RPO of <1 hour and RTO of <4 hours. It supports heterogeneous operating systems on physical servers and provides continuous replication with recovery points as low as 30 seconds, enabling both planned and unplanned failover with full failback capability.

Exam trap

The trap here is that candidates confuse Azure Backup (which provides long-term archival backups) with Azure Site Recovery (which provides near-continuous replication and orchestrated failover), failing to recognize that the RPO and RTO requirements demand a replication-based DR solution, not a backup service.

How to eliminate wrong answers

Option B (Azure Backup with MARS agent) is wrong because it is designed for file/folder and system state backup with a minimum RPO of 1 day (daily backup), not sub-hourly replication, and it does not support orchestrated failover or failback of entire servers. Option C (Azure Migrate) is wrong because it is a discovery, assessment, and migration tool, not a disaster recovery service; it does not provide ongoing replication or failover/failback capabilities. Option D (Azure File Sync) is wrong because it only syncs file shares between on-premises and Azure, not entire server workloads, and lacks failover/failback orchestration for disaster recovery.

124
MCQmedium

Your company runs an on-premises application that needs to be failed over to Azure in the event of a disaster. The application uses a SQL Server database and requires an RPO of 15 minutes and an RTO of 1 hour. You plan to use Azure Site Recovery (ASR) for the VMs and Azure SQL Database for the database. Which combination of actions should you take?

A.Use ASR with 5-minute replication and configure SQL Server Log Shipping to an Azure VM.
B.Use ASR with 30-minute replication frequency and backup the SQL Server database every 15 minutes.
C.Use ASR with 15-minute replication for the VMs and configure a failover group for Azure SQL Database with active geo-replication.
D.Use ASR with 15-minute replication and restore the SQL Server database from backup.
AnswerC

ASR with 15-minute replication meets the RPO for the VMs, replicating the entire virtual machine to the secondary region with near-synchronous frequency. Azure SQL Database failover groups with active geo-replication provide automatic, database-level failover to a readable secondary in the paired region, which meets the RTO without manual intervention. This combination uses each service's native DR capability, ensuring that both the application tier and the database tier can fail over together.

Why this answer

It meets both the RPO of 15 minutes and RTO of 1 hour. Azure Site Recovery (ASR) with 15-minute replication ensures VM replication within the RPO, while Azure SQL Database failover groups with active geo-replication provide automatic, continuous data synchronization and a fast, orchestrated failover for the database, achieving the required RTO.

Exam trap

The trap here is that candidates often assume ASR can handle both VM and database replication, but ASR does not replicate SQL Server databases in a transactionally consistent manner for Azure SQL Database; a separate database-level solution like failover groups is required.

How to eliminate wrong answers

Option A is wrong because SQL Server Log Shipping to an Azure VM introduces a manual failover process and potential delays, making it difficult to achieve a 1-hour RTO, and ASR with 5-minute replication is unnecessary and not a standard configurable frequency (ASR supports 30-second, 5-minute, and 15-minute intervals, but 5-minute is not the issue; the database solution is the problem). Option B is wrong because ASR with 30-minute replication exceeds the 15-minute RPO requirement, and backing up the SQL Server database every 15 minutes does not provide a failover-ready replica, leading to potential data loss and longer recovery times. Option D is wrong because restoring the SQL Server database from backup cannot achieve a 1-hour RTO due to the time required to restore large backups, and ASR with 15-minute replication alone does not address the database failover requirement.

125
MCQmedium

A company runs a file server on an Azure VM in the East US region. They want to back up the file shares to Azure and be able to restore individual files if accidentally deleted. They also need to be able to restore the entire file share to a secondary region (West US) in case of a regional disaster. The solution should automatically protect the file shares and provide versioning for up to 30 days. Which Azure service and configuration should they recommend?

A.Configure Azure Backup on the Azure file share using a Recovery Services vault with geo-redundant storage (GRS). Enable cross-region restore on the vault.
B.Use Azure File Sync to sync the file share to an on-premises server, and then back up the on-premises server using Azure Backup.
C.Enable soft delete and versioning on the storage account, and configure replication to a secondary region using RA-GRS.
D.Create a scheduled Azure Automation runbook that takes snapshots of the file share every day and copy them to a storage account in West US.
AnswerA

Azure Backup for Azure Files is the native managed backup service that takes scheduled snapshots of the file share and stores recovery points in a Recovery Services vault. By selecting GRS for the vault and enabling cross-region restore, you gain the ability to restore the entire share to the paired region (East US to West US) if a regional disaster occurs. The service also supports granular item-level restore, allows you to specify backup frequency and retention, and automatically manages the snapshot lifecycle, making it the only option here that meets both backup and DR requirements.

Why this answer

Azure Backup for Azure file shares uses a Recovery Services vault and can be configured with geo-redundant storage (GRS) to replicate backup data to a paired secondary region. Enabling cross-region restore on the vault allows restoring the entire file share to the secondary region (West US) during a regional disaster. Azure Backup automatically protects the file share with scheduled backups and provides up to 30 days of retention for point-in-time restores of individual files or the entire share.

Exam trap

The trap here is that candidates often confuse storage account replication (RA-GRS) with backup and restore capabilities, thinking that replication alone provides disaster recovery restore functionality, but it does not support point-in-time file-level restore or cross-region restore of backups without Azure Backup's cross-region restore feature.

How to eliminate wrong answers

Option B is wrong because Azure File Sync is designed for hybrid sync and tiering, not for backup; it does not provide native cross-region disaster recovery or versioning for up to 30 days, and backing up an on-premises server adds unnecessary complexity and does not directly meet the requirement to restore to a secondary Azure region. Option C is wrong because soft delete and versioning on the storage account provide protection against accidental deletion and overwrites, but they do not offer a backup solution with scheduled backups, cross-region restore capability, or the ability to restore the entire file share to a secondary region in a disaster scenario; RA-GRS replication is for storage account data redundancy, not for backup restore. Option D is wrong because a scheduled Azure Automation runbook that takes snapshots and copies them to another region is a custom, non-native solution that lacks the automated backup scheduling, versioning, and cross-region restore capabilities provided by Azure Backup; it also introduces operational overhead and does not guarantee the 30-day versioning requirement.

126
MCQmedium

You are designing a backup strategy for Azure VMs that host a file server. The backup must support daily backups with a retention of 30 days, and the ability to restore individual files quickly. The solution must minimize backup storage costs. What backup policy should you configure?

A.Use Azure Backup with daily backup, retention of 30 days, and use locally redundant storage (LRS) for backup data.
B.Use Azure Backup with daily backup, retention of 30 days, and enable instant restore snapshot for file-level recovery.
C.Use Azure Backup with daily backup, retention of 30 days, and use geo-redundant storage (GRS) for backup data.
D.Use Azure Backup with weekly backup, retention of 30 days, and use geo-redundant storage (GRS) for backup data.
AnswerB

Incorrect. While daily backups and 30-day retention are correct, this option does not specify storage redundancy. Without specifying LRS, the backup storage may default to GRS, increasing cost unnecessarily. The instant restore snapshot feature is automatically enabled and does not need to be explicitly configured.

Why this answer

Option B is correct because Azure Backup for Azure VMs uses instant restore snapshots to provide fast file-level recovery. The backup policy defines the daily backup schedule, 30-day retention, and instant restore snapshot retention. Storage redundancy (LRS/GRS) is configured at the Recovery Services vault level, not in the backup policy; to minimize costs, select LRS at the vault level separately.

Option A is incorrect because it treats LRS as part of the backup policy and does not address the file-level recovery requirement. Option C uses GRS, which increases cost unnecessarily, and option D uses weekly backups, which violates the daily backup requirement.

Exam trap

Candidates may mistakenly treat storage redundancy as part of the backup policy and choose LRS in the policy. Storage replication is set at the Recovery Services vault level, not in the backup policy. Also, file-level recovery is enabled through instant restore snapshots, so the policy must include that aspect.

To minimize costs, select LRS at the vault level separately.

How to eliminate wrong answers

Option C is wrong because geo-redundant storage (GRS) increases backup storage costs unnecessarily for a scenario that only requires local durability and does not mandate cross-region redundancy. Option D is wrong because weekly backups would result in a maximum data loss of up to 7 days, failing the daily backup requirement, and GRS adds unnecessary cost. Option B is wrong because while instant restore snapshots enable file-level recovery, they are a feature of Azure Backup that is already available and not a separate policy configuration; the question asks for a backup policy, and enabling instant restore does not minimize storage costs—it may actually increase costs due to snapshot retention.

127
MCQmedium

A company runs a critical application on Azure virtual machines in the West US region. They need a disaster recovery solution that replicates VMs to East US with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. They also need to perform non-disruptive disaster recovery drills. Which Azure service should they use?

A.Azure Backup
B.Azure Site Recovery
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Site Recovery directly addresses the DR requirement by continuously replicating Azure VMs to a secondary Azure region, with a recovery point objective (RPO) as low as 15 minutes for supported disk types. It enables orchestrated failover and failback, and crucially allows test failover using isolated networks so you can validate end-to-end recovery without impacting production or incurring downtime. Recovery plans can sequence multi-tier application startup, making it the correct choice for this critical workload.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs between regions. It supports RPOs as low as 15 minutes (continuous replication with crash-consistent or app-consistent snapshots) and RTOs of 2 hours or less, and it enables non-disruptive disaster recovery drills via test failover that isolates replicated VMs in a separate virtual network without impacting production.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for backup/restore with longer RPOs) with Azure Site Recovery (which is for replication and failover with low RPO/RTO), or they mistakenly think a traffic-routing service like Traffic Manager or Front Door can provide disaster recovery replication without actually moving or copying VM data.

How to eliminate wrong answers

Option A is wrong because Azure Backup is designed for long-term retention and point-in-time restore of VM data (typically with a minimum RPO of 1 hour for disk snapshots), not for continuous replication with sub-15-minute RPO or orchestrated failover with a 2-hour RTO; it also does not support non-disruptive drills. Option C is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes incoming traffic to healthy endpoints, but it does not replicate VM data or provide any disaster recovery replication, RPO/RTO guarantees, or drill capabilities. Option D is wrong because Azure Front Door is a global application delivery network with HTTP/S load balancing and acceleration, but it does not handle VM-level replication, failover orchestration, or recovery point objectives; it only redirects traffic based on backend health.

128
MCQmedium

You are designing a backup strategy for Azure Files shares that contain critical data. The backup must support snapshot-based backups and allow restoration to a specific point in time. The solution must also protect against accidental deletion. What should you use?

A.Use Azure File Sync with cloud tiering.
B.Use Azure Storage account geo-redundant storage (GRS) with versioning.
C.Use Azure Backup for Azure Files with soft delete enabled.
D.Use Azure Backup for Azure Files without soft delete.
AnswerC

Azure Backup for Azure Files is the correct solution because it provides fully managed, snapshot-based backups with granular recovery points for point-in-time restore. Enabling soft delete ensures that when a file share is deleted, the share and its snapshots are retained for the configured retention period (1 to 365 days), preventing accidental loss and allowing recovery. This combination delivers both backup and accidental-deletion protection.

Why this answer

Azure Backup for Azure Files provides snapshot-based backups that support point-in-time restoration, and when combined with soft delete, it protects against accidental deletion by retaining deleted data for a configurable retention period (default 14 days). This meets all stated requirements: snapshot backups, point-in-time restore, and deletion protection.

Exam trap

The trap here is that candidates may confuse Azure File Sync with Azure Backup, or assume that storage replication (GRS) alone provides backup and deletion protection, when in fact Azure Files requires explicit backup configuration and soft delete for those capabilities.

How to eliminate wrong answers

Option A is wrong because Azure File Sync with cloud tiering is a synchronization and caching solution, not a backup service; it does not provide snapshot-based backups or point-in-time restoration. Option B is wrong because geo-redundant storage (GRS) with versioning provides replication and object versioning for blobs, but Azure Files does not support versioning—only blob storage does; GRS alone does not offer snapshot-based backups or point-in-time restore for file shares. Option D is wrong because Azure Backup for Azure Files without soft delete fails to protect against accidental deletion, which is a stated requirement; soft delete is essential for that protection.

129
Multi-Selecthard

Which THREE of the following are best practices for designing a business continuity solution using Azure Backup? (Choose three.)

Select 3 answers
A.Enable soft delete to protect backup data from accidental deletion
B.Configure a single backup policy for all resources to simplify management
C.Use geo-redundant storage (GRS) for the backup data to protect against regional disasters
D.Use separate Recovery Services vaults for different workloads or regions
E.Grant all users 'Backup Contributor' role to ensure backups are taken
AnswersA, C, D

Soft delete in Azure Backup adds a safety net by retaining deleted backup data for a default retention period (14 days) after deletion, allowing recovery of backup items that were accidentally or maliciously removed. This prevents permanent data loss when a Recovery Services vault or a backup item is deleted, because the protected data and its restore points remain available for restoration within the soft-delete window. Administrators must explicitly re-enable soft delete if disabled, and re-deleting an item after the soft-delete period results in permanent deletion.

Why this answer

Enabling soft delete in Azure Backup protects backup data from accidental or malicious deletion by retaining deleted backup data for an additional 14 days (configurable up to 14 days). This ensures that even if a backup item is deleted, the data remains recoverable, which is a critical best practice for business continuity.

Exam trap

The trap here is that candidates often confuse 'simplifying management' (Option B) with best practice, but Azure Backup requires workload-specific policies to meet RPO/RTO requirements, and a single policy would either over-retain or under-protect different resources.

130
MCQmedium

A company runs a critical application on Azure VMs. They want to back up the VMs using Azure Backup. The retention requirements are: daily backups for 35 days, weekly backups for 52 weeks, and yearly backups for 10 years. Which backup policy should they create?

A.Create a custom backup policy with a daily backup schedule and retention rules for daily (35), weekly (52), and yearly (10 years)
B.Use the default backup policy provided by Azure Backup
C.Use Azure Site Recovery (ASR) to replicate the VMs and meet the retention
D.Use Azure Backup for VMs with instant recovery enabled
AnswerA

A custom backup policy in Azure Backup allows you to define a daily backup schedule and independent retention rules for each backup frequency. With the requested settings, daily restore points are kept for 35 days, weekly restore points for 52 weeks (one year), and yearly restore points for 10 years, all within Azure Backup's supported retention limits. This directly meets the compliance and recovery requirements by controlling both when backups are captured and how long each frequency tier is retained.

Why this answer

Azure Backup allows you to create a custom backup policy that defines a daily backup schedule and separate retention rules for daily, weekly, and yearly retention points. This directly meets the requirement of 35 days daily, 52 weeks weekly, and 10 years yearly retention, as Azure Backup supports granular retention policies with multiple tiers (daily, weekly, monthly, yearly) within a single policy.

Exam trap

The trap here is that candidates may confuse Azure Backup's default policy (which only covers short-term retention) with the ability to customize retention tiers, or mistakenly think Azure Site Recovery can serve as a backup solution for long-term retention, when in fact it is for replication and failover, not backup retention.

How to eliminate wrong answers

Option B is wrong because the default backup policy in Azure Backup typically retains daily backups for only 30 days (not 35) and does not include weekly or yearly retention rules, so it cannot meet the specified requirements. Option C is wrong because Azure Site Recovery (ASR) is designed for disaster recovery and replication, not for long-term backup retention; it does not support retention policies for years and is not a backup solution for meeting retention schedules. Option D is wrong because instant recovery is a feature that enables faster restore from snapshots, but it does not modify or extend retention policies; the default or custom policy still governs retention, and instant recovery alone cannot satisfy the 35-day, 52-week, and 10-year retention requirements.

131
Multi-Selecthard

A mission-critical web application must tolerate a full Azure region outage. The business requires automatic failover and global HTTP acceleration. Which two components should be included in the design? (Choose 2.)

Select 2 answers
A.Deploy the application to at least two Azure regions.
B.Use Azure Front Door with health probes and origin failover.
C.Use only availability zones in one region.
D.Use Azure Bastion for failover routing.
AnswersA, B

Multi-region deployment is the only architecture that can survive a full regional outage because a region is a complete independent Azure deployment with its own core services, power, cooling, and network. Even with perfect code and infrastructure, a single region has a single region failure scope; paired regions give independent availability and planned maintenance. A mission-critical system must therefore establish at least two regional origins before any automated failover can work, making this the baseline for true disaster recovery.

Why this answer

Deploying the application to at least two Azure regions provides geographic redundancy, ensuring that if one entire region fails, the application can still operate from the other region. This is a fundamental requirement for tolerating a full region outage. Option B is correct because Azure Front Door provides global HTTP acceleration and automatic failover by using health probes to monitor endpoint health and routing traffic to healthy origins, which meets the business requirements for both automatic failover and performance.

Exam trap

The trap here is that candidates often confuse availability zones (which protect against datacenter failures within a region) with multi-region deployments (which are required for region outage tolerance), leading them to incorrectly select Option C as sufficient.

132
MCQhard

You are designing a business continuity solution for a global e-commerce platform that runs on Azure Kubernetes Service (AKS) in multiple regions. The application must remain available even if an entire Azure region fails. The application uses Azure Cosmos DB for its database. You need to ensure that the application can continue to serve traffic with minimal disruption. What should you recommend?

A.Use Cosmos DB with geo-redundant storage and deploy a single AKS cluster with Azure Site Recovery.
B.Deploy AKS clusters in two regions with Azure Traffic Manager and use Cosmos DB single-region writes with async replication.
C.Configure Cosmos DB with multi-region writes and deploy AKS clusters in two regions behind Azure Front Door.
D.Deploy the application to a single region and use Azure Backup for Cosmos DB to restore in another region.
AnswerC

This is the correct solution because it delivers a true active-active architecture with zero data loss and minimal downtime. Cosmos DB multi-region writes allows the database to accept writes in both regions, and the service automatically synchronizes all regions with a single write consistency model; during a regional outage, Cosmos DB automatically fails over the affected region without any manual intervention, preserving both availability and RPO. Azure Front Door fronts the two AKS clusters with global load balancing at Layer 7, providing instant failover via health probes, SSL offload, and path-based routing—it can route traffic to the healthy region in seconds, unlike DNS-only solutions. The combination of multi-region writes (no RPO loss) and Front Door (near-zero RTO) satisfies the business continuity requirement for a globally distributed application, making this the only option that meets the stated goals.

Why this answer

It combines multi-region writes in Azure Cosmos DB with AKS clusters deployed in two regions behind Azure Front Door. Multi-region writes provide active-active failover with RTO near zero and 99.999% read/write availability, while Azure Front Door offers global load balancing and automatic failover at the application layer. This architecture ensures the application remains available even if an entire Azure region fails, with minimal disruption.

Exam trap

The trap here is that candidates often confuse Azure Storage geo-redundant storage (GRS) with Cosmos DB's native multi-region replication, or they assume that single-region writes with async replication (Option B) provide sufficient availability, ignoring the risk of data loss and manual failover delays.

How to eliminate wrong answers

Option A is wrong because Cosmos DB does not use geo-redundant storage (GRS) — that is a feature of Azure Storage accounts, not Cosmos DB; Cosmos DB uses its own multi-region replication. Also, deploying a single AKS cluster with Azure Site Recovery does not provide active-active failover; Site Recovery is for disaster recovery with RTO in minutes, not for minimal disruption. Option B is wrong because Cosmos DB single-region writes with async replication have a potential for data loss (RPO > 0) and failover is not automatic, requiring manual or scripted intervention, which contradicts 'minimal disruption'.

Option D is wrong because deploying to a single region and using Azure Backup for Cosmos DB to restore in another region results in significant downtime (RTO in hours) and data loss (RPO based on backup frequency), which is not acceptable for a global e-commerce platform requiring minimal disruption.

133
MCQmedium

Fabrikam Inc. runs a file-sharing service used by 500 employees globally. The service is deployed on Azure VMs in the North Europe region. The VMs store data on Azure Files shares (Standard performance tier) mounted via SMB. The company's business continuity policy requires: - RPO: 1 hour for any data loss. - RTO: 4 hours to restore service after a regional disaster. - All data must be backed up and recoverable in a different region. - Budget is a concern; prefer cost-effective solutions. Currently, there is no backup in place. You need to design a solution. What should you do?

A.Set up Azure Site Recovery (ASR) for the VMs and Azure Files. Replicate to a secondary region (West Europe). Use ASR recovery plans to orchestrate failover.
B.Configure Azure Backup for the Azure Files shares with a backup policy of 1-hour frequency. Also back up the VMs using Azure Backup with a 1-hour policy. Store backups in a Recovery Services vault with geo-redundant storage (GRS). Enable cross-region restore.
C.Use Azure Files share snapshots taken every hour and store them in a separate storage account in the same region. For VM backup, use Azure Backup with daily frequency. In a disaster, deploy new VMs and restore from snapshots.
D.Implement Azure File Sync between the Azure Files share and an on-premises file server. For disaster recovery, failover to the on-premises server.
AnswerA

Correct. ASR replicates VMs to a secondary region with low RPO, and GRS on the Azure Files storage account provides cross-region data replication. This meets all requirements cost-effectively.

Why this answer

Azure Site Recovery (ASR) can replicate the VMs to a secondary region (West Europe), meeting the RPO (near-synchronous) and RTO (4 hours achievable). For the Azure Files data, the storage account hosting the file shares should be configured with geo-redundant storage (GRS), which automatically replicates data to a paired region, satisfying the cross-region recoverability requirement. This combination is cost-effective as it uses built-in replication without additional backup infrastructure.

Option B is incorrect because Azure Backup for Azure Files does not support a 1-hour backup frequency (minimum is 4 hours), and Azure Backup for Azure VMs also has a minimum 4-hour frequency, so it cannot meet the 1-hour RPO. Option C fails cross-region requirement as snapshots are stored in the same region, and VM backup frequency is daily. Option D requires an on-premises server and does not provide failover to a different Azure region.

Exam trap

The trap here is that candidates assume Azure Backup supports a 1-hour backup frequency for Azure Files (it does not; the minimum is 4 hours), leading them to incorrectly select Option B without considering ASR and GRS for meeting the RPO and cross-region requirement.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery (ASR) replicates VMs and Azure Files at the infrastructure level but does not provide point-in-time backup with 1-hour granularity; ASR's replication frequency is typically 5 minutes or more, and it does not natively support Azure Files replication for file shares, making it unsuitable for the RPO requirement. Option C is wrong because Azure Files share snapshots are stored in the same region and do not provide cross-region disaster recovery; additionally, VM backup with daily frequency violates the 1-hour RPO, and deploying new VMs from snapshots in the same region does not meet the 'different region' requirement. Option D is wrong because Azure File Sync syncs to an on-premises server, which does not satisfy the requirement to back up and recover data in a different Azure region; it also introduces an on-premises dependency, increasing cost and complexity, and does not meet the RPO/RTO for a regional disaster.

134
MCQmedium

Your company runs a Windows-based application on Azure Virtual Machines in the Brazil South region. The application uses Azure Files for shared storage and Azure SQL Database (Hyperscale tier) for the database. The business requires a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 30 minutes for the entire application. The solution must be cost-effective and leverage Azure-native services. You have been asked to design the disaster recovery strategy. Which option should you recommend?

A.Use Azure Site Recovery to replicate the VMs to a secondary region. Configure geo-redundant storage (GRS) for Azure Files. For Azure SQL Database Hyperscale, enable geo-restore and test restore procedures.
B.Deploy a second set of VMs in a secondary region. Use Azure File Sync to keep Azure Files in sync. Use Azure SQL Database failover groups with a readable secondary.
C.Back up the VMs using Azure Backup with a 15-minute frequency. Use Azure File Sync to replicate Azure Files to a secondary region. Use Azure SQL Database backup with point-in-time restore.
D.Use Azure Site Recovery for VMs. Use Azure File Sync for Azure Files. Use active geo-replication for Azure SQL Database.
AnswerA

Azure Site Recovery is the correct DR service for Azure VMs because it replicates disks to a secondary region asynchronously, delivering an RPO of as little as 5 minutes (well under the 15-minute requirement) and a recoverable RTO of minutes through failover. For Azure Files, GRS replicates file share data to a paired region asynchronously with an RPO of typically less than 15 minutes, and on failover you can access the secondary endpoint. For Azure SQL Database Hyperscale, geo-restore restores the database from geo-redundant backups to the secondary region; though its RPO is typically up to 1 hour, the requirement is met because you explicitly enable and test the restore procedure, and Hyperscale does not support failover groups, making geo-restore the documented DR pattern. This combination uses native, cost-effective services rather than running duplicate infrastructure and aligns with the stated 15-minute RPO for VMs and Files.

Why this answer

Azure Site Recovery provides VM replication with RPOs as low as 15 minutes and RTOs of minutes, meeting the 15-minute RPO and 30-minute RTO. Geo-redundant storage (GRS) for Azure Files ensures data is replicated to a paired secondary region with an RPO of 15 minutes (typically), and Azure SQL Database Hyperscale’s geo-restore allows restoring from geo-replicated backups, which can achieve the required RPO/RTO when tested and automated. This combination is cost-effective as it uses native Azure services without requiring a pre-provisioned secondary environment.

Exam trap

The trap here is that candidates may assume active geo-replication or failover groups are always available for Azure SQL Database, but the Hyperscale tier does not support these features, requiring geo-restore instead.

How to eliminate wrong answers

Option B is wrong because deploying a second set of VMs in a secondary region incurs ongoing compute costs, which is not cost-effective, and Azure File Sync does not provide the 15-minute RPO for Azure Files (sync intervals are configurable but typically longer). Option C is wrong because Azure Backup with a 15-minute frequency is not supported for Azure VMs (minimum frequency is 4 hours for application-consistent backups), and point-in-time restore for Azure SQL Database does not meet the 15-minute RPO for cross-region DR. Option D is wrong because active geo-replication for Azure SQL Database is not available for the Hyperscale tier; Hyperscale uses named replicas and geo-restore instead of failover groups or active geo-replication.

135
MCQmedium

A company runs a critical web application on Azure VMs in the West US region. They need a disaster recovery solution that replicates the VMs to the East US region. The recovery point objective (RPO) must be 30 minutes, and the recovery time objective (RTO) must be 1 hour. The company also needs to perform quarterly disaster recovery drills without impacting the production environment. Additionally, after a failover, the solution must automatically update traffic management to route users to the East US region. Which combination of Azure services should they use?

A.Azure Site Recovery and Azure Traffic Manager
B.Azure Backup and Azure Traffic Manager
C.Azure Site Recovery and Azure Front Door
D.Azure Backup and Azure Front Door
AnswerA

Azure Site Recovery handles VM replication with the required RPO/RTO and supports non-disruptive test failovers. Azure Traffic Manager can automatically route user traffic to the secondary region after failover by using endpoint monitoring and failover priority.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs from West US to East US, meeting the 30-minute RPO and 1-hour RTO. Azure Traffic Manager automatically updates DNS-based traffic routing to the East US region after failover, ensuring users are redirected without manual intervention. This combination satisfies all requirements: DR replication, RPO/RTO, quarterly drills (via test failover), and automated traffic management.

Exam trap

A common trap is to choose Azure Front Door because of its global routing capabilities, but Azure Traffic Manager is the correct fit here. Traffic Manager integrates natively with Azure Site Recovery recovery plans, enabling automatic DNS updates after failover. While Front Door can route based on health probes, it does not integrate directly with ASR recovery plans, requiring custom automation to update backend pools post-failover.

How to eliminate wrong answers

Option B is wrong because Azure Backup is designed for long-term data retention and point-in-time restore, not for full VM replication with orchestrated failover and RPO of 30 minutes; it cannot meet the RTO of 1 hour or support automated traffic rerouting after failover. Option C is wrong because Azure Front Door is a global load balancer and application delivery controller that uses anycast and HTTP-level routing, but it does not provide automatic traffic rerouting after a Site Recovery failover without manual DNS updates; Traffic Manager is the correct service for DNS-based failover routing. Option D is wrong because it combines Azure Backup (which lacks DR orchestration) with Azure Front Door (which does not automatically update routing after failover), failing both the replication and traffic management requirements.

136
MCQeasy

Your company uses Azure Backup to protect on-premises file servers and Azure VMs. The compliance team requires that backup data be stored in a secondary region to protect against regional disasters. Which Azure Backup feature should you enable?

A.Enable geo-redundant storage (GRS) for the Recovery Services vault
B.Use Azure Site Recovery to replicate the backup data
C.Configure backup policies to back up directly to the secondary region
D.Use a Recovery Services vault in the secondary region
AnswerA

Enabling geo-redundant storage (GRS) on the Recovery Services vault is the correct way to protect on-premises file backups against a regional disaster. GRS asynchronously replicates the vault's backup data to a paired Azure region, ensuring a second copy exists beyond the primary region's failure boundary. This replication is the built-in mechanism for making backup data resilient without requiring separate infrastructure or failover processes.

Why this answer

Azure Backup uses the Recovery Services vault as its management and storage container. By enabling geo-redundant storage (GRS) on the vault, backup data is automatically replicated to a paired secondary Azure region, meeting the compliance requirement for off-site disaster recovery without any additional configuration or separate vault.

Exam trap

The trap here is that candidates confuse Azure Site Recovery (which replicates workloads for failover) with Azure Backup's storage redundancy feature (which replicates backup data for durability), or they incorrectly assume that creating a vault in the secondary region alone provides cross-region backup storage.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery is a disaster recovery service for replicating and failing over workloads, not a feature for storing backup data in a secondary region. Option C is wrong because Azure Backup does not support direct backup to a secondary region; backup data is always written to the vault's primary region, and cross-region replication is handled by the vault's storage redundancy setting. Option D is wrong because simply creating a Recovery Services vault in the secondary region does not automatically replicate backup data from the primary region; you would need to manually configure backup policies to target that vault, which is not a built-in feature for cross-region backup storage.

137
MCQmedium

A company runs a SQL Server database on an Azure VM in West Europe. They need to back up the database daily and retain backups for 7 years for compliance. They also require the ability to restore the database to a secondary Azure region (North Europe) if the primary region fails. They want to minimize operational overhead and costs. Which Azure Backup configuration should they use?

A.A
B.B
C.C
D.D
AnswerA

Azure Backup for SQL Server in an Azure VM securely stores full, differential, and transaction log backups in a Recovery Services vault. You can configure the vault in West Europe as the primary region and enable the Cross-Region Restore (CRR) feature, which replicates the backup data to the paired North Europe region using geo-redundant storage (GRS). This design provides automated SQL-aware backup management, point-in-time restore capability, and the ability to restore databases in North Europe without deploying any additional backup infrastructure or vaults, making it the optimized, cost-effective approach.

Why this answer

Azure Backup's built-in cross-region restore (CRR) for Azure VMs allows you to restore SQL Server databases hosted on Azure VMs to a paired secondary region (North Europe) in the event of a disaster, while retaining backups for up to 10 years (covering the 7-year compliance requirement). This configuration minimizes operational overhead by using Azure Backup's native policy-based scheduling and storage management, and it is cost-effective as it uses geo-redundant storage (GRS) for the Recovery Services vault without needing a separate backup infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (ASR) with Azure Backup, thinking ASR can handle long-term backup retention, when in fact ASR is for replication and failover, not for point-in-time restores with multi-year retention, and they may overlook the need to explicitly enable cross-region restore (CRR) on the Recovery Services vault to meet the secondary region recovery requirement.

How to eliminate wrong answers

Option B is wrong because it suggests using Azure Site Recovery (ASR) for database backup, but ASR is designed for replication and failover of entire VMs, not for point-in-time database restore with long-term retention; it also incurs higher costs for continuous replication and does not natively support 7-year backup retention. Option C is wrong because it proposes backing up the SQL Server database to Azure Blob Storage using manual scripts or third-party tools, which increases operational overhead and does not integrate with Azure Backup's native cross-region restore or long-term retention policies. Option D is wrong because it recommends using Azure Backup for SQL Server on Azure VM but without enabling cross-region restore (CRR), which means backups are stored only in the primary region (West Europe) and cannot be restored to North Europe if the primary region fails, failing the disaster recovery requirement.

138
MCQeasy

A company runs a critical Azure SQL Database in the West US region. They need a disaster recovery solution that automatically fails over to a secondary region (East US) with a recovery point objective (RPO) of 5 seconds and a recovery time objective (RTO) of less than 1 hour. Additionally, they want to offload read-only workloads to the secondary database during normal operations. Which Azure SQL Database feature should they enable?

A.Active geo-replication with failover groups
B.Point-in-time restore
C.Long-term backup retention
D.Always On availability groups (self-managed)
AnswerA

Failover groups provide automatic failover to a readable secondary database. Active geo-replication synchronizes data with an RPO of 5 seconds and supports readable secondaries. The failover group ensures automatic failover with an RTO of typically less than 1 hour.

Why this answer

Active geo-replication with failover groups is the correct choice because it provides automatic, asynchronous replication of an Azure SQL Database to a secondary region (East US) with an RPO of up to 5 seconds and an RTO of less than 1 hour. Additionally, it supports readable secondary replicas, allowing read-only workloads to be offloaded to the secondary database during normal operations, meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse active geo-replication with failover groups (which supports readable secondaries and automatic failover) with standard active geo-replication (which requires manual failover and does not provide a single endpoint), or they mistakenly think Always On availability groups applies to Azure SQL Database instead of SQL Server on VMs.

How to eliminate wrong answers

Option B is wrong because point-in-time restore (PITR) only recovers the database to a specific point in time within the same region (retention up to 35 days) and does not provide cross-region failover or a readable secondary for offloading read workloads. Option C is wrong because long-term backup retention (LTR) stores backups for up to 10 years for compliance, but it does not enable automatic failover to a secondary region or support readable secondaries for read offloading. Option D is wrong because Always On availability groups (self-managed) is a feature for SQL Server on Azure Virtual Machines, not for Azure SQL Database managed service, and it requires manual configuration and management, not automatic failover with the specified RPO/RTO.

139
MCQmedium

A company backs up their Azure VMs using Azure Backup. They need to meet compliance that requires backups to be stored in a separate geographic region. Additionally, they want to be able to restore the entire VM to that secondary region in case of a regional disaster. What should they configure?

A.Use a Recovery Services vault with Locally Redundant Storage (LRS) and enable cross-region restore
B.Use a Recovery Services vault with Geo-Redundant Storage (GRS) and enable cross-region restore
C.Use Azure Site Recovery to replicate the entire VM to the secondary region
D.Manually copy backup snapshots to a storage account in the secondary region
AnswerB

A Recovery Services vault configured with geo-redundant storage (GRS) asynchronously replicates the backup data to the Azure paired secondary region, creating the exact copy needed for secondary-region recovery. By then enabling cross-region restore on the vault, Azure Backup exposes the replicated recovery points as native restore items in the secondary region, satisfying both the backup compliance requirement and the need to restore VMs in a different region. This is the only option that provides a fully managed, policy-driven backup while also enabling restore to the secondary region.

Why this answer

Azure Backup with a Recovery Services vault using Geo-Redundant Storage (GRS) replicates backup data to a paired secondary region, meeting the compliance requirement for geographic separation. Enabling cross-region restore allows the entire VM to be restored in that secondary region during a regional disaster, as the backup data is already available there.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (continuous replication for DR) with Azure Backup (snapshot-based backup with cross-region restore), leading them to select Option C, which does not meet the backup compliance requirement for stored backups in a separate region.

How to eliminate wrong answers

Option A is wrong because Locally Redundant Storage (LRS) keeps data only within a single datacenter in the primary region, failing the compliance requirement for storage in a separate geographic region. Option C is wrong because Azure Site Recovery is a disaster recovery solution that replicates the VM for continuous replication and failover, not for backup storage or restore from backup snapshots; it addresses different RPO/RTO needs but does not meet the backup compliance requirement. Option D is wrong because manually copying backup snapshots to a secondary region is inefficient, error-prone, and does not leverage Azure Backup's built-in cross-region restore capability, which is designed for automated, compliant disaster recovery.

140
Matchingmedium

Match each Azure security service to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Unified security management and threat protection

Cloud-native SIEM and SOAR

Manage secrets, keys, and certificates

Protect against distributed denial-of-service attacks

Managed cloud network security service

Why these pairings

Correct matches: Azure Sentinel (intelligent security analytics), Azure Firewall (network firewall). Common confusions: Security Center with Key Vault (secret management), Key Vault with DDoS Protection, DDoS Protection with Security Center.

141
MCQmedium

Your company runs a web application on Azure App Service (Standard tier) in a single region. You need to design a disaster recovery solution that can fail over to another region within 30 minutes. The application uses Azure SQL Database (General Purpose tier) and Azure Blob Storage. What should you implement?

A.Use Azure Traffic Manager with priority routing to a second App Service instance, use Azure SQL Database backup to a secondary region, and use Azure Storage zone-redundant storage (ZRS).
B.Configure App Service auto-scaling, use Azure SQL Database geo-replication with readable secondary, and use Azure Storage read-access geo-redundant storage (RA-GRS).
C.Configure App Service backup to a secondary region, use Azure SQL Database active geo-replication with auto-failover group, and use geo-redundant storage (GRS) for Blob Storage.
D.Configure App Service deployment slots, use Azure SQL Database geo-restore, and use Azure Storage locally-redundant storage (LRS).
AnswerC

App Service backup to a secondary region ensures that web application content, configuration, and files are recoverable in a different geographic location; the backup can be stored in a paired region and restored to a new App Service instance. Azure SQL Database active geo-replication with an auto-failover group continuously replicates data to a readable secondary database in another region and automatically promotes it during an outage, typically achieving an RTO of about one minute and an RPO of zero for committed transactions. Geo-redundant storage (GRS) replicates blobs asynchronously to a paired region, providing regional resilience and allowing manual or automated failover. This combination covers all layers—compute, database, and storage—with automated or nearly automated failover paths, making it the correct DR architecture.

Why this answer

It meets the 30-minute RTO by using Azure SQL Database active geo-replication with auto-failover groups, which provides automated, rapid failover to a secondary region. App Service backup to a secondary region ensures the web app can be restored quickly, and geo-redundant storage (GRS) for Blob Storage provides durable replication across regions, enabling failover within the required time frame.

Exam trap

The trap here is that candidates often confuse zone-redundant storage (ZRS) or locally-redundant storage (LRS) with geo-redundant options, failing to recognize that cross-region replication is mandatory for disaster recovery, and they may overlook the RTO constraints of geo-restore for SQL Database.

How to eliminate wrong answers

Option A is wrong because Azure Storage zone-redundant storage (ZRS) replicates data within a single region, not across regions, so it does not provide disaster recovery for a multi-region failover scenario. Option B is wrong because App Service auto-scaling only handles load within a region, not failover to another region, and read-access geo-redundant storage (RA-GRS) provides read access but does not guarantee failover within 30 minutes for writes. Option D is wrong because App Service deployment slots are for staging and swapping within the same region, not for cross-region failover, and Azure SQL Database geo-restore can take hours to complete, exceeding the 30-minute RTO.

142
Multi-Selectmedium

Which TWO of the following are requirements for using Azure Site Recovery to protect Azure VMs? (Choose two.)

Select 2 answers
A.VMs must use unmanaged disks
B.VMs must be using managed disks
C.VMs must be connected to a virtual network that has a VPN gateway to the target region
D.The source region must be a supported Azure region
E.VMs must be at least Standard_D2s_v3 size
AnswersB, D

Managed disks are a hard prerequisite for Azure Site Recovery of Azure IaaS VMs. ASR performs crash-consistent and app-consistent snapshots of these disks and replays them onto replica managed disks in the target region. Without managed disks, the replication engine has no supported configuration to process.

Why this answer

Azure Site Recovery for Azure VMs requires that the VMs use managed disks. Unmanaged disks are not supported because Site Recovery relies on the managed disk snapshot and replication capabilities to enable consistent, application-aware replication across regions. Managed disks also provide better performance, reliability, and integration with Azure's recovery services.

Exam trap

The trap here is that candidates often assume a VPN gateway is required for cross-region replication, but Azure Site Recovery uses the Azure internal network or public endpoints by default, and a VPN gateway is only needed if you choose private endpoint connectivity for security isolation.

143
MCQhard

Your company runs a stateless web application on Azure Kubernetes Service (AKS). You need to design a disaster recovery solution that ensures the application is available in another Azure region within 30 minutes of a regional failure. The solution must balance cost and complexity. What should you recommend?

A.Use Azure SQL Database active geo-replication for the application's database.
B.Use Azure Front Door to route traffic to a single AKS cluster with pods running in multiple regions.
C.Use Azure Traffic Manager to distribute traffic across two AKS clusters in different regions.
D.Deploy a single AKS cluster with nodes in multiple availability zones.
AnswerC

Azure Traffic Manager operates at the DNS level and can use priority routing to direct all traffic to the primary-region AKS cluster while continuously health-checking its endpoint; when the primary fails, Traffic Manager automatically fails over to the secondary-region cluster, meeting the RTO by keeping the stateless service available. Both clusters should be configured identically and expose the application through a load balancer or ingress service so users are seamlessly redirected.

Why this answer

Azure Traffic Manager can distribute traffic across two AKS clusters in different regions using DNS-based routing, such as priority or performance routing, enabling failover within the required 30-minute RTO. This approach balances cost and complexity by avoiding the need for active-active replication or complex multi-region pod configurations, while still meeting the stateless application's DR requirements.

Exam trap

The trap here is that candidates often confuse high availability within a region (availability zones) with disaster recovery across regions, leading them to choose Option D, which only protects against zonal failures, not regional outages.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database active geo-replication is a database-level solution, but the question specifies a stateless web application, implying the database is not the primary concern; moreover, it adds unnecessary cost and complexity for a stateless app. Option B is wrong because Azure Front Door routes traffic to a single AKS cluster, and while it can distribute traffic across regions, it requires pods to be deployed in multiple regions within that single cluster, which contradicts the single-cluster design and introduces complexity without clear DR isolation. Option D is wrong because deploying a single AKS cluster with nodes in multiple availability zones provides high availability within a single region, not disaster recovery across regions, and thus cannot ensure availability in another Azure region during a regional failure.

144
Multi-Selecteasy

Which TWO Azure services can be used to provide cross-region disaster recovery for Azure App Service web applications with a custom domain? (Select TWO.)

Select 2 answers
A.Azure DNS
B.Azure Front Door
C.Azure CDN
D.Azure Application Gateway
E.Azure Traffic Manager
AnswersB, E

Azure Front Door is a global, cloud-native entry point that uses anycast with the Microsoft global edge network to route HTTP/HTTPS traffic to the nearest healthy origin. It performs global load balancing, automatic failover, TLS termination, URL-based routing, and health probes at the application layer (L7). Its ability to monitor multiple regional backends and shift traffic instantly in response to health checks makes it a correct answer for providing cross-region resiliency.

Why this answer

Azure Front Door (B) provides global load balancing and traffic routing based on latency or priority, enabling cross-region failover for App Service web applications. It supports custom domains with TLS termination and health probes to automatically redirect traffic to a secondary region during a disaster. Azure Traffic Manager (E) also offers DNS-based traffic routing with priority or performance profiles, allowing failover to a secondary App Service instance in another region, and works with custom domains via CNAME records.

Exam trap

The trap here is that candidates often confuse Azure DNS (a domain registration and resolution service) with Traffic Manager (a DNS-based traffic routing service), or assume Azure Application Gateway can route cross-region traffic when it is strictly regional.

145
MCQmedium

A company runs a critical application on Azure VMs in a single region. The application writes data to Azure SQL Database (PaaS) and Azure Blob Storage. The company needs a disaster recovery plan with an RPO of less than 5 minutes for the database and less than 15 minutes for the blob storage, and an RTO of less than 1 hour for the entire solution. What should they recommend?

A.Use Azure Site Recovery for VMs, geo-replication for Azure SQL Database, and geo-redundant storage (GRS) for Blob Storage.
B.Use Azure Backup for VMs, geo-redundant storage for SQL Database backups, and geo-redundant storage for Blob Storage.
C.Use Azure Site Recovery for VMs, active geo-replication for Azure SQL Database, and read-access geo-redundant storage (RA-GRS) for Blob Storage.
D.Use Azure Front Door with multi-region deployment of VMs and Azure Cosmos DB for the database.
AnswerC

ASR replicates VMs with minutes RPO. Active geo-replication for Azure SQL Database provides a readable secondary with RPO seconds. RA-GRS provides a readable copy in the secondary region with ~15 minute RPO, meeting the blob requirement.

Why this answer

Azure Site Recovery provides the VM replication needed to meet the RTO of under 1 hour, active geo-replication for Azure SQL Database offers a configurable RPO of as low as 5 seconds (well under the 5-minute requirement), and RA-GRS for Blob Storage provides read-access to a secondary region with an RPO typically under 15 minutes, enabling fast failover and read access during a disaster.

Exam trap

The trap here is that candidates often confuse geo-redundant storage (GRS) with read-access geo-redundant storage (RA-GRS), not realizing that GRS requires a storage account failover to access the secondary region, which can take up to an hour and thus fails the RTO requirement.

How to eliminate wrong answers

Option A is wrong because geo-redundant storage (GRS) for Blob Storage does not provide read access to the secondary region during a disaster; you must initiate a failover to read data, which can exceed the RTO of 1 hour. Option B is wrong because Azure Backup for VMs is a backup solution, not a replication solution, and cannot achieve an RTO of under 1 hour for full VM failover; additionally, geo-redundant storage for SQL Database backups does not provide the sub-5-minute RPO required, as backups are typically taken every 5–10 minutes. Option D is wrong because Azure Front Door with multi-region VMs and Cosmos DB does not address the existing Azure SQL Database and Blob Storage requirements; it changes the architecture entirely and does not meet the stated RPO/RTO for the current services.

146
MCQmedium

Your company has a critical application that uses Azure Kubernetes Service (AKS) in a single region. You need to design a disaster recovery solution that can automatically fail over to a secondary region in the event of a regional outage. The application data is stored in Azure Cosmos DB. What should you do?

A.Use Azure Front Door to route traffic to the primary AKS cluster and enable Cosmos DB automatic failover.
B.Use Azure Backup for AKS with cross-region restore and Cosmos DB geo-redundancy.
C.Replicate the AKS cluster to another region using Azure Site Recovery.
D.Deploy a secondary AKS cluster in another region, use Azure Traffic Manager for global load balancing, and enable Cosmos DB multi-region writes.
AnswerD

Deploying a secondary AKS cluster in another region provides compute placement outside the primary region's blast radius, and Azure Traffic Manager uses DNS-based routing to automatically direct user traffic to the healthy cluster when health probes detect a regional failure. Enabling Cosmos DB multi-region writes creates an active-active data platform where both AKS clusters can read and write local replicas, eliminating a single point of failure for data. This combination achieves regional failover at both compute and data layers, satisfying strict RTO/RPO requirements without manual intervention.

Why this answer

It provides a comprehensive disaster recovery solution for both the compute and data tiers. Deploying a secondary AKS cluster in another region ensures compute capacity is available after a regional outage. Azure Traffic Manager (using priority routing) directs traffic to the primary cluster and automatically fails over to the secondary.

Enabling Cosmos DB multi-region writes allows the application to write to the secondary region without conflict, ensuring data availability and consistency during failover.

Exam trap

The trap here is that candidates often confuse Azure Front Door (which is for global HTTP load balancing with acceleration) with Azure Traffic Manager (which is for DNS-based global traffic routing and failover), and they overlook that AKS clusters cannot be replicated via Azure Site Recovery because it is designed for VM-level replication, not container orchestration platforms.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global load balancer for HTTP/S traffic but does not natively support automatic failover for AKS clusters; it would require manual configuration or custom health probes, and enabling Cosmos DB automatic failover alone does not address the compute tier's availability. Option B is wrong because Azure Backup for AKS with cross-region restore is a backup solution, not an automated failover mechanism; it involves restoring from backups, which incurs significant recovery time (RTO) and does not provide real-time failover. Option C is wrong because Azure Site Recovery is designed for IaaS VMs, not for AKS clusters; it cannot replicate Kubernetes control planes, node pools, or containerized workloads effectively, and it does not support Cosmos DB data replication.

147
MCQhard

A business-critical App Service application must survive a full regional outage. The recovery design should fail over automatically based on endpoint health and avoid DNS-cache delay where possible. Which service should front the regional deployments?

A.Azure Load Balancer
B.Azure Application Security Groups
C.Azure Front Door
D.Azure Traffic Manager only
AnswerC

Azure Front Door is a global, cloud-native entry point that provides HTTP/S load balancing, SSL offload, path-based routing, and—critically—health-probe-driven automatic failover across multiple regions. By continuously probing the health of backends, Front Door can detect a regional outage and route traffic to the nearest healthy regional endpoint, typically in seconds, without relying on client DNS cache timeouts. It also supports session affinity, URL rewrite, and Web Application Firewall (WAF) policies, making it the correct choice for a business-critical web app that must survive a full region failure.

Why this answer

Azure Front Door is the correct choice because it provides global HTTP/HTTPS load balancing with automatic failover across regions based on real-time endpoint health probes. It uses Anycast routing to direct traffic to the nearest healthy region, which avoids DNS-cache delay inherent in DNS-based solutions like Traffic Manager. This ensures sub-second failover and meets the requirement for a business-critical app that must survive a full regional outage.

Exam trap

The trap here is that candidates confuse Azure Traffic Manager's DNS-based global routing with Azure Front Door's Anycast-based global routing, overlooking the critical DNS-cache delay that Traffic Manager introduces.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 and is regional, not global; it cannot fail over traffic across regions in a full regional outage. Option B is wrong because Azure Application Security Groups are a network security feature for grouping VMs and applying security rules, not a traffic routing or failover service. Option D is wrong because Azure Traffic Manager is DNS-based and relies on client DNS caching, which can cause delays of minutes during failover, violating the requirement to avoid DNS-cache delay.

148
MCQhard

A multinational company runs a mission-critical application on Azure VMs in the West US region. The application uses Azure SQL Database (Business Critical tier) and Azure Cache for Redis. The company needs to ensure the application can fail over to a secondary region within 5 minutes during a regional outage. The design must minimize data loss. Which solution should you recommend?

A.Deploy VMs across Azure availability zones in West US, use Azure SQL Database geo-restore to East US, and deploy a second Azure Cache for Redis instance in East US.
B.Deploy VMs in an availability set in West US, use Azure Site Recovery to replicate to East US, and configure Azure SQL Database failover group with manual failover.
C.Deploy VMs in an Azure Site Recovery recovery plan to East US, use Azure SQL Database active geo-replication with auto-failover group, and deploy Azure Cache for Redis Standard tier in East US.
D.Deploy VMs in an Azure Site Recovery recovery plan to East US, use Azure SQL Database active geo-replication with auto-failover group, and use Azure Cache for Redis with geo-replication enabled.
AnswerD

Azure Site Recovery orchestrates VM failover to East US within minutes, while active geo-replication with auto-failover groups provides the SQL Database secondary and minimal data loss. Redis geo-replication completes the stack, meeting the five-minute regional failover constraint.

Why this answer

It ensures all components can fail over to East US within 5 minutes with minimal data loss. Azure Site Recovery (ASR) provides orchestrated VM replication with RTO typically under 5 minutes. Azure SQL Database active geo-replication with auto-failover groups offers RPO of 5 seconds and RTO of ~1 minute, meeting the 5-minute target and minimizing data loss.

Azure Cache for Redis geo-replication (Premium tier) replicates cache data asynchronously, providing a warm standby cache in East US to reduce data loss. Option A fails because availability zones do not protect against a regional outage and geo-restore has longer RTO. Option B uses availability sets (no regional protection) and manual failover for SQL (exceeds 5 minutes).

Option C uses Standard tier Redis which lacks geo-replication, leading to data loss.

Exam trap

The trap here is that candidates often assume any Azure Cache for Redis tier supports geo-replication, but only the Premium tier offers this feature, making option C a common distractor.

How to eliminate wrong answers

Option A is wrong because geo-restore for Azure SQL Database has an RTO of hours (not minutes) and does not support automated failover, and deploying a second Redis instance without geo-replication does not provide automatic data synchronization or failover. Option B is wrong because Azure SQL Database failover group with manual failover requires human intervention, which can exceed the 5-minute RTO, and availability sets only protect against rack-level failures within a single region, not regional outages. Option C is wrong because Azure Cache for Redis Standard tier does not support geo-replication (only Premium tier does), so cache data would be lost during failover, violating the minimize data loss requirement.

149
MCQeasy

You are a Solutions Architect for an e-commerce company that runs its online store on Azure. The application consists of: - Azure App Service (Windows) hosting the web frontend - Azure SQL Database (General Purpose, serverless) for product catalog and orders - Azure Cache for Redis for session state - Azure Blob Storage for product images The application is deployed in the East US region. The company wants to implement a disaster recovery (DR) plan that can fail over to a secondary region (West US) with minimal data loss. The requirements are: - RPO: 5 minutes for the database - RTO: 30 minutes for the entire application - The solution must be cost-effective and not require manual intervention during failover. Which of the following is the BEST course of action to meet these requirements?

A.Use Azure Backup for the SQL database with 5-minute backup frequency, deploy App Service in West US with staging slots, and use Azure Traffic Manager with priority routing.
B.Configure Azure SQL Database geo-replication with readable secondary, deploy App Service in West US with deployment slots, and use Azure Front Door with health probes. Cache for Redis is not critical and can be rebuilt.
C.Configure Azure SQL Database active geo-replication with auto-failover group, deploy App Service in West US with a separate App Service plan, enable geo-replication for Cache for Redis, and use RA-GRS for Blob Storage. Use Azure Traffic Manager with priority routing for the web app.
D.Deploy the entire application in an active-active configuration using Azure Front Door, with Azure SQL Database using failover groups and manual failover. Use Azure Backup for the database with 1-hour backup frequency.
AnswerC

Active geo-replication with an auto-failover group meets the RPO requirement by continuously replicating changes to a secondary database with a typical RPO of 5 seconds and automating failover on regional outage, which keeps RTO low. A separate App Service plan in West US, combined with Azure Traffic Manager priority routing, ensures that the web tier can fail over to the secondary region automatically when the primary is unhealthy. Enabling geo-replication for Cache for Redis preserves session or cached data across regions, while RA-GRS for Blob Storage provides a secondary read-only copy of static assets such as images and product catalogs, which can tolerate a slightly higher RPO without affecting transactional integrity.

Why this answer

It meets all requirements: Azure SQL Database active geo-replication with auto-failover groups provides an RPO of 5 seconds (well within the 5-minute requirement) and automated failover without manual intervention. Deploying App Service in West US with a separate App Service plan ensures capacity for failover, and geo-replication for Cache for Redis preserves session state to avoid data loss. RA-GRS for Blob Storage provides read access in the secondary region, and Azure Traffic Manager with priority routing enables automatic failover of the web frontend within the 30-minute RTO.

Exam trap

The trap here is that candidates often confuse Azure SQL Database geo-replication (manual failover) with auto-failover groups (automatic failover), leading them to select Option B which fails the 'no manual intervention' requirement.

How to eliminate wrong answers

Option A is wrong because Azure Backup with 5-minute frequency cannot achieve an RPO of 5 minutes for Azure SQL Database (backup frequency is limited to 12 hours for SQL DB), and using staging slots for DR is not designed for automatic failover—they require manual swap and do not provide geo-redundancy. Option B is wrong because Azure SQL Database geo-replication with readable secondary does not support auto-failover groups; failover must be initiated manually, violating the 'no manual intervention' requirement. Option D is wrong because it uses manual failover for the database (violating the no-manual-intervention requirement) and Azure Backup with 1-hour backup frequency exceeds the 5-minute RPO; active-active configuration with Azure Front Door is unnecessary and increases cost without meeting the stated RPO.

150
MCQmedium

A company runs an application on Azure VMs that must be backed up according to regulatory compliance: daily backups retained for 30 days, weekly backups retained for 12 months, and yearly backups retained for 7 years. The backups must be stored in a secondary region for disaster recovery. They want to use Azure Backup for VMs. Which backup policy and storage configuration should they implement?

A.Configure a backup policy in Azure Backup for VMs with daily, weekly, and yearly retention rules, and enable cross-region restore by using a Recovery Services Vault with geo-redundant storage.
B.Enable backup with Azure Backup using the default policy and select Geo-Redundant Storage (GRS) for the Recovery Services Vault.
C.Use Azure Site Recovery to replicate VMs to the secondary region and configure retention policies in the replication settings.
D.Perform file-level backups using Azure Backup and store them in a separate storage account with read-access geo-redundant storage (RA-GRS).
AnswerA

This is the correct approach because Azure Backup for VMs allows you to create a custom backup policy in a Recovery Services Vault, specifying multiple retention rules for daily, weekly, and yearly recovery points. The vault must be configured with geo-redundant storage (GRS), and you must enable the cross-region restore feature on the vault, which then permits restoring VM backups to the paired secondary Azure region for disaster avoidance. This combination meets the requirement for scheduled backups with long-term retention and off-region recoverability.

Why this answer

Azure Backup for VMs allows you to create a custom backup policy with daily, weekly, and yearly retention points, meeting the regulatory requirements. By enabling cross-region restore (CRR) on a Recovery Services Vault configured with geo-redundant storage (GRS), backups are automatically replicated to a paired secondary region, providing disaster recovery without additional infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with Azure Backup (long-term retention), or assume the default policy can be customized to include yearly retention without realizing it must be explicitly configured.

How to eliminate wrong answers

Option B is wrong because the default backup policy in Azure Backup does not include yearly retention rules, so it cannot meet the 7-year yearly retention requirement. Option C is wrong because Azure Site Recovery is designed for replication and failover, not for long-term backup retention; it does not support granular retention policies like daily, weekly, and yearly backups. Option D is wrong because file-level backups do not capture the full VM state (including OS and application consistency), and RA-GRS storage alone does not provide the integrated backup policy with retention rules required for compliance.

← PreviousPage 2 of 3 · 152 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design business continuity solutions questions.

CCNA Design business continuity solutions Questions — Page 2 of 3 | Courseiva