Courseiva

CCNA Design data storage solutions Questions

75 of 180 questions · Page 1/3 · Design data storage solutions · Answers revealed

1
MCQmedium

Refer to the exhibit. An organization deploys this ARM template to create a storage account. They need to ensure that data is replicated synchronously across two Azure regions. Does this template meet the requirement?

A.No, the template uses RA-GRS
B.Yes, GRS provides synchronous replication
C.No, the template uses LRS
D.No, GRS provides asynchronous replication
AnswerD

The correct answer is 'No' because GRS replicates data asynchronously to a secondary region, meaning there is a lag between writes to the primary and their availability in the secondary. Azure's GRS and RA-GRS are always asynchronous for cross-region copies, unlike LRS/ZRS which are synchronous within the primary region. This asynchronous behavior introduces a recovery point objective (RPO) that can be minutes or hours, so GRS does not provide synchronous replication.

Why this answer

The template uses GRS (Geo-Redundant Storage), which replicates data asynchronously from the primary region to the secondary region. Because the replication is asynchronous, there is a potential for data loss if a regional disaster occurs before the secondary region is fully updated. The requirement specifies synchronous replication across two Azure regions, which is only provided by Azure Storage’s geo-zone-redundant storage (GZRS) with read-access (RA-GZRS) or by using Azure Files with synchronous replication via Azure File Sync or a third-party solution.

Therefore, GRS does not meet the synchronous requirement.

Exam trap

The trap here is that candidates often confuse GRS’s geo-redundancy with synchronous replication, not realizing that GRS uses asynchronous replication to the secondary region, while synchronous replication is only available within a single region (LRS, ZRS) or across availability zones (ZRS).

How to eliminate wrong answers

Option A is wrong because RA-GRS (Read-Access Geo-Redundant Storage) is not used in the template; the template specifies GRS, and RA-GRS also uses asynchronous replication, so it would not meet the synchronous requirement either. Option B is wrong because GRS provides asynchronous replication, not synchronous; synchronous replication across regions is not a feature of standard Azure Storage replication options. Option C is wrong because the template does not use LRS (Locally Redundant Storage); it uses GRS, which replicates to a secondary region, but the core issue is that GRS is asynchronous, not synchronous.

2
MCQmedium

A company runs a data analytics application that stores large volumes of structured data in a relational format. The data is write-intensive and the application needs to scale horizontally for high throughput. The solution must support SQL queries, including joins and ACID transactions. Which Azure database service should they choose?

A.Azure Database for PostgreSQL - Hyperscale (Citus)
B.Azure SQL Database Hyperscale
C.Azure Cosmos DB (SQL API)
D.Azure Synapse Analytics
AnswerA

Azure Database for PostgreSQL - Hyperscale (Citus) extends PostgreSQL by sharding tables across multiple worker nodes using a coordinator node, allowing the cluster to handle both large analytical scans and high-throughput OLTP queries without abandoning relational semantics. It supports full SQL including multi-table joins and ACID transactions across distributed tables, making it the only listed option that combines horizontal write scalability with strong consistency and relational query power. This fits a data analytics application that needs to ingest and query data at scale while preserving transactional integrity.

Why this answer

Azure Database for PostgreSQL - Hyperscale (Citus) is correct because it provides horizontal scaling (sharding) across multiple nodes while preserving full SQL support, including JOINs and ACID transactions. Citus distributes data across worker nodes using a coordinator node, enabling write-intensive workloads to achieve high throughput through parallelized writes. This makes it ideal for large-volume, relational, write-heavy analytics applications that require relational integrity.

Exam trap

The trap here is that candidates often confuse Azure SQL Database Hyperscale's 'scale-out' read replicas with true horizontal write scaling, or they assume Cosmos DB's SQL API supports relational queries and transactions, when in fact it is a NoSQL store with limited consistency and no JOIN support.

How to eliminate wrong answers

Option B (Azure SQL Database Hyperscale) is wrong because it scales compute and storage vertically, not horizontally for write throughput; it is designed for large databases with high read scalability, not write-intensive horizontal scaling. Option C (Azure Cosmos DB SQL API) is wrong because it is a NoSQL database that does not support SQL JOINs or ACID transactions across multiple documents; it uses eventual consistency by default and lacks relational integrity. Option D (Azure Synapse Analytics) is wrong because it is a massively parallel processing (MPP) data warehouse optimized for analytical queries on large datasets, not for transactional, write-intensive workloads with ACID compliance; it uses a columnar store and does not support point-write transactions with the same isolation levels as a relational OLTP database.

3
MCQeasy

You have an Azure SQL Database that stores sales data. You need to ensure that the database can recover to any point in time within the last 35 days. What should you configure?

A.Configure the point-in-time restore (PITR) retention period to 35 days
B.Configure long-term retention (LTR) backups with a retention of 35 days
C.Create a secondary database in the same region
D.Enable geo-replication with a readable secondary
AnswerA

Point-in-time restore (PITR) is the native Azure SQL Database feature designed to recover a database to any precise point within a configurable retention window, with a maximum retention of 35 days. Automatic full, differential, and transaction log backups (taken every 5–10 minutes) let you restore to nearly any second in that window, making a 35-day PITR setting exactly what is needed to recover sales data lost or changed up to 35 days ago.

Why this answer

Point-in-time restore (PITR) for Azure SQL Database allows you to restore a database to any point within the configured retention period. The default retention is 7 days, but you can increase it up to 35 days. By setting the PITR retention period to 35 days, you meet the requirement to recover to any point in time within the last 35 days.

Exam trap

The trap here is confusing long-term retention (LTR) with point-in-time restore (PITR); candidates often think LTR provides point-in-time recovery, but LTR only retains full backups at fixed intervals and cannot restore to an arbitrary point within the retention window.

How to eliminate wrong answers

Option B is wrong because long-term retention (LTR) backups are designed for retaining full backups for extended periods (up to 10 years) and do not support point-in-time recovery; they only allow restoration to specific full backup timestamps, not any point in time. Option C is wrong because creating a secondary database in the same region provides high availability and failover capability but does not enable point-in-time recovery to any arbitrary time within the last 35 days. Option D is wrong because geo-replication with a readable secondary provides disaster recovery and read-scale out, but it does not offer point-in-time restore functionality; it replicates data asynchronously and cannot recover to an arbitrary past point.

4
MCQeasy

You need to store semi-structured data from IoT devices in Azure. The data has varying schemas and high write throughput. Which Azure service should you use?

A.Azure Blob Storage.
B.Azure SQL Database.
C.Azure Cosmos DB.
D.Azure Table Storage.
AnswerC

Azure Cosmos DB is a multi-model, schema-agnostic NoSQL database designed specifically for globally distributed, semi-structured data such as JSON documents emitted by IoT devices. Its automatic indexing of every property enables flexible, ad-hoc queries without requiring schema changes, while partitions provide horizontal scaling for high write throughput and sub-10-ms responses. Cosmos DB also supports multiple consistency levels and turnkey global distribution, making it ideal for IoT workloads that need low-latency reads and writes across regions. This combination of schema flexibility, elastic scaling, and query capability is why it is the correct choice.

Why this answer

Azure Cosmos DB is the correct choice because it is a globally distributed, multi-model database service designed for high write throughput and semi-structured data with varying schemas. It supports multiple APIs (e.g., SQL, MongoDB, Cassandra) and offers single-digit millisecond latency at any scale, making it ideal for IoT scenarios where device telemetry has inconsistent fields and requires rapid ingestion.

Exam trap

The trap here is that candidates often confuse Azure Table Storage with Cosmos DB because both are NoSQL, but Table Storage lacks the global distribution, multi-model APIs, and guaranteed high throughput that Cosmos DB provides, making it a weaker choice for high-write IoT workloads.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage is optimized for unstructured binary or text data (e.g., images, logs) and lacks native querying capabilities for semi-structured data with varying schemas; it does not provide the high write throughput and schema flexibility needed for IoT device data. Option B is wrong because Azure SQL Database is a relational database that enforces a fixed schema, requiring schema changes for each new device field, and its write throughput is limited compared to Cosmos DB's horizontal scaling for high-velocity IoT ingestion. Option D is wrong because Azure Table Storage is a NoSQL key-value store that can handle semi-structured data, but it lacks the global distribution, multi-model support, and guaranteed low-latency write throughput that Cosmos DB offers; it is also limited to a single index on partition and row keys, making it less suitable for complex query patterns.

5
MCQhard

An organization is migrating on-premises Oracle databases to Azure. They require minimal code changes and support for Oracle PL/SQL stored procedures. Which Azure data service best meets these requirements?

A.Azure Database for MySQL
B.Azure Database for PostgreSQL with Oracle compatibility
C.Azure SQL Database
D.Azure Cosmos DB
AnswerB

Azure Database for PostgreSQL can be configured with an Oracle compatibility mode via the orafce extension, which emulates Oracle built-in functions, data types, and PL/SQL constructs. This compatibility layer allows many existing PL/SQL stored procedures, triggers, and functions to run with minimal or no modifications, significantly reducing migration effort. It is not a perfect one-to-one replacement, but it is the most viable managed service for preserving Oracle code logic in Azure, making it the correct choice for this migration.

Why this answer

Azure Database for PostgreSQL with the Oracle compatibility extension (e.g., orafce) provides support for Oracle PL/SQL stored procedures and syntax, minimizing code changes during migration. This service is designed to handle Oracle workloads with minimal re-engineering, unlike other Azure database options that lack native Oracle compatibility.

Exam trap

The trap here is that candidates often assume Azure SQL Database is the natural choice for Oracle migrations due to its relational nature, but it lacks native PL/SQL support, whereas PostgreSQL with Oracle compatibility is the correct service for minimizing code changes.

How to eliminate wrong answers

Option A is wrong because Azure Database for MySQL does not support Oracle PL/SQL stored procedures or Oracle-specific syntax, requiring significant code rewrites. Option C is wrong because Azure SQL Database uses T-SQL, not PL/SQL, and lacks direct compatibility with Oracle stored procedures, necessitating manual conversion. Option D is wrong because Azure Cosmos DB is a NoSQL database that does not support relational Oracle PL/SQL stored procedures or schema-based migrations.

6
MCQhard

You deploy the above ARM template. The deployment succeeds. However, you cannot access the storage account from the Azure portal. What is the most likely reason?

A.The storage account is configured to require HTTPS traffic only.
B.The network ACLs deny all traffic by default, and no allow rules are configured.
C.The minimum TLS version is set to TLS 1.2, which is not supported by the portal.
D.The encryption key source is set to Microsoft.Storage, which prevents portal access.
AnswerB

The network ACLs are the key culprit. In the ARM template, the default action is explicitly set to 'Deny' and no IP rules or virtual network rules are included, so the public endpoint is effectively locked down. When you open the storage account in the Azure portal, the portal's management pane uses the control plane to show settings, but trying to view or edit containers, blobs, or data relies on a data plane request from your client's public IP address, which is not permitted by the ACLs. Thus, the deployment succeeds but data operation access from the portal is impossible.

Why this answer

The ARM template likely includes a network ACL configuration that, by default, denies all traffic. Without explicit allow rules for the Azure portal's IP ranges or the 'Allow trusted Microsoft services' exception, the portal cannot reach the storage account's management endpoints, resulting in an inability to access it from the portal despite a successful deployment.

Exam trap

The trap here is that candidates often overlook network ACLs as a cause for portal access failure, mistakenly focusing on TLS versions or encryption settings, which do not affect basic connectivity from the Azure portal.

How to eliminate wrong answers

Option A is wrong because requiring HTTPS traffic only does not block portal access; the portal uses HTTPS to communicate with storage accounts, so this setting would not prevent access. Option C is wrong because the Azure portal fully supports TLS 1.2; setting the minimum TLS version to 1.2 does not block portal access, as the portal uses TLS 1.2 or higher. Option D is wrong because setting the encryption key source to Microsoft.Storage is the default and does not affect portal access; portal connectivity is independent of encryption key management.

7
MCQmedium

A media company needs to store large video files that are frequently accessed for the first month, then infrequently after that. They want to minimize storage costs while ensuring files are instantly accessible when needed. Which storage strategy should they implement?

A.Store all files in the hot access tier
B.Manually move files between tiers using AzCopy
C.Store all files in the archive access tier
D.Use Azure Blob Storage lifecycle management to move files from hot to cool after 30 days
AnswerD

Azure Blob Storage lifecycle management lets you define a policy that automatically transitions blobs from the hot tier to the cool tier after 30 days since last modification, matching the stated access pattern. This is the correct approach because it is server-side, transparent, and eliminates manual intervention while reducing storage costs as content ages. The cool tier still offers low-latency reads, so any occasional access to older videos remains convenient without paying hot-tier storage rates. Because lifecycle management manipulates tier metadata rather than copying data, it avoids the network and compute overhead associated with manual moves.

Why this answer

Azure Blob Storage lifecycle management allows you to define rules that automatically transition blobs from the hot tier (frequent access) to the cool tier (infrequent access) after a specified number of days. This meets the requirement of instant accessibility for the first month and cost minimization thereafter, as the cool tier offers lower storage costs with the same low-latency access as the hot tier.

Exam trap

The trap here is that candidates may choose manual tiering (Option B) thinking it offers more control, but the exam tests the understanding that Azure's built-in lifecycle management is the automated, cost-optimized solution for predictable access patterns, and that archive tier (Option C) is not instantly accessible.

How to eliminate wrong answers

Option A is wrong because storing all files in the hot access tier incurs higher storage costs for the infrequently accessed period after the first month, failing to minimize costs. Option B is wrong because manually moving files between tiers using AzCopy is not a scalable or automated solution; it requires ongoing operational overhead and does not provide a policy-driven, cost-effective strategy for large volumes of files. Option C is wrong because the archive access tier has a retrieval latency of several hours (up to 15 hours for rehydration), which violates the requirement for instant accessibility when files are needed.

8
MCQeasy

You are reviewing the data protection settings of an Azure Blob Storage container using the above JSON. Which of the following is true?

A.Deleted blobs are retained for 30 days
B.Blobs can be restored to any point within the last 7 days
C.Previous versions of blobs are retained
D.Versioning is disabled
AnswerC

This statement is correct because the account has blob versioning enabled (isVersioningEnabled is true). When versioning is enabled, every modification or deletion of a blob creates a new version, and all previous versions are preserved. This allows you to retrieve or restore an earlier version of a blob at any time, independent of soft-delete or point-in-time restore policies.

Why this answer

The JSON shows that the `versioning` property is set to `Enabled` for the Blob Storage container. When versioning is enabled, every modification to a blob creates a new version, and previous versions are retained indefinitely (or until explicitly deleted or a lifecycle management policy removes them). This directly supports the statement that previous versions of blobs are retained.

Exam trap

The trap here is that candidates may confuse versioning with soft delete or point-in-time restore, assuming that versioning alone provides a specific retention period or point-in-time recovery capability, when in fact versioning retains all versions indefinitely unless a lifecycle policy is applied.

How to eliminate wrong answers

Option A is wrong because the JSON does not specify a soft-delete retention period; the `deleteRetentionPolicy` is not shown or is set to a different value, and the default soft-delete retention for blobs is 7 days, not 30 days. Option B is wrong because point-in-time restore requires both versioning and change feed to be enabled, and the JSON does not indicate that change feed is enabled; additionally, point-in-time restore has a maximum retention period of 30 days, not 7 days. Option D is wrong because the JSON explicitly shows `"versioning": "Enabled"`, meaning versioning is enabled, not disabled.

9
MCQmedium

A software company hosts 100 small Azure SQL databases for different clients. Each database has low average usage but experiences unpredictable spikes. The company wants to minimize costs while allowing each database to burst up to a maximum resource limit during spikes. They also need to easily add new databases without manual sizing. Which Azure SQL Database deployment option should they use?

A.Elastic pools
B.Single databases with DTU-based tiers
C.Managed Instance
D.Hyperscale single database
AnswerA

Elastic pools are ideal for managing multiple databases with unpredictable, variable usage because they let a set of databases share a single pool of eDTUs or vCores. Each database can burst up to its per-database maximum using resources released by idle databases, while you set a per-database minimum to guarantee performance. This pooling model significantly reduces cost compared to provisioning dedicated resources per database, and adding or removing databases is an automated, simple operation. It is precisely the right fit for a large fleet of small, spiky workloads.

Why this answer

Elastic pools allow multiple databases with low average usage and unpredictable spikes to share a fixed pool of resources (eDTUs or eVCores), enabling each database to burst up to a maximum limit while minimizing overall cost. This model also supports easy addition of new databases without manual sizing, as they are simply added to the pool and share its allocated resources.

Exam trap

The trap here is that candidates may choose single databases with DTU-based tiers because they think 'bursting' requires dedicated resources, but they overlook the cost inefficiency and manual sizing overhead of managing many small databases individually.

How to eliminate wrong answers

Option B is wrong because single databases with DTU-based tiers require individual sizing and do not share resources, leading to higher costs for many low-usage databases that need burst capacity. Option C is wrong because Managed Instance is designed for lift-and-shift scenarios with full SQL Server instance-level features, not for cost-efficient multi-tenant database management with burst behavior. Option D is wrong because Hyperscale single database is optimized for very large databases (up to 100 TB) with high throughput and fast scaling, not for many small databases with unpredictable spikes where resource sharing is more cost-effective.

10
MCQmedium

A company stores unstructured data such as documents and images in Azure Blob Storage. The data is accessed frequently for the first month, then only rarely for the next year, and after that must be retained for 10 years for compliance. The company wants to minimize storage costs by automatically moving data to the most cost-effective storage tiers. Which Azure Blob Storage feature should they implement?

A.Lifecycle management policies
B.Azure Data Lake Storage access tiers
C.Soft delete
D.Immutability policies
AnswerA

Azure Blob Storage lifecycle management policies enable automatic transition of blobs to cooler tiers (Cool, Archive) based on age. The policy can move data from Hot to Cool after 30 days, then to Archive after one year, meeting the access pattern and minimizing costs.

Why this answer

Lifecycle management policies in Azure Blob Storage allow you to automatically transition blobs to cooler tiers (e.g., from Hot to Cool, then to Archive) based on age or last modification time. This directly matches the requirement to move data from frequent access (first month) to rare access (next year) and then to long-term retention (10 years) while minimizing costs.

Exam trap

The trap here is that candidates confuse storage tiers (Hot, Cool, Archive) with the automation feature (lifecycle management) that moves data between them, assuming tiers alone handle cost optimization without explicit policies.

How to eliminate wrong answers

Option B is wrong because Azure Data Lake Storage access tiers (Hot, Cool, Archive) are storage tiers themselves, not an automated policy; they require manual tier selection or lifecycle rules to move data between them. Option C is wrong because soft delete is a data protection feature that recovers accidentally deleted blobs, not a cost-optimization mechanism for tier transitions. Option D is wrong because immutability policies (WORM) prevent data modification or deletion for compliance, but do not automate tier transitions or reduce storage costs.

11
MCQhard

Refer to the exhibit. Your team deploys this ARM template to a resource group in West US. After deployment, you need to ensure the storage account is geo-redundant. What is the most efficient way to modify the template to achieve this?

A.Add a second storage account resource with Geo-redundant replication.
B.Change the 'kind' property to 'BlobStorage'.
C.Change the 'apiVersion' to a newer version.
D.Change the 'sku.name' property from 'Standard_LRS' to 'Standard_GRS'.
AnswerD

Set `sku.name` to `Standard_GRS` because this SKU explicitly configures geo-redundant storage (GRS) for the account. With GRS, data is synchronously replicated three times within the primary region and asynchronously replicated three times in the paired secondary region, providing higher durability than LRS. In the ARM template, `sku.name` is the authoritative property for the replication strategy, and `Standard_GRS` meets the geo-redundancy requirement.

Why this answer

Changing the 'sku.name' property from 'Standard_LRS' to 'Standard_GRS' directly modifies the replication type of the existing storage account to geo-redundant storage (GRS). This is the most efficient approach as it updates the single resource in-place without adding extra resources or altering the storage account's kind or API version.

Exam trap

The trap here is that candidates may think adding a new resource or changing the API version is necessary, but the most efficient way is to modify the existing resource's 'sku.name' property, which directly controls replication redundancy.

How to eliminate wrong answers

Option A is wrong because adding a second storage account with Geo-redundant replication does not make the existing storage account geo-redundant; it creates a separate resource, which is inefficient and does not meet the requirement. Option B is wrong because changing the 'kind' property to 'BlobStorage' changes the storage account type to blob-only storage, which does not affect replication redundancy; replication is controlled by the 'sku.name' property. Option C is wrong because changing the 'apiVersion' to a newer version does not alter the replication setting; the 'apiVersion' only defines the schema version for the template and does not impact resource properties like redundancy.

12
Multi-Selecteasy

Which TWO of the following Azure storage services support hosting static websites?

Select 2 answers
A.Azure Storage Account (general-purpose v2)
B.Azure Cosmos DB
C.Azure NetApp Files
D.Azure Blob Storage
E.Azure Files
AnswersA, D

A general-purpose v2 storage account is the management object that exposes the static website feature. When you enable the 'Static website' property, Azure provisions a dedicated web endpoint and a hidden `$web` blob container that serves your HTML, CSS, and JavaScript files with HTTP GET requests, supporting custom domains and CDN integration.

Why this answer

Azure Storage Account (general-purpose v2) supports hosting static websites by enabling the 'Static website' feature, which configures a container named '$web' to serve static content (HTML, CSS, JS) directly via a public endpoint. This feature is built into the storage account's blob service and provides automatic routing for index and error documents, making it a cost-effective solution for static site hosting.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage (which supports static websites when part of a general-purpose v2 account) with Azure Files or Azure NetApp Files, assuming any storage service can serve web content, but only the blob service with the static website feature enabled provides the necessary HTTP endpoint and routing logic.

13
MCQmedium

A company is migrating on-premises SQL Server databases to Azure. They need to minimize administrative overhead for patching and backups while ensuring high availability. The solution must support automatic failover within the same Azure region. Which Azure service should they choose?

A.SQL Server on Azure Virtual Machines
B.Azure SQL Database Hyperscale
C.Azure SQL Database (single database)
D.Azure SQL Database Managed Instance
AnswerD

Azure SQL Database Managed Instance delivers the broadest SQL Server engine compatibility, including support for SQL Agent, linked servers, CLR, and cross-database transactions, while fully automating maintenance tasks such as patching, backups, and high availability with auto-failover. This makes it the ideal PaaS target for migrating existing on-premises SQL Server databases with minimal administrative overhead, as it removes the need to manage VMs or handle manual DR configuration. The service provides a native virtual network (VNet) deployment and near-100% feature parity, so applications and DBAs can operate almost exactly as they did on-premises.

Why this answer

Azure SQL Database Managed Instance is correct because it provides near-100% compatibility with on-premises SQL Server, automated patching and backups, and built-in high availability with automatic failover within the same region via Always On availability groups. This minimizes administrative overhead while meeting the high availability requirement without manual configuration.

Exam trap

The trap here is that candidates often confuse Azure SQL Database Managed Instance with Azure SQL Database single database, assuming both offer the same high availability and compatibility, but Managed Instance provides full SQL Server instance-level features and automatic failover within the region without additional configuration.

How to eliminate wrong answers

Option A is wrong because SQL Server on Azure Virtual Machines requires manual patching and backup management, increasing administrative overhead, and high availability requires manual configuration of Windows Server Failover Clustering or SQL Server Always On. Option B is wrong because Azure SQL Database Hyperscale is designed for large databases with fast scaling and read scale-out, but its high availability model uses page servers and a log-based service, not automatic failover within the same region in the same way as Managed Instance; it also lacks full SQL Server agent and CLR support. Option C is wrong because Azure SQL Database (single database) offers automated patching and backups but does not support automatic failover within the same region without configuring active geo-replication or failover groups, which adds complexity and cost; it also has limited compatibility for existing SQL Server features like SQL Agent jobs and cross-database queries.

14
MCQmedium

A company uses Azure SQL Database for a line-of-business application. They need to implement a disaster recovery solution across Azure regions with RPO of 5 seconds and RTO of 30 seconds. Which feature should they use?

A.Active geo-replication
B.Geo-restore
C.Azure SQL Database zone-redundant configuration
D.Auto-failover groups
AnswerA

Active geo-replication is the correct answer because it continuously replicates the database asynchronously to a readable secondary in a different Azure region, offering an RPO of under 5 seconds and an RTO of less than 30 seconds when the application's connection string is manually redirected. Because failover is a manual command, there is no DNS propagation delay, making it ideal for strict RTO requirements. The secondary can also be used for read-only queries, but its main purpose is low-latency disaster recovery.

Why this answer

Active geo-replication for Azure SQL Database provides a continuous replication mechanism with an RPO of 5 seconds and an RTO of 30 seconds when using a readable secondary replica in a paired region. It replicates transactions asynchronously but with very low latency, meeting the strict RPO/RTO requirements for cross-region disaster recovery.

Exam trap

The trap here is that candidates often confuse auto-failover groups with active geo-replication, assuming the managed failover group provides faster RTO, but in reality, auto-failover groups have a longer RTO (typically 1 hour) due to DNS propagation and health probe intervals, while active geo-replication allows manual failover with sub-minute RTO.

How to eliminate wrong answers

Option B (Geo-restore) is wrong because it restores a database from geo-replicated backups with an RPO of 1 hour and an RTO of 12+ hours, far exceeding the required 5-second RPO and 30-second RTO. Option C (Azure SQL Database zone-redundant configuration) is wrong because it protects against datacenter failures within a single region, not across Azure regions, and does not provide cross-region disaster recovery. Option D (Auto-failover groups) is wrong because, while it uses active geo-replication under the hood, it adds a DNS-level routing layer that introduces additional failover latency, typically achieving an RTO of 1 hour, not the required 30 seconds.

15
MCQhard

A company ingests millions of IoT events per second from sensors around the world. Each event is a JSON message with timestamp, device ID, and readings. They need to support real-time analytics dashboards and also store all raw data for long-term historical analysis. They want to minimize operational overhead. Which Azure data storage solution should they recommend?

A.Azure Data Lake Storage Gen2 for all data.
B.Azure Event Hubs with Capture to Azure Data Lake Storage.
C.Azure Cosmos DB for both real-time and historical data.
D.Azure Time Series Insights (TSI) Standard.
AnswerB

Event Hubs can handle millions of events per second. The Capture feature automatically writes ingested events to Data Lake Storage in Avro format (or JSON). For real-time dashboards, you can use Stream Analytics to query the Event Hubs stream. This provides a seamless, low-operational-overhead solution.

Why this answer

Azure Event Hubs is designed for high-throughput data ingestion, capable of handling millions of events per second. By enabling the Capture feature, data is automatically and durably persisted to Azure Data Lake Storage in Avro format, providing a serverless, low-latency pipeline for real-time dashboards while storing raw data for long-term analytics. This minimizes operational overhead by eliminating the need to manage separate ingestion and storage infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Data Lake Storage as a complete solution for both ingestion and storage, overlooking the need for a dedicated event ingestion service like Event Hubs to handle high-throughput streaming data before persisting it to the lake.

How to eliminate wrong answers

Option A is wrong because Azure Data Lake Storage Gen2 is a scalable storage service but lacks native real-time ingestion capabilities; it would require an additional service like Event Hubs to handle the high-velocity IoT stream, adding complexity. Option C is wrong because Azure Cosmos DB is a NoSQL database optimized for low-latency reads/writes and transactional workloads, not for ingesting millions of events per second as a streaming buffer; using it for both real-time and historical data would incur high costs and operational overhead for raw event storage. Option D is wrong because Azure Time Series Insights (TSI) Standard is purpose-built for time-series data visualization and analysis, but it has limited throughput and retention compared to Event Hubs with Capture, and it is not designed to store raw JSON events for long-term historical analysis at this scale.

16
MCQmedium

A global e-commerce platform uses Azure Cosmos DB for its product catalog. The application requires multi-region writes to provide low-latency updates from any geographic location. Two users may update the same product item concurrently, so the solution must automatically resolve conflicts. For real-time inventory checks, reads must be strongly consistent, while product description reads can be eventually consistent. Which Cosmos DB configuration should they choose?

A.SQL API with multi-region writes, last-writer-wins conflict resolution, and per-request strong consistency
B.MongoDB API with multi-region writes and automatic conflict resolution
C.Table API with multi-region writes and strong consistency
D.Cassandra API with multi-region writes and strong consistency
AnswerA

SQL API supports multi-master writes, customizable conflict resolution, and the ability to set strong consistency on a per-request basis.

Why this answer

The SQL API in Cosmos DB supports multi-region writes with last-writer-wins (LWW) conflict resolution using a timestamp or custom property, which automatically resolves concurrent updates to the same product item. Per-request strong consistency allows inventory reads to achieve linearizability by setting the consistency level at the request level, while product description reads can use the default session or eventual consistency for performance. This combination meets all requirements: multi-region writes, automatic conflict resolution, and the ability to mix strong and eventual consistency on a per-request basis.

Exam trap

The trap here is that candidates assume all Cosmos DB APIs support multi-region writes and per-request strong consistency equally, but only the SQL API (and the Table API with specific limitations) offers the full flexibility to mix consistency levels per request, while the MongoDB, Cassandra, and Table APIs have fixed account-level consistency or lack multi-region write support entirely.

How to eliminate wrong answers

Option B is wrong because the MongoDB API in Cosmos DB does not support per-request strong consistency; it only offers a fixed set of consistency levels at the account level, and its automatic conflict resolution is limited to LWW without the flexibility to mix consistency levels per request. Option C is wrong because the Table API does not support multi-region writes; it is designed for single-region writes with read-only replicas, and it lacks per-request strong consistency. Option D is wrong because the Cassandra API does not support multi-region writes in Cosmos DB; it is limited to single-region writes, and its consistency model is based on Cassandra's tunable consistency (e.g., QUORUM) rather than Cosmos DB's per-request strong consistency.

17
MCQhard

A company is designing a hybrid storage solution to connect on-premises file shares to Azure. They need to cache frequently accessed files locally for low-latency access while storing all files in Azure. The solution must support SMB protocol and integrate with existing Windows file servers. Which Azure service should they use?

A.Azure Blob Storage with NFS 3.0 support
B.Azure Files
C.Azure File Sync
D.Azure NetApp Files
AnswerC

Azure File Sync is the correct hybrid solution because it combines an Azure file share with a local Windows Server caching tier. The sync agent replicates changes both ways, and cloud tiering ensures only hot files occupy on-premises capacity while all data remains accessible on demand. This gives the performance and compatibility of local SMB storage with the durability and scalability of Azure Files, directly addressing the requirement for cloud connectivity and local caching.

Why this answer

Azure File Sync is the correct choice because it enables caching of frequently accessed files on-premises via a sync agent installed on Windows Server, while all files are stored in Azure Files. This provides low-latency access for local users and supports SMB protocol, seamlessly integrating with existing Windows file servers through a cloud tiering feature that keeps only hot files locally.

Exam trap

The trap here is that candidates often confuse Azure Files (a cloud-only SMB share) with Azure File Sync (which adds local caching and sync capabilities), leading them to select Azure Files without recognizing the requirement for on-premises low-latency access.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with NFS 3.0 support does not natively support SMB protocol and cannot integrate with existing Windows file servers as a cached file share; it is designed for POSIX-compliant workloads. Option B is wrong because Azure Files alone provides a cloud-based SMB share but does not cache files locally on-premises; it requires direct network connectivity and does not offer local caching for low-latency access. Option D is wrong because Azure NetApp Files supports SMB but is a fully managed, high-performance file service that does not provide local caching on existing Windows file servers; it is intended for enterprise workloads requiring dedicated throughput, not hybrid caching.

18
MCQeasy

A company is designing a data storage solution for a globally distributed application that requires low-latency read access to frequently accessed data and high throughput for write operations. The data is non-relational and can be stored as key-value pairs. Which Azure service should they use?

A.Azure Table Storage
B.Azure Cosmos DB
C.Azure SQL Database
D.Azure Blob Storage
AnswerB

Azure Cosmos DB is a multi-model database that provides turnkey global distribution: any number of Azure regions can be associated with the account, and data is automatically replicated so requests are served from the nearest region. It supports key-value APIs, multiple consistency models, and offers 99.999% availability with single-digit-millisecond reads/writes at any scale—exactly what a globally distributed key-value workload needs.

Why this answer

Azure Cosmos DB is the correct choice because it is a globally distributed, multi-model database service that provides guaranteed low-latency reads (under 10 ms at the 99th percentile) and high throughput for write operations, with automatic indexing and turnkey global distribution. It natively supports key-value data models, making it ideal for non-relational, frequently accessed data requiring consistent performance across regions.

Exam trap

The trap here is that candidates often confuse Azure Table Storage as a sufficient key-value store for global scenarios, overlooking its lack of global distribution and guaranteed low-latency SLAs, which Cosmos DB uniquely provides.

How to eliminate wrong answers

Option A is wrong because Azure Table Storage is a NoSQL key-value store but lacks global distribution, automatic indexing, and guaranteed low-latency SLAs; it is designed for simpler, less demanding workloads and cannot match Cosmos DB's throughput and latency guarantees. Option C is wrong because Azure SQL Database is a relational database that requires a fixed schema and does not natively support key-value pair storage; it is optimized for structured, relational data and ACID transactions, not for high-throughput, low-latency key-value access. Option D is wrong because Azure Blob Storage is an object storage service for unstructured data (e.g., images, videos) and does not provide key-value pair semantics or the sub-10 ms read latency and high write throughput required for a globally distributed application; it is designed for bulk storage and streaming, not transactional key-value operations.

19
Multi-Selectmedium

Which TWO of the following Azure services support storing JSON documents without requiring a predefined schema? (Select two.)

Select 2 answers
A.Azure Purview
B.Azure Blob Storage
C.Azure Cosmos DB
D.Azure Analysis Services
E.Azure SQL Database
AnswersB, C

Azure Blob Storage holds unstructured data as blobs with no enforced schema, so JSON documents can be stored as-is without defining fields or types. This schema-agnostic object storage satisfies the requirement to store JSON without a predefined schema.

Why this answer

Azure Blob Storage can store JSON documents as block blobs without requiring a predefined schema, treating the JSON as opaque binary data. Azure Cosmos DB is a NoSQL database that natively supports schema-less JSON document storage. Both services allow storing JSON documents without needing to define a schema upfront.

Exam trap

The trap here is that candidates may mistakenly think Azure SQL Database's JSON support (e.g., OPENJSON, JSON_VALUE) means it can store JSON without a schema, but in reality, the JSON must be inserted into a predefined table column, so the table schema is still required.

20
MCQhard

A financial services company needs to store sensitive transaction records in Azure for 7 years to meet regulatory compliance. The data must be immutable and cannot be deleted or modified during the retention period. Which Azure storage feature should you enable?

A.Blob versioning with lifecycle management
B.Soft delete for blob storage
C.Immutable blob with time-based retention policy
D.Legal hold on the storage container
AnswerC

A time-based retention policy on an immutable blob container enforces a WORM (write-once, read-many) model, prohibiting any deletion or modification of blobs until the specified retention interval has elapsed. The policy is enforced by Azure Storage and cannot be shortened or removed before expiry, ensuring data meets SEC 17a-4-style compliance requirements. It can be applied at the container level or to individual blob versions, and is protected from administrative tampering. This is the appropriate choice for a fixed retention period.

Why this answer

Immutable blob storage with a time-based retention policy enforces WORM (Write Once, Read Many) compliance, ensuring that data cannot be deleted or modified for a specified retention period. This meets the 7-year regulatory requirement for sensitive transaction records, as the policy locks the data at the blob level and prevents any overwrite or deletion, even by administrators with elevated permissions.

Exam trap

The trap here is that candidates confuse soft delete or versioning with immutability, not realizing that only immutable blob storage provides true WORM protection that prevents any modification or deletion during the retention period.

How to eliminate wrong answers

Option A is wrong because blob versioning with lifecycle management preserves previous versions of blobs but does not prevent deletion or modification of the current version; it only allows recovery of older versions, not immutability. Option B is wrong because soft delete for blob storage retains deleted blobs for a configurable period but does not prevent deletion in the first place; data can still be deleted (and later recovered), which violates the immutable requirement. Option D is wrong because a legal hold on the storage container prevents deletion of blobs only while the hold is active, but it does not enforce a fixed retention period and can be removed by an authorized user, failing the 7-year compliance mandate.

21
MCQhard

Refer to the exhibit. You run a KQL query against Azure Cosmos DB diagnostics logs. The query shows increasing latency for Query operations over time. Which is the most likely root cause?

A.A query is consuming increasing RU over time, possibly due to a hot partition
B.The Cosmos DB account has reached its storage limit
C.The Cosmos DB account is being throttled due to insufficient RUs
D.There is network latency between the client and the Cosmos DB endpoint
AnswerA

Increasing RU per query commonly signals a hot partition: a single partition key receives disproportionate request volume, forcing that physical partition to consume more throughput and causing cross-partition query scans. As relevant documents accumulate under one key, the query's logical operations grow, which raises RU charge while response time climbs. Monitor per-partition metrics and Query RU/min to confirm.

Why this answer

The query latency increase over time, combined with the fact that the query is consuming more Request Units (RU) per execution, strongly indicates a hot partition. In Azure Cosmos DB, a hot partition occurs when a disproportionate amount of traffic hits a single physical partition, causing that partition's RU budget to be exhausted while others remain underutilized. This leads to increased latency for queries targeting that partition, as the partition's resources become saturated.

Exam trap

The trap here is that candidates often confuse throttling (Option C) with latency degradation, but throttling is an immediate rejection (HTTP 429), not a gradual latency increase; the key clue is the 'increasing latency over time' combined with 'increasing RU consumption,' which points to a hot partition, not a capacity issue.

How to eliminate wrong answers

Option B is wrong because Cosmos DB has no fixed storage limit; it scales horizontally, and storage limits are tied to provisioned throughput, not a hard cap that would cause increasing latency. Option C is wrong because throttling (HTTP 429) would cause immediate errors or retries, not a gradual increase in latency over time; the query would either succeed or fail, not slowly degrade. Option D is wrong because network latency between client and endpoint would manifest as a constant baseline delay, not a trend of increasing latency; it would not correlate with query RU consumption.

22
MCQmedium

A company is building a big data analytics platform that will process structured, semi-structured, and unstructured data using Azure Synapse Analytics and other tools. They need a storage layer that supports hierarchical namespaces and fine-grained access control at the directory level. Which Azure storage solution should they use?

A.Azure Blob Storage
B.Azure Data Lake Storage Gen2
C.Azure Files
D.Azure Cosmos DB
AnswerB

Azure Data Lake Storage Gen2 is the correct choice because it combines the scalability and cost-effectiveness of Blob Storage with a hierarchical namespace that organizes data into directories, enabling efficient atomic operations and fast path-based access. It also supports POSIX-compliant ACLs at both file and directory levels, allowing fine-grained security that matches the needs of multi-tenant analytics workloads. Its native integration with Hadoop, Spark, Databricks, and Azure Synapse makes it the optimal storage layer for big data analytics, as it provides high throughput and parallel processing capabilities.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines Azure Blob Storage with a hierarchical namespace, enabling directory-level access control lists (ACLs) and POSIX-compliant permissions. This is essential for the big data analytics platform described, as it must support structured, semi-structured, and unstructured data with fine-grained access control at the directory level, which Azure Synapse Analytics can directly query via ABFS (Azure Blob File System) driver.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with ADLS Gen2, assuming blob storage supports hierarchical namespaces natively, but it requires explicit enabling of the hierarchical namespace feature, which is only available in ADLS Gen2 accounts.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage does not support a hierarchical namespace by default; it uses a flat namespace, which prevents directory-level ACLs and requires workarounds for folder-like structures. Option C is wrong because Azure Files provides SMB file shares with directory-level access, but it is designed for lift-and-shift file shares and lacks the hierarchical namespace and POSIX ACLs needed for big data analytics with Azure Synapse. Option D is wrong because Azure Cosmos DB is a NoSQL database for globally distributed, low-latency applications, not a storage layer for hierarchical namespace and directory-level ACLs; it uses a document or graph model, not a file system.

23
MCQhard

Your company is designing a data lake solution using Azure Data Lake Storage Gen2. The solution must support hierarchical namespace for efficient directory operations, and must provide encryption at rest using customer-managed keys stored in Azure Key Vault. Which steps must you take to enable customer-managed key encryption for the storage account?

A.Create the storage account with a user-assigned managed identity, then enable hierarchical namespace, and configure encryption.
B.Create the storage account without hierarchical namespace, then enable it later, and configure encryption with Key Vault.
C.Create the storage account and specify customer-managed key encryption during creation using the Azure portal.
D.Create the storage account with hierarchical namespace enabled, then assign a system-assigned managed identity, and configure encryption with Azure Key Vault.
AnswerD

This is the correct sequence because the hierarchical namespace is an immutable account-level feature that must be set when the storage account is created for Azure Data Lake Storage Gen2. After creation, a system-assigned managed identity should be assigned to the account so it can authenticate to Azure Key Vault for customer-managed key encryption. Finally, encryption is configured using that Key Vault, completing a valid and supported data lake solution.

Why this answer

Azure Data Lake Storage Gen2 requires hierarchical namespace to be enabled at account creation time, and customer-managed key encryption with Azure Key Vault requires a system-assigned managed identity to be assigned to the storage account after creation. The system-assigned identity is used to authenticate to Key Vault for key access, and encryption with customer-managed keys can be configured post-creation via the Azure portal or PowerShell.

Exam trap

The trap here is that candidates assume customer-managed key encryption can be configured during storage account creation, but Azure requires it to be set post-creation after a managed identity is assigned, and hierarchical namespace must be enabled at creation time.

How to eliminate wrong answers

Option A is wrong because a user-assigned managed identity is not required; a system-assigned managed identity is the correct identity type for customer-managed key encryption with Key Vault, and hierarchical namespace must be enabled during creation, not after. Option B is wrong because hierarchical namespace cannot be enabled after the storage account is created; it must be specified at creation time. Option C is wrong because customer-managed key encryption cannot be specified during storage account creation in the Azure portal; it must be configured after the account is created, and a managed identity must be assigned first.

24
MCQmedium

A company uses Azure Redis Cache to improve the performance of a web application. They need to ensure that cached data survives a failover to a secondary region. Which Azure Redis Cache tier should they choose?

A.Standard tier
B.Basic tier
C.Premium tier
D.Enterprise tier
AnswerC

The Premium tier is the appropriate choice because it includes built-in geo-replication, allowing you to link two cache instances in different regions to keep data synchronized and provide failover across regions. It also offers enterprise-grade features such as Redis persistence (RDB/AOF), clustering for scalability, and a 99.99% SLA, directly supporting both performance improvement and durable, geographically resilient caching. This tier meets the requirement without unnecessary architectural complexity, making it the correct answer.

Why this answer

The Premium tier of Azure Redis Cache supports geo-replication, which enables data to be replicated across paired regions. This ensures that cached data survives a failover to a secondary region, meeting the requirement for disaster recovery. The Standard tier only provides replication within a single region, while the Basic tier offers no replication at all.

Exam trap

The trap here is that candidates often confuse the Standard tier's in-region replication with cross-region disaster recovery, or they assume the Enterprise tier is always the best choice for high availability without considering the specific failover scenario described.

How to eliminate wrong answers

Option A is wrong because the Standard tier replicates data only within a single Azure region (two nodes in the same datacenter) and does not support cross-region failover. Option B is wrong because the Basic tier is a single-node cache with no replication, so all data is lost on any failure. Option D is wrong because the Enterprise tier (which uses Redis Enterprise) does support active geo-replication, but the Premium tier is the correct choice for the stated requirement as it provides passive geo-replication with a simpler configuration and is the tier explicitly designed for cross-region failover in the context of Azure Redis Cache.

25
Multi-Selectmedium

A company is designing a solution for storing sensitive financial records that must be retained for 7 years. The solution must meet the following requirements: - Data must be immutable during the retention period. - After the retention period, data must be automatically deleted. - The solution must minimize storage costs. Which two Azure services should the company use? (Choose two.)

Select 2 answers
A.Microsoft Purview Data Map
B.Azure Blob Storage lifecycle management
C.Azure NetApp Files with replication
D.Azure Blob Storage with immutable storage policy
E.Azure Files with snapshots
AnswersB, D

Azure Blob Storage lifecycle management automatically transitions blobs to Cool, Cold, or Archive tiers and executes user-defined deletion rules based on blob age, last modification, or index tags. For sensitive financial records that must be purged after a regulatory retention window, a lifecycle rule with an 'expire' action removes the blobs at the exact scheduled time, providing a cost-effective, fully managed deletion mechanism without manual cleanup.

Why this answer

Azure Blob Storage lifecycle management (B) is correct because it allows you to define rules to automatically delete blobs after a specified period, such as 7 years, minimizing storage costs by tiering or expiring data. Azure Blob Storage with immutable storage policy (D) is correct because it enforces WORM (Write Once, Read Many) immutability, preventing data modification or deletion during the retention period, which is essential for sensitive financial records.

Exam trap

The trap here is that candidates may think a single service like immutable storage alone handles deletion, but they overlook that immutability prevents deletion unless explicitly combined with lifecycle management to trigger automatic removal after the retention period ends.

26
MCQmedium

An enterprise data platform must store petabytes of raw files for analytics and support fine-grained access control through Microsoft Entra ID. Which storage solution should be selected?

A.Azure Queue Storage
B.Azure Disk Storage attached to one VM
C.Azure Cache for Redis
D.Azure Data Lake Storage Gen2
AnswerD

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines Blob Storage's virtually unlimited scalability and durability with a hierarchical namespace, enabling directory-level rename and atomic operations. It integrates with Entra ID to enforce POSIX-like ACLs and RBAC, giving fine-grained, identity-based security over raw petabytes, and it is natively supported by analytics engines such as Apache Spark, Hive, and Azure Synapse. This makes it a true data lake capable of storing raw enterprise data at any volume while providing high-throughput access.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) combines a hierarchical namespace with Azure Blob Storage, enabling petabyte-scale storage for raw files and fine-grained access control via POSIX-like ACLs integrated with Microsoft Entra ID (formerly Azure AD). This makes it the ideal solution for enterprise analytics requiring both massive capacity and granular security.

Exam trap

The trap here is that candidates may confuse Azure Blob Storage (which lacks a hierarchical namespace and fine-grained ACLs) with ADLS Gen2, or assume that any Azure storage service can handle petabyte-scale analytics, ignoring the specific requirements for Entra ID integration and granular permissions.

How to eliminate wrong answers

Option A is wrong because Azure Queue Storage is a messaging service for asynchronous communication between application components, not a storage solution for raw analytics files, and it lacks the hierarchical namespace and Entra ID-based ACLs needed for fine-grained access control. Option B is wrong because Azure Disk Storage attached to a single VM is limited to the VM's capacity (typically terabytes, not petabytes), is not designed for multi-user analytics access, and requires the VM's OS to manage access, which does not natively integrate with Entra ID for fine-grained control. Option C is wrong because Azure Cache for Redis is an in-memory data store for caching and low-latency access, not a durable storage system for petabytes of raw files, and it does not support Entra ID-based ACLs for file-level permissions.

27
Multi-Selecthard

Which THREE of the following are considerations when designing a storage solution for a high-availability application on Azure?

Select 3 answers
A.Recovery Point Objective (RPO) and Recovery Time Objective (RTO)
B.Use of zone-redundant storage (ZRS) for within-region resilience
C.Data encryption at rest using Azure Storage Service Encryption
D.Data striping with RAID 0 for performance
E.Use of geo-redundant storage (GRS) for cross-region disaster recovery
AnswersA, B, E

RPO and RTO are the foundational metrics that drive the replication and failover architecture for any Azure workload. RPO defines the maximum acceptable data loss measured in time, which dictates the frequency of synchronous or asynchronous replication between source and target. RTO defines the maximum acceptable downtime, which determines the required failover automation, testing cadence, and the choice between active-active and active-passive designs. Together, these metrics force explicit trade-offs between cost, complexity, and resilience, making them the first consideration for designing high availability and disaster recovery.

Why this answer

RPO and RTO are fundamental design considerations for any high-availability application. RPO defines the maximum acceptable data loss (measured in time), which directly influences the choice of backup frequency and replication type (e.g., synchronous vs. asynchronous). RTO defines the maximum acceptable downtime, which dictates the failover mechanism and infrastructure redundancy (e.g., active-passive vs. active-active).

Both metrics must be explicitly defined before selecting a storage redundancy tier or disaster recovery strategy.

Exam trap

The trap here is confusing security features (encryption at rest) or performance optimizations (RAID 0) with high-availability design requirements, leading candidates to select options that are valid in other contexts but irrelevant to uptime and disaster recovery.

28
MCQmedium

A gaming company is developing a multiplayer online game that requires a low-latency data store for player profiles, inventory, and session state. The data is accessed globally, and the solution must support millions of concurrent players. The company expects write-heavy workloads with occasional reads. The solution must provide single-digit millisecond latency for reads and writes. The company also needs to run analytics on the data to understand player behavior, but analytics queries can tolerate higher latency (minutes). Which Azure data storage solution should the company recommend for the transactional data?

A.Azure SQL Database with active geo-replication
B.Azure Redis Cache with persistence
C.Azure Cosmos DB with multiple write regions
D.Azure Table Storage with geo-redundancy
AnswerC

Azure Cosmos DB with multiple write regions (multi-master) enables every region to accept writes, and each write is replicated asynchronously to all other regions with conflict resolution policies (e.g., last-writer-wins, custom). This delivers single-digit-millisecond read and write latencies at the 99th percentile anywhere in the world because the client can target the nearest region for both reads and writes. The service provides 99.999% availability with SLAs, automatic failover, and a choice of consistency levels, making it the correct fit for globally distributed, always-on multiplayer game state.

Why this answer

Azure Cosmos DB with multiple write regions is the correct choice because it provides global distribution with multi-master writes, delivering single-digit millisecond latency for both reads and writes at any scale. It supports millions of concurrent players via automatic and elastic scaling, and its change feed enables analytics with higher latency tolerance by streaming data to Azure Synapse or HDInsight without impacting transactional performance.

Exam trap

The trap here is that candidates often choose Azure Redis Cache (Option B) because of its low latency, but they overlook that it is a cache, not a durable transactional store, and cannot serve as the primary data store for player profiles and inventory with global write-heavy workloads.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database with active geo-replication supports only a single writable primary, creating a bottleneck for write-heavy global workloads, and its latency for writes can exceed single-digit milliseconds due to synchronous replication overhead. Option B is wrong because Azure Redis Cache with persistence is an in-memory cache, not a durable transactional data store; it lacks native support for complex queries, indexing, and global multi-write replication, and its persistence model can introduce data loss or higher latency under write-heavy loads. Option D is wrong because Azure Table Storage with geo-redundancy offers eventual consistency and higher latency (typically 10-50 ms) for writes, lacks native multi-region write support, and does not provide the single-digit millisecond latency required for real-time player interactions.

29
MCQeasy

A media company stores raw video files and processed output in Azure. These files are accessed via REST APIs by a processing application. After processing, the files are rarely accessed but must be retained. To minimize costs, the company wants to automatically move files to a cheaper storage tier after 30 days and archive them after 90 days. Which Azure storage solution and feature should they use?

A.Azure Blob Storage with lifecycle management policies
B.Azure Files with snapshot schedules
C.Azure Disk Storage with incremental snapshots
D.Azure NetApp Files with snapshot policies
AnswerA

Blob Storage is the only service here with built-in lifecycle management that can automatically transition media files across hot, cool, cold, and archive tiers based on age or last modification. For raw videos and processed output, rules can move older data to cool after 30 days and to archive after 90 days, optimizing cost without manual intervention. Access tiers are native to blobs, so this directly fits the requirement.

Why this answer

Azure Blob Storage with lifecycle management policies is correct because it allows you to define rules that automatically transition blobs from the hot tier to the cool tier after 30 days and then to the archive tier after 90 days. This directly meets the cost-minimization requirement for rarely accessed files that must be retained, as lifecycle management automates tier transitions without manual intervention.

Exam trap

The trap here is that candidates may confuse Azure Files or Azure NetApp Files with object storage, not realizing that only Azure Blob Storage supports REST API access and automated lifecycle tiering to cool and archive tiers.

How to eliminate wrong answers

Option B is wrong because Azure Files is a fully managed file share accessed via SMB or NFS, not REST APIs, and snapshot schedules provide point-in-time recovery, not automated tiering between storage tiers. Option C is wrong because Azure Disk Storage provides block-level storage for VMs with incremental snapshots for backup, not object storage with lifecycle tiering, and it does not support REST API access for media files. Option D is wrong because Azure NetApp Files offers high-performance NFS/SMB volumes with snapshot policies for data protection, but it lacks built-in lifecycle management to automatically move data to cheaper tiers like cool or archive.

30
MCQeasy

A company needs to store video files for a media streaming application. The files are accessed frequently for the first 30 days, then rarely after that. The solution must minimize storage costs while ensuring low-latency access during the initial period. Which storage tier should be used for the first 30 days?

A.Azure Blob Storage Hot tier
B.Azure Blob Storage Cool tier
C.Azure Premium Blob Storage
D.Azure Blob Storage Archive tier
AnswerA

Azure Blob Storage Hot tier is the default and optimal choice for video files that are accessed frequently, such as during the first 30 days of a media streaming workload. It provides low latency (milliseconds) and high throughput for continuous streaming, with storage costs that are lower than Premium or Archive tiers while still being performant. Unlike Cool or Archive tiers, Hot tier has no minimum storage duration or retrieval charges, making it cost-efficient for sustained, high-frequency read operations.

Why this answer

Azure Blob Storage Hot tier is designed for data that is accessed frequently, offering low-latency access (typically under 10 milliseconds for first-byte read) and the highest storage cost but lowest access cost. Since the video files require low-latency access during the first 30 days, the Hot tier meets the performance requirement while minimizing overall cost compared to Premium Blob Storage, which is optimized for sub-millisecond latency and higher IOPS scenarios.

Exam trap

The trap here is that candidates often choose the Cool tier thinking it balances cost and access, but they overlook that Cool tier has higher access costs and a 30-day early deletion penalty, making it more expensive than Hot for frequent access during the first 30 days.

How to eliminate wrong answers

Option B is wrong because the Cool tier has higher access costs and a 30-day early deletion penalty, making it suboptimal for frequent access during the first 30 days; it is designed for data accessed infrequently (about once a month or less). Option C is wrong because Azure Premium Blob Storage provides sub-millisecond latency via SSDs and is intended for high-transaction workloads, not for minimizing storage costs for frequently accessed video files; it would be significantly more expensive than the Hot tier. Option D is wrong because the Archive tier has the lowest storage cost but the highest access latency (hours to rehydrate) and is intended for data that is rarely accessed (less than once a year); it cannot provide low-latency access during the first 30 days.

31
MCQmedium

A company wants to analyze IoT sensor data from millions of devices in near real-time and store the raw data for batch processing. Which combination of Azure services should they use?

A.Azure Event Hubs and Azure Synapse Analytics
B.Azure IoT Hub and Azure Cosmos DB
C.Azure Data Lake Storage and Azure Stream Analytics
D.Azure Event Hubs and Azure Blob Storage
AnswerD

Event Hubs is a fully managed, high-throughput event ingestion service that accepts millions of messages per second with low latency, making it ideal for collecting IoT telemetry. Blob Storage offers massively scalable, cost-effective object storage that preserves the raw event bodies exactly as received, providing a durable data lake foundation for subsequent analytical processing. Together they satisfy the core requirement of ingesting and storing raw sensor data before any transformation or querying.

Why this answer

Azure Event Hubs is a highly scalable data streaming platform and event ingestion service capable of ingesting millions of events per second from IoT devices in near real-time. Azure Blob Storage provides cost-effective, durable object storage for the raw data, which can then be used for batch processing with services like Azure Data Lake Analytics or Azure Synapse. This combination directly meets the requirements for near real-time ingestion and raw data storage for batch processing.

Exam trap

The trap here is that candidates often confuse Azure IoT Hub with Azure Event Hubs, assuming IoT Hub is required for all IoT scenarios, but Event Hubs is the correct choice for high-throughput, near real-time event ingestion without device management overhead.

How to eliminate wrong answers

Option A is wrong because Azure Synapse Analytics is primarily a data warehouse for structured analytics, not optimized for storing raw, unstructured IoT data for batch processing; using it for raw storage would be costly and unnecessary. Option B is wrong because Azure IoT Hub is a device management and messaging service, not a high-throughput event ingestion pipeline for near real-time analytics, and Azure Cosmos DB is a NoSQL database for transactional workloads, not designed for storing massive volumes of raw data for batch processing. Option C is wrong because Azure Data Lake Storage is a storage service, not an ingestion service; it cannot ingest and buffer streaming data in near real-time, and Azure Stream Analytics is a real-time processing engine, not a storage solution for raw data.

32
MCQeasy

A company needs to store and retrieve large binary files (e.g., images and videos) for a web application. The data must be accessible via HTTPS URLs and support both public read access for anonymous users and private access for administrators. The solution must be highly durable and cost-effective for storing terabytes of data. Which Azure storage solution should they recommend?

A.Azure Blob Storage
B.Azure Files
C.Azure Queue Storage
D.Azure Table Storage
AnswerA

Azure Blob Storage is the correct choice because it is an object storage service purpose-built for massive amounts of unstructured data, including large binary files like images and videos. It exposes every blob via a unique HTTP/HTTPS URL, allowing both private access (using stored access policies or shared access signatures) and public access at the container or blob level, which is ideal for direct retrieval by clients or browsers. Blob Storage also scales to exabytes, offers tiered storage (hot, cool, archive) to optimize cost, and integrates with Azure CDN to serve media at scale, making it the de facto solution for storing and serving binary content.

Why this answer

Azure Blob Storage is the correct choice because it is designed for storing large amounts of unstructured data, such as images and videos, and supports both public anonymous read access (via a public container or blob-level access policy) and private access (via shared access signatures or Azure AD authentication). It provides HTTPS URL access for direct retrieval, offers 99.9999999999% (11 nines) durability for hot and cool tiers, and is cost-effective for terabytes of data due to its tiered storage options (hot, cool, archive).

Exam trap

The trap here is that candidates may confuse Azure Files (a managed file share) with Blob Storage because both can store files, but Azure Files uses SMB/NFS protocols and is not designed for direct HTTPS URL access or public anonymous read for large binary objects.

How to eliminate wrong answers

Option B (Azure Files) is wrong because it provides fully managed file shares accessible via SMB and NFS protocols, not HTTPS URLs for direct binary object retrieval, and is optimized for shared file access rather than large-scale unstructured blob storage. Option C (Azure Queue Storage) is wrong because it is a messaging service for asynchronous communication between application components, not for storing or retrieving binary files. Option D (Azure Table Storage) is wrong because it is a NoSQL key-value store for structured data, not for large binary files like images and videos.

33
MCQhard

A data platform must support analytical queries over petabytes of files in a data lake, while preserving hierarchical namespaces and fine-grained ACLs. Which storage service should you design around?

A.Azure Data Lake Storage Gen2.
B.Azure Files premium shares.
C.Azure Table Storage.
D.Azure Queue Storage.
AnswerA

Azure Data Lake Storage Gen2 is correct because it combines Azure Blob Storage's durable, scalable object storage with a hierarchical namespace, enabling true file/directory semantics such as atomic rename and POSIX-like access control lists (ACLs). It is specifically engineered as a scalable data lake for petabyte-scale analytical workloads, supporting parallel-processing engines like Azure Synapse, Databricks, and Hadoop via ABFS (Azure Blob File System) driver. This design optimizes throughput for full-scan analytical queries and allows incremental directory-level operations, making it the default storage platform for enterprise data platforms.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with POSIX-like ACLs, enabling fine-grained access control at the file and directory level while supporting petabyte-scale analytical workloads. It is built on Azure Blob Storage, providing high-throughput and parallel processing for big data analytics engines like Azure Synapse, Spark, and Hadoop.

Exam trap

The trap here is that candidates may confuse Azure Files (which also supports ACLs) with ADLS Gen2, overlooking that Azure Files is optimized for shared file access (SMB/NFS) and not for petabyte-scale analytical data lake workloads with hierarchical namespace and POSIX ACLs.

How to eliminate wrong answers

Option B is wrong because Azure Files premium shares provide SMB/NFS file shares with ACLs but are designed for low-latency, IOPS-intensive workloads (e.g., lift-and-shift apps), not for petabyte-scale analytical queries over a data lake. Option C is wrong because Azure Table Storage is a NoSQL key-value store for structured, semi-structured data at scale, but it lacks a hierarchical namespace and does not support file-level ACLs or analytical query patterns over files. Option D is wrong because Azure Queue Storage is a messaging service for decoupling application components, not a storage service for data lake analytics or hierarchical namespace management.

34
MCQmedium

A multinational company stores large amounts of unstructured data (documents, images) that must be read with low latency from multiple global regions. Data is written primarily in one region but read globally. Cost optimization is a key requirement. Which Azure storage replication option should they use?

A.Azure Blob Storage with geo-redundant storage (GRS)
B.Azure Blob Storage with read-access geo-redundant storage (RA-GRS)
C.Azure Files with premium shares
D.Azure NetApp Files
AnswerB

RA-GRS extends GRS by providing a read-only endpoint at the secondary region, so clients can retrieve data directly from the geo-replicated copy without waiting for a failover. This lets the storage account serve low-latency reads in both the primary and the paired secondary regions while still using standard, cost-effective blob storage rather than premium tiers. Note that the secondary is eventually consistent, and there can be a slight replication delay, but for most unstructured content such as documents and media this is an acceptable trade-off.

Why this answer

B is correct because RA-GRS provides geo-redundant storage with read access to the secondary region, enabling low-latency reads from multiple global regions while maintaining cost efficiency. The data is written primarily in one region, but RA-GRS allows read requests to be served from the secondary region without additional compute costs, meeting the global read requirement.

Exam trap

The trap here is that candidates often confuse GRS with RA-GRS, assuming geo-redundancy alone provides read access to the secondary region, but GRS requires a manual failover to enable reads, while RA-GRS allows reads from the secondary region at all times.

How to eliminate wrong answers

Option A is wrong because GRS provides geo-redundant storage but does not allow read access to the secondary region, so reads from other regions would still be served from the primary region, increasing latency. Option C is wrong because Azure Files with premium shares is designed for high-performance file shares with low latency but uses locally redundant storage (LRS) or zone-redundant storage (ZRS), not geo-replication, and is cost-prohibitive for large-scale unstructured data. Option D is wrong because Azure NetApp Files is a high-performance file service for enterprise workloads (e.g., SAP, HPC) with NFS/SMB protocols, not optimized for cost-effective global read access of unstructured data, and uses LRS or ZRS by default.

35
Matchingmedium

Match each Azure storage redundancy option to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

3 copies within a single datacenter

3 copies across 3 availability zones in a region

LRS in primary region + LRS in paired secondary region

GRS with read access to secondary region

ZRS in primary region + LRS in paired secondary region

Why these pairings

Azure Storage offers several redundancy options: LRS (local), ZRS (zone), GRS (geo), and RA-GRS (geo with read access). Common confusions include mixing LRS and ZRS, or assuming all geo-replicated options provide read access.

36
Multi-Selectmedium

A company is designing a data storage solution for its IoT devices that generate telemetry data. The data is ingested at high velocity (millions of events per second) and must be stored for real-time dashboards and historical analysis. The solution must also support complex event processing and alerting. Which two Azure services should the company use together? (Choose two.)

Select 2 answers
A.Azure IoT Hub
B.Azure Event Hubs
C.Azure Stream Analytics
D.Azure Synapse Analytics
E.Azure Data Lake Storage Gen2
AnswersB, C

Azure Event Hubs is the correct choice because it is a fully managed, partitioned event-streaming platform engineered for high-throughput telemetry ingestion from millions of IoT devices, supporting millions of events per second and automatic data retention for replay. It decouples producers (devices) from consumers, exposes Kafka-compatible APIs, and enables Stream Analytics, functions, or custom consumers to process the stream, making it the foundational buffer before durable storage.

Why this answer

Azure Event Hubs is the correct choice because it is a high-throughput data ingestion service designed to handle millions of events per second from IoT devices, providing low-latency, durable event capture for real-time dashboards and historical analysis. Azure Stream Analytics is the correct companion service because it natively integrates with Event Hubs to perform complex event processing (CEP), such as pattern matching, aggregation, and alerting, on the streaming telemetry data in real time.

Exam trap

The trap here is that candidates often confuse Azure IoT Hub with Event Hubs, assuming IoT Hub is the default for all IoT data ingestion, but IoT Hub is for device management and lower-throughput scenarios, while Event Hubs is the correct choice for high-velocity, multi-million-events-per-second telemetry ingestion.

37
MCQeasy

A software company runs 50 small Azure SQL databases for different clients. Each database has low average usage but unpredictable spikes. The company wants to minimize cost while providing resources for peak loads and easily adding new databases without manual sizing. Which Azure data service should they use?

A.Azure SQL Database single databases
B.Azure SQL Database elastic pool
C.Azure SQL Managed Instance
D.SQL Server on Azure Virtual Machines
AnswerB

Azure SQL Database elastic pools distribute a shared pool of eDTUs or vCores across many databases, allowing each database to burst beyond its guaranteed minimum without a dedicated allocation. This statistical multiplexing is ideal for 50 small databases with variable, low average utilization because you pay only for the pooled resources actually needed, not the sum of individual peak demands. By configuring per-database min and max limits, you protect individual tenants while maximizing overall cost efficiency.

Why this answer

Azure SQL Database elastic pool is ideal for multiple databases with low average usage and unpredictable spikes because it allows them to share a fixed set of resources (eDTUs or vCores). This pooling model minimizes cost by only paying for the aggregate peak usage across all databases, not each database's individual peak, and automatically handles resource allocation without manual sizing for new databases.

Exam trap

The trap here is that candidates often choose single databases (Option A) thinking they can scale individually for spikes, but they overlook the cost inefficiency of provisioning each database for its peak load versus sharing resources in an elastic pool.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database single databases would require each database to be sized for its own peak load, leading to over-provisioning and higher costs for 50 low-usage databases with spikes. Option C is wrong because Azure SQL Managed Instance is a fully managed instance of SQL Server with fixed resources, designed for lift-and-shift migrations, not for cost-efficient multi-tenant scenarios with variable loads. Option D is wrong because SQL Server on Azure Virtual Machines requires manual VM sizing, patching, and management, increasing operational overhead and cost, and does not provide the automatic resource sharing needed for unpredictable spikes.

38
MCQmedium

A healthcare organization needs to store patient records that must be immutable and auditable for compliance purposes. The records should be stored in a cost-effective manner with the ability to set retention policies. Which Azure storage solution should they implement?

A.Azure NetApp Files
B.Azure SQL Database
C.Azure Blob Storage with immutable storage
D.Azure Files
AnswerC

Azure Blob Storage with immutable storage — available as a container-level policy or legal hold — enforces a Write Once, Read Many (WORM) model at the object layer. Once a time-based retention interval is locked, blobs cannot be overwritten or deleted by any user, including subscription administrator, until the interval expires; legal hold makes such protection indefinite. This behavior is Microsoft’s recommended path for retaining regulated health records like EHR/PHI because it meets HIPAA data integrity and retention compliance via auditable, policy-controlled protection.

Why this answer

Azure Blob Storage with immutable storage (WORM policy) is the correct solution because it provides time-based retention policies and legal hold capabilities that make data non-erasable and non-modifiable, meeting compliance requirements for patient records. It is cost-effective for large volumes of data and integrates with Azure Policy for audit logging, making it ideal for healthcare compliance scenarios like HIPAA.

Exam trap

The trap here is that candidates often confuse Azure Files or Azure NetApp Files with immutable storage because they support snapshots, but snapshots can be deleted or overwritten, whereas Blob Storage immutable policies enforce true WORM compliance that cannot be bypassed.

How to eliminate wrong answers

Option A is wrong because Azure NetApp Files is a high-performance file share for NFS/SMB workloads, not designed for immutable storage or compliance retention policies. Option B is wrong because Azure SQL Database supports row-level security and auditing but does not offer native immutable storage capabilities; data can be modified or deleted unless using complex triggers or backups. Option D is wrong because Azure Files provides SMB file shares with snapshots but lacks built-in WORM (Write Once, Read Many) immutability and retention policy enforcement required for compliance.

39
MCQmedium

A startup is building a social media analytics platform that processes streaming data. They need a data store for time-series events with high write throughput and fast timestamp-based range queries. Which Azure data store is most suitable for this workload?

A.Azure Cosmos DB with SQL API
B.Azure SQL Database with columnstore index
C.Azure Table Storage
D.Azure Data Lake Storage Gen2
AnswerC

Azure Table Storage is a schema-less key-value store where data is addressed by PartitionKey and RowKey, making it a natural fit for IoT-style time-series data. Using a partition key such as device ID and a row key such as inverted timestamp allows efficient range scans for a given device over a time window, while inserts are cheap and highly parallel across partitions. This design delivers low latency at very low cost without the operational complexity of a SQL-based service, which is why it is the correct recommendation.

Why this answer

Azure Table Storage is a NoSQL key-value store that supports high-volume, low-latency writes and efficient range queries on the PartitionKey and RowKey, which can be structured as a timestamp for time-series data. Its schema-less design and ability to scale to massive throughput without sharding overhead make it ideal for streaming event ingestion and timestamp-based retrieval.

Exam trap

The trap here is that candidates often choose Cosmos DB for its flexibility and global distribution, but for a simple, high-throughput time-series workload with timestamp-based queries, Azure Table Storage is the most cost-effective and performant choice, as Cosmos DB adds unnecessary complexity and cost.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB with SQL API, while supporting time-series patterns, introduces higher latency and cost for simple key-value workloads compared to Table Storage, and its throughput is provisioned per container, requiring careful RU management that adds complexity for high-write streaming. Option B is wrong because Azure SQL Database with columnstore index is optimized for analytical queries on large datasets, not for high-write throughput of individual streaming events; its transactional overhead and indexing costs make it unsuitable for real-time ingestion. Option D is wrong because Azure Data Lake Storage Gen2 is a hierarchical file system designed for big data analytics and batch processing, not for low-latency point writes or timestamp-based range queries on individual events.

40
Multi-Selectmedium

Which TWO options are valid methods to secure access to Azure Cosmos DB?

Select 2 answers
A.X.509 certificate-based authentication
B.Azure Storage account keys
C.Azure RBAC roles
D.Primary and secondary keys
E.Shared access signatures (SAS)
AnswersC, D

Azure RBAC roles are a valid method to secure access to Cosmos DB. For the control plane, built-in roles like DocumentDB Account Contributor let you manage the Cosmos DB account, while for the data plane, roles such as Cosmos DB Built-in Data Reader and Data Contributor allow Azure AD identities to read or write data without using account keys. This provides fine-grained, identity-based access to databases and containers, making RBAC a supported alternative to key-based authentication.

Why this answer

Azure RBAC roles (Option C) provide fine-grained, role-based access control to Azure Cosmos DB, allowing you to assign permissions to users, groups, or service principals for operations like read, write, or delete on specific resources. Primary and secondary keys (Option D) are the default authentication method, enabling full access to the Cosmos DB account for data plane operations, and are commonly used for application connections.

Exam trap

The trap here is that candidates often confuse Azure Cosmos DB authentication with Azure Storage authentication, mistakenly selecting SAS tokens or storage account keys, which are valid for Azure Storage but not for Cosmos DB.

41
MCQhard

You run the above PowerShell script to upload a blob to Azure Storage. The script fails with an error: 'The specified container does not exist.' What should you do first to resolve the issue?

A.Create the container using New-AzStorageContainer.
B.Use a different connection string with a SAS token.
C.Grant the storage account key access to the user.
D.Change the -StandardBlobTier parameter to Cool.
AnswerA

The script fails because the target container is not present in the storage account. Azure Blob Storage enforces a strict hierarchy: every blob must reside inside an existing container. The Set-AzStorageBlobContent cmdlet (or equivalent upload command) returns a 404 ContainerNotFound error when the container is missing. Running New-AzStorageContainer with the same storage context and container name creates the required namespace, allowing the upload to succeed.

Why this answer

The error 'The specified container does not exist' indicates that the target container has not been created in the Azure Storage account. The PowerShell script uses the `Set-AzStorageBlobContent` cmdlet, which requires an existing container as the destination. Therefore, the first corrective action is to create the container using `New-AzStorageContainer` before uploading the blob.

Exam trap

The trap here is that candidates may confuse authentication/authorization issues (SAS tokens, key access) with the fundamental prerequisite of container existence, leading them to select options that address permissions rather than the missing resource.

How to eliminate wrong answers

Option B is wrong because using a different connection string with a SAS token does not create the missing container; it only changes authentication, and the container still does not exist. Option C is wrong because granting storage account key access to the user addresses permissions, not the absence of the container; the container must exist regardless of access level. Option D is wrong because changing the -StandardBlobTier parameter to Cool affects the blob's access tier, not the existence of the container; the container must be present before any blob can be uploaded.

42
MCQmedium

A company has 10 branch offices, each with Windows file servers. They want to centralize file storage in Azure and allow each branch office to cache files locally for fast access. The solution must support cloud tiering so that only frequently accessed files are kept locally. Which Azure service should they implement?

A.Azure File Sync
B.Azure Files
C.Azure Blob Storage with Azure File Sync
D.Azure NetApp Files
AnswerA

Azure File Sync is the only solution that provides continuous, multi-site synchronization between on-premises Windows file servers and Azure Files. Its cloud tiering feature keeps only the most frequently accessed files on each branch server's local disk while transparently offloading the rest to Azure, allowing each office to retain a fast, cache-like working set without requiring a full copy. This gives you a single cloud namespace with local caching and hierarchical sync across all branch offices.

Why this answer

Azure File Sync is the correct choice because it enables centralizing file shares in Azure Files while providing local caching on Windows file servers at each branch office. It supports cloud tiering, which automatically keeps only frequently accessed files locally and moves cold data to the cloud, meeting the requirement for fast local access and efficient storage.

Exam trap

The trap here is that candidates often confuse Azure Files (a standalone cloud file share) with Azure File Sync (the hybrid caching and sync service), or incorrectly assume Azure Blob Storage can be used with File Sync, when in fact File Sync only integrates with Azure Files.

How to eliminate wrong answers

Option B (Azure Files) is wrong because it provides cloud-based file shares without native local caching or cloud tiering; it requires Azure File Sync to achieve those capabilities. Option C (Azure Blob Storage with Azure File Sync) is wrong because Azure File Sync works exclusively with Azure Files, not Azure Blob Storage; Blob Storage is designed for unstructured data and does not support the SMB protocol or file-level caching needed for branch office file servers. Option D (Azure NetApp Files) is wrong because it is a high-performance, enterprise-grade NFS/SMB file service for specialized workloads like HPC, not designed for distributed branch office caching with cloud tiering, and it lacks the integrated sync and tiering features of Azure File Sync.

43
MCQeasy

A company needs to store large amounts of unstructured data such as images and videos for a content management system. The data must be accessible via HTTPS and support tiered storage for cost optimization. Which Azure service should they use?

A.Azure Cosmos DB
B.Azure Blob Storage
C.Azure Data Lake Storage
D.Azure Files
AnswerB

Azure Blob Storage is Microsoft's object storage solution, purpose-built for storing massive amounts of unstructured data—anything from text and binary streams to images, logs, and application backups. It exposes a flat namespace via REST over HTTPS, supports data tiering to hot/cool/archive for cost optimization, and provides life-cycle management, soft-delete, and replication options that meet enterprise durability and disaster-recovery requirements. Because the requirement explicitly calls for large-scale unstructured data and HTTPS access, Blob Storage is the direct, default Azure service for that scenario.

Why this answer

Azure Blob Storage is the correct choice because it is designed for storing large amounts of unstructured data (such as images and videos) and provides HTTPS access. It also offers tiered storage (hot, cool, cold, and archive tiers) to optimize costs based on data access patterns, making it ideal for a content management system.

Exam trap

The trap here is that candidates often confuse Azure Data Lake Storage (which is built on Blob Storage) as a separate service for unstructured data, but it is specifically optimized for analytics workloads, not general-purpose content management with tiered storage.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL document database designed for structured or semi-structured data with low-latency queries, not for storing large unstructured blobs like images and videos. Option C is wrong because Azure Data Lake Storage is built on Blob Storage but is optimized for big data analytics workloads (e.g., Hadoop/Spark) and hierarchical namespaces, not for general-purpose content management with tiered storage. Option D is wrong because Azure Files provides SMB and NFS file shares for shared file access, not HTTPS-based blob storage, and its tiering is limited to transaction-optimized, hot, and cool tiers, lacking the full archive tier for deep cost optimization.

44
MCQmedium

Refer to the exhibit. You have an Azure Storage account with hierarchical namespace enabled. You create this JSON policy to assign to a container. Users report that they can access the container from any IP, not just the specified range. What is the most likely reason?

A.Hierarchical namespace disables IP-based restrictions
B.Anonymous access is enabled on the container
C.IP address conditions are not supported in RBAC for Azure Storage data plane operations
D.The resource scope is incorrect; RBAC cannot be assigned at the container level
AnswerC

Azure RBAC condition expressions, part of ABAC (attribute-based access control), support a limited set of attributes for a given action. For Azure Storage data-plane operations, the supported condition attributes include container names, blob paths, tags, and request metadata—but the client's IP address is not among them. Therefore, any attempt to add an IP-address condition to an RBAC role assignment for a storage scope will not be evaluated, and the policy cannot restrict traffic by IP. The recommended mechanism for IP filtering is the storage account firewall, which operates independently of RBAC.

Why this answer

RBAC roles for Azure Storage data plane operations do not support IP address conditions in role assignments. IP address conditions are only supported for Azure Resource Manager (control plane) RBAC roles, not for data plane operations like accessing blob or container data. Since the policy uses RBAC with an IP condition, the condition is ignored, and access is allowed from any IP.

Exam trap

The trap here is that candidates confuse RBAC conditions with Azure Storage firewall rules, assuming that IP conditions can be applied directly in RBAC role assignments for data plane operations, when in fact IP restrictions must be configured separately via the storage account's networking blade.

How to eliminate wrong answers

Option A is wrong because hierarchical namespace (Azure Data Lake Storage Gen2) does not disable IP-based restrictions; IP-based network rules can still be applied via Azure Storage firewall and virtual network settings, but not via RBAC conditions. Option B is wrong because anonymous access being enabled would allow unauthenticated access, but the question states users are authenticated and reporting that IP restrictions are not enforced, which points to a RBAC condition issue, not anonymous access. Option D is wrong because RBAC can be assigned at the container level for data plane operations; the scope is valid, but the IP condition within the RBAC assignment is unsupported.

45
MCQhard

You are a cloud architect at a healthcare company. They have an existing application running on Azure VMs in a single region. The application uses SQL Server on a VM for its database. The company is migrating to Azure SQL Managed Instance for better manageability and compliance. The database is 2 TB and requires point-in-time restore (PITR) capability with a retention period of 35 days. The workload is critical with an RPO of 5 minutes and an RTO of 2 hours. The company wants to minimize costs while meeting these requirements. Which of the following should you recommend?

A.Use Azure SQL Managed Instance with automated backups configured for 35-day retention and a backup storage redundancy of Locally Redundant Storage (LRS)
B.Use Azure SQL Managed Instance with active geo-replication to a secondary region
C.Use Azure SQL Managed Instance with long-term retention (LTR) backups
D.Use Azure SQL Database with the Hyperscale service tier
AnswerA

Automated backups in Azure SQL Managed Instance are enabled by default and retain full, differential, and transaction log backups to support point-in-time restore (PITR) within the configured retention period. You can set the retention to exactly 35 days, the maximum for Managed Instance, and choose Locally Redundant Storage (LRS) to minimize backup storage cost while still meeting the recovery requirement. LRS is cost-effective because it replicates only within the same data center, which is sufficient for PITR when no geo-redundancy requirement exists.

Why this answer

Azure SQL Managed Instance's automated backups with a 35-day retention period and LRS storage meet the PITR requirement while minimizing cost. LRS is the cheapest redundancy option and sufficient for PITR within a single region, as the RPO of 5 minutes is satisfied by the default transaction log backup frequency (every 5-10 minutes). The RTO of 2 hours is achievable by restoring from these backups, and no cross-region replication is needed since the workload is single-region.

Exam trap

The trap here is that candidates often confuse PITR retention with long-term retention (LTR) or assume geo-replication is required for any critical workload, but the question's RPO/RTO and single-region focus make automated backups with LRS the most cost-effective choice.

How to eliminate wrong answers

Option B is wrong because active geo-replication is designed for disaster recovery across regions, which is not required here; it adds unnecessary cost and complexity for a single-region workload with a 2-hour RTO that can be met by local backups. Option C is wrong because long-term retention (LTR) backups are for archival retention beyond 35 days (e.g., years), not for meeting the 35-day PITR requirement; automated backups already cover this period at lower cost. Option D is wrong because Azure SQL Database Hyperscale is a different service tier with a different architecture (e.g., page servers, log-based replication) and does not support SQL Managed Instance features like full instance-level compatibility, which is needed for the migration from SQL Server on a VM.

46
MCQeasy

Refer to the exhibit. A KQL query is run against Azure Storage logs. The result shows a high number of 404 errors for 'GetBlob' operations. What is the most likely cause?

A.The client does not have permission to access the blobs
B.The storage account is throttling requests
C.The blobs being requested do not exist
D.The client is using an incorrect authentication method
AnswerC

A 404 response for a blob operation in Azure Storage corresponds to the BlobNotFound error code, meaning the specified blob does not exist at that path or has been deleted. Because the query returned this code rather than 403 or 429, authentication and rate limits were satisfied. The only remaining conclusion is that the requested blob (or its container) is missing, perhaps due to an incorrect name, a different container, or lifecycle policy deletion.

Why this answer

A 404 (Not Found) error for 'GetBlob' operations in Azure Storage logs specifically indicates that the requested blob resource does not exist at the specified URI. This is distinct from authorization failures (which return 403) or throttling (which returns 503). The high number of 404 errors suggests the client is attempting to retrieve blobs that have been deleted, never created, or are referenced with an incorrect path.

Exam trap

The trap here is that candidates confuse 404 (Not Found) with 403 (Forbidden), assuming that a missing blob is caused by a permissions problem, but Azure strictly differentiates these status codes based on whether the resource exists versus whether access is denied.

How to eliminate wrong answers

Option A is wrong because permission issues (e.g., missing RBAC role or SAS token) result in a 403 (Forbidden) error, not 404. Option B is wrong because throttling by the storage account returns a 503 (Server Busy) or 429 (Too Many Requests) status code, not 404. Option D is wrong because an incorrect authentication method (e.g., using an invalid key or expired SAS) also leads to a 403 (Forbidden) error, as the request is authenticated but not authorized, or a 401 (Unauthorized) if the authentication header is missing or malformed.

47
MCQhard

A company runs large-scale analytics workloads using Apache Hadoop and Spark. They need a cloud storage solution that is fully compatible with the Hadoop Distributed File System (HDFS) and provides unlimited storage with high throughput for parallel processing. They also want to take advantage of tiered storage to reduce costs for older data. Which Azure data service should they use?

A.Azure Blob Storage
B.Azure Data Lake Storage Gen2
C.Azure Files
D.Azure Disk Storage
AnswerB

Azure Data Lake Storage Gen2 is the correct choice because it merges Blob Storage's durable object storage with a hierarchical namespace and native HDFS support via the ABFS driver. It provides unlimited storage, POSIX-like permissions, atomic directory renames, and high throughput, enabling Spark and Hadoop jobs to run at scale without a dedicated HDFS cluster. Lifecycle tiering further reduces costs while retaining analytics performance.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with Azure Blob Storage, providing full HDFS compatibility. This allows Apache Hadoop and Spark workloads to use the `wasbs://` or `abfss://` driver for unlimited storage and high throughput parallel processing, while also supporting tiered storage (hot, cool, archive) to reduce costs for older data.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage (which is object storage without a hierarchical namespace) with ADLS Gen2, assuming both are equally HDFS-compatible, but only ADLS Gen2 provides the required HDFS semantics and the `abfss://` driver for native Hadoop/Spark integration.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage lacks a hierarchical namespace by default, making it incompatible with HDFS semantics (e.g., atomic directory operations) required by Hadoop/Spark; it also does not support the `abfss://` driver natively. Option C is wrong because Azure Files uses the SMB protocol and is designed for file shares, not for HDFS-compatible distributed storage; it cannot handle the massive throughput and parallel processing demands of large-scale analytics. Option D is wrong because Azure Disk Storage provides block-level storage attached to VMs, which is limited in capacity, not natively HDFS-compatible, and does not offer tiered storage for cost optimization of older data.

48
MCQhard

A multinational corporation needs to store and analyze petabytes of historical data for regulatory reporting. The data is rarely accessed but must be available for queries within 5 minutes. Which Azure storage solution should they choose to minimize cost?

A.Azure SQL Database
B.Azure Data Lake Storage Gen2
C.Azure Files
D.Azure Cosmos DB
AnswerB

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct foundation for petabyte-scale analytics because it combines Blob Storage's massive, low-cost capacity with a hierarchical namespace for folder-level permissions and efficient file management. It is engineered for high-throughput parallel scanning, and features like query acceleration allow filtering and aggregating large datasets without spinning up dedicated compute. Its native integration with Azure Synapse, Databricks, and HDInsight makes it the analytics data lake standard.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with Azure Blob Storage's massive scalability, enabling petabyte-scale storage at low cost. It supports fast queries via tools like Azure Synapse or PolyBase, meeting the 5-minute query SLA for cold data, while its tiered storage (e.g., Cool or Archive access tiers) minimizes cost for rarely accessed historical data.

Exam trap

The trap here is that candidates often choose Azure SQL Database or Cosmos DB for 'query performance' without considering the massive cost and architectural mismatch for petabyte-scale cold data, or they pick Azure Files thinking 'file storage' implies analytical capability, ignoring its lack of native query engines and higher cost per GB.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database is a relational OLTP service optimized for transactional workloads with structured data, not designed for petabyte-scale historical data storage and analysis, and its cost would be prohibitive for cold data. Option C is wrong because Azure Files provides SMB/NFS file shares for shared access, lacks native analytical query capabilities, and is not cost-effective for petabyte-scale archival storage. Option D is wrong because Azure Cosmos DB is a NoSQL database for low-latency, globally distributed real-time applications, not suited for petabyte-scale historical data analysis, and its provisioned throughput model would be excessively expensive for rarely accessed data.

49
MCQhard

Your company is designing a data lake solution for IoT telemetry data. The data is ingested continuously and must be stored cost-effectively while allowing occasional interactive queries. The data has a lifespan of 90 days for hot access and 3 years for archived access. Which Azure storage tiering strategy minimizes costs?

A.Use Azure Blob Storage with only Hot tier for 90 days, then delete
B.Use Azure Blob Storage with lifecycle management: Hot for 90 days, then Cool, then Archive after 3 years
C.Use Azure Blob Storage with Cool tier for all data
D.Use Azure Files with lifecycle management to Archive after 90 days
AnswerB

This approach uses Azure Blob Storage lifecycle management policies to automatically transition blobs from Hot to Cool after 90 days of frequent access, then to Archive after 3 years, aligning with the retention period. The Archive tier offers the lowest storage cost for rarely accessed historical data while preserving it for future analytics, and the automated transitions reduce operational overhead and optimize cost without compromising data availability.

Why this answer

Azure Blob Storage lifecycle management can automatically transition data from Hot to Cool to Archive tiers based on age, minimizing costs for IoT telemetry that needs 90 days of hot access and 3 years of archival. The Hot tier provides low-latency access for interactive queries, Cool offers lower storage cost for infrequent access, and Archive provides the lowest cost for long-term retention. This tiering strategy aligns with the data's lifespan and access patterns, reducing overall storage expenses compared to keeping all data in a single tier.

Exam trap

The trap here is that candidates may assume Cool tier is sufficient for all data to save costs, but they overlook the need for hot access during the first 90 days and the even lower Archive tier for long-term retention, leading to higher overall costs.

How to eliminate wrong answers

Option A is wrong because deleting data after 90 days ignores the 3-year archival requirement, and storing all data in Hot tier for 90 days is more expensive than using Cool or Archive tiers for older data. Option C is wrong because using Cool tier for all data incurs higher costs for the first 90 days of hot access and does not provide the lowest-cost Archive tier for the 3-year retention period. Option D is wrong because Azure Files is not optimized for data lake scenarios with large-scale IoT telemetry ingestion; it uses SMB/NFS protocols and lacks the native tiering and lifecycle management capabilities of Blob Storage, plus archiving after 90 days does not meet the 3-year retention need.

50
Matchingmedium

Match each Azure governance tool to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Enforce rules and compliance for resources

Define repeatable set of Azure resources and policies

Hierarchical structure for managing access and policies

Query and explore Azure resources across subscriptions

Monitor, allocate, and optimize cloud costs

Why these pairings

Azure Policy enforces rules; Azure Blueprints provides repeatable templates; Management Groups organize subscriptions; RBAC controls access. Confusions often arise between policy enforcement and access control, or between blueprints and management groups.

51
MCQmedium

A media company is designing a storage solution for its large video files (average 50 GB each) that are edited by multiple users simultaneously. The solution must support SMB protocol for compatibility with existing editing software and provide low-latency access. The files must be stored in a highly available configuration across multiple availability zones in a single region. Which Azure storage solution should the company recommend?

A.Azure Files Premium tier with zone-redundant storage (ZRS)
B.Azure Blob Storage Premium tier with geo-redundant storage (GRS)
C.Azure Disk Storage with shared disks
D.Azure NetApp Files Premium tier with cross-zone replication
AnswerA

Azure Files Premium tier provides fully managed SMB and NFS file shares backed by SSD storage, delivering the low-latency I/O required for media workloads. Zone-redundant storage (ZRS) synchronously replicates data across three Azure availability zones within a region, ensuring high availability and resilience to zone failures without the cost of geo-replication. This combination offers native file sharing, strong performance, and simple integration, making it the most appropriate choice for a media company's scalable, low-latency storage.

Why this answer

Azure Files Premium tier supports SMB protocol natively, which is required for compatibility with existing editing software. Zone-redundant storage (ZRS) replicates data synchronously across three availability zones within a single region, providing high availability and low-latency access for simultaneous editing of large video files.

Exam trap

The trap here is that candidates may confuse Azure Blob Storage (which is object storage, not file storage) with Azure Files, or assume that geo-redundant storage (GRS) is required for high availability, when zone-redundant storage (ZRS) within a single region is sufficient and provides lower latency for real-time editing workloads.

How to eliminate wrong answers

Option B is wrong because Azure Blob Storage Premium tier does not support the SMB protocol; it uses REST APIs or NFS (preview), not SMB, and geo-redundant storage (GRS) adds asynchronous cross-region replication that increases latency and is unnecessary for single-region high availability. Option C is wrong because Azure Disk Storage with shared disks supports SMB but is designed for single-VM attached disks or shared block storage for clustered VMs, not for file-level sharing across multiple users; it lacks native SMB file-sharing semantics and is not optimized for concurrent user editing of large files. Option D is wrong because Azure NetApp Files Premium tier supports SMB and cross-zone replication, but cross-zone replication is asynchronous, which can introduce latency and potential data inconsistency for real-time editing; Azure NetApp Files is also more expensive and complex to manage compared to Azure Files for this use case.

52
Multi-Selectmedium

Which TWO data storage solutions in Azure provide built-in, automatic geo-redundancy for disaster recovery across paired regions?

Select 2 answers
A.Azure SQL Database (active geo-replication)
B.Azure Cosmos DB (default)
C.Azure Blob Storage (with GRS or RA-GRS)
D.Azure Data Lake Storage Gen2
E.Azure Files (standard tier)
AnswersA, C

Azure SQL Database active geo-replication is a built-in feature that continuously replicates committed transactions from a primary database to a readable secondary in a paired Azure region. This is a native capability of the platform, not an add-on or explicit custom configuration. It supports manual failover and provides a clear disaster recovery path with minimal administrative overhead, making it a correct answer.

Why this answer

Azure SQL Database's active geo-replication automatically creates a readable secondary database in a paired Azure region, enabling synchronous or asynchronous replication for disaster recovery. Azure Blob Storage with GRS or RA-GRS replicates data to a paired secondary region automatically, ensuring durability even during a regional outage. Both services provide built-in geo-redundancy without manual configuration beyond selecting the replication option.

Exam trap

The trap here is that candidates assume all Azure storage services have built-in geo-redundancy by default, but only specific services (like SQL Database with active geo-replication and Blob Storage with GRS/RA-GRS) offer it automatically without additional configuration.

53
MCQmedium

A company runs a custom analytics application that reads data using the NFS 3.0 protocol. The data consists of large files organized in a directory structure. The application also requires POSIX-like access control lists (ACLs) for fine-grained permissions. The solution must be fully managed and support high throughput for parallel reads. Which Azure data service should they use?

A.Azure Blob Storage
B.Azure Files
C.Azure NetApp Files
D.Azure Data Lake Storage Gen2
AnswerD

Azure Data Lake Storage Gen2 is the correct answer because it combines the massive scalability of Azure Blob Storage with a hierarchical namespace, enabling true directory structures and atomic, directory-level rename/delete operations that analytics applications require. It exposes POSIX-compliant access control lists (ACLs) and supports NFS 3.0 endpoints, so an NFS 3.0-based custom application can connect directly while also benefiting from the ABFS driver for Spark, Hadoop, and other analytic frameworks. This unique fusion of hierarchical namespace, POSIX ACLs, NFS 3.0 interoperability, and blob-storage economics makes ADLS Gen2 the only option that fully satisfies all the stated requirements for a cloud-scale analytics data lake.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with POSIX-like ACLs and supports the NFS 3.0 protocol for high-throughput parallel reads. It is fully managed and designed for big data analytics workloads that require fine-grained permissions and directory structure management.

Exam trap

The trap here is that candidates often confuse Azure Files (which supports NFS but only version 4.1) with the NFS 3.0 requirement, or they overlook that Azure NetApp Files, while technically capable, is not the fully managed, high-throughput parallel read solution optimized for analytics that ADLS Gen2 provides.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage does not natively support NFS 3.0 (it requires a preview feature or workaround) and lacks a true hierarchical namespace and POSIX ACLs, relying instead on flat storage and Azure RBAC. Option B is wrong because Azure Files supports SMB and NFS 4.1, not NFS 3.0, and its ACLs are based on Windows NTFS permissions, not POSIX-like ACLs. Option C is wrong because Azure NetApp Files is a fully managed file share service that supports NFS 3.0 and POSIX ACLs, but it is not the best fit for high-throughput parallel reads in a custom analytics application; it is more suited for enterprise workloads requiring low-latency access and is not as optimized for big data analytics as ADLS Gen2.

54
MCQeasy

You need to provide temporary shared access to a specific blob in Azure Storage for a contractor. The access must expire after 24 hours. Which feature should you use?

A.Managed identity
B.Azure role-based access control (RBAC)
C.Storage account access key
D.Shared access signature (SAS)
AnswerD

A shared access signature (SAS) is a signed URI that contains query parameters (e.g., 'sp' for permissions, 'se' for expiry, 'sr' for resource type) and can be scoped precisely to a single blob while the signature is validated by Azure Storage. You can specify read permissions and a short expiration window, and optionally use a user delegation SAS signed with Azure AD credentials to avoid using an account key. This is the standard Azure mechanism for granting temporary, delegated access to a specific blob without exposing the account key or requiring a persistent role assignment.

Why this answer

A shared access signature (SAS) provides delegated, time-limited access to a specific Azure Storage resource, such as a blob, without exposing the storage account key. By configuring the SAS with an expiration time of 24 hours, you grant the contractor temporary access that automatically revokes after that period, meeting the requirement precisely.

Exam trap

The trap here is that candidates often confuse managed identities or RBAC as suitable for temporary access, but neither provides time-bound, scoped delegation to a single blob without persistent permissions or full account access.

How to eliminate wrong answers

Option A is wrong because a managed identity is used for authenticating Azure resources (e.g., VMs, App Services) to Azure services without storing credentials, not for granting temporary external user access to a specific blob. Option B is wrong because Azure RBAC provides persistent, role-based access to storage account resources at the container or account level, not time-bound access to a single blob, and it cannot enforce a 24-hour expiration. Option C is wrong because the storage account access key grants full administrative access to the entire storage account, which violates the principle of least privilege and cannot be scoped to a single blob or set to expire automatically.

55
MCQmedium

A company needs a data storage solution for a global application that frequently accesses recent data and less frequently older data. Data is unstructured blobs. They want to automatically move blobs to cool storage after 30 days and to archive storage after 90 days. Additionally, blobs must be retained for 7 years and cannot be deleted or modified during that period. Which Azure Blob Storage features should they combine?

A.Use blob lifecycle management policies and legal hold (immutable blobs).
B.Use blob lifecycle management policies and time-based retention policies.
C.Use Azure Storage Analytics and immutability policies.
D.Use Azure File Sync and lifecycle management.
AnswerB

Blob lifecycle management policies automate cost-efficient data tiering, moving blobs from hot to cool to archive tiers based on age or last modification, thereby reducing storage costs as data ages. Time-based retention policies, a form of immutable blob storage with a fixed retention interval, prevent blobs from being modified or deleted for a specified period—here, 7 years—which satisfies regulatory compliance. Together they meet the global application's need for both automated tiering and fixed-duration write-once-read-many (WORM) protection, whereas a legal hold would leave retention indefinite and untethered to a specific deadline.

Why this answer

Blob lifecycle management policies automatically transition blobs from hot to cool after 30 days and to archive after 90 days, while time-based retention policies enforce immutability for a fixed period (7 years), preventing deletion or modification. This combination meets both the tiering and retention requirements without manual intervention.

Exam trap

The trap here is confusing legal hold (which is indefinite and manually managed) with time-based retention (which has a fixed expiry), leading candidates to choose Option A when they need a defined retention period.

How to eliminate wrong answers

Option A is wrong because legal hold (immutable blobs) has no expiration date and must be manually cleared, making it unsuitable for a fixed 7-year retention period; it also does not support automatic tiering. Option C is wrong because Azure Storage Analytics provides metrics and logging, not lifecycle management or immutability policies. Option D is wrong because Azure File Sync is for syncing on-premises file shares with Azure Files, not for managing blob tiering or retention.

56
Multi-Selectmedium

Which TWO of the following are benefits of using Azure Files shares for lift-and-shift migrations of on-premises file servers?

Select 2 answers
A.Integration with Azure File Sync for hybrid scenarios
B.Block-level deduplication
C.Support for iSCSI protocol
D.Automatic tiering of data to archive storage
E.Support for SMB protocol
AnswersA, E

Azure File Sync is a native Azure service that replicates an Azure file share to on-premises Windows Servers, creating a multi-site distributed cache. This integration enables hybrid scenarios where branch offices and local users can access a local server cache with low latency while still benefiting from centralized management, backup, and disaster recovery in Azure. It is a core benefit of Azure Files because it directly extends your cloud file share to existing on-premises infrastructure.

Why this answer

Azure Files shares provide fully managed SMB file shares in the cloud, which are directly compatible with on-premises file servers that use the SMB protocol. This makes them ideal for lift-and-shift migrations because applications can continue accessing files over SMB without code changes. Azure File Sync further extends this by enabling hybrid scenarios where on-premises servers can cache frequently accessed files while tiering to the cloud, simplifying the migration process.

Exam trap

The trap here is that candidates may confuse Azure Files with Azure NetApp Files or on-premises file server features, assuming block-level deduplication or iSCSI support are available, when in fact Azure Files is a managed SMB/NFS service without those capabilities.

57
MCQhard

A globally distributed application requires multi-region writes to a NoSQL database and must tolerate regional write outages. Which Azure service capability should be selected?

A.Azure Table Storage RA-GRS
B.Azure SQL Database serverless only
C.Azure Cosmos DB multi-region writes
D.Azure Files geo-redundant storage
AnswerC

Azure Cosmos DB with multi-region writes enables active-active replication where every region assigned to the account is writable, allowing any region to accept write requests with configurable conflict resolution (e.g., Last-Writer-Wins or custom). Each write is replicated to all other regions asynchronously while the chosen consistency level (such as bounded staleness or eventual) is honored at the client. This architecture provides high write availability, low latency for globally distributed applications, and is the only listed option that natively supports multi-region writes.

Why this answer

Azure Cosmos DB multi-region writes is the correct choice because it provides active-active replication across multiple Azure regions, enabling writes to be accepted in any configured region and automatically replicated. This design ensures that if one region experiences a write outage, the application can continue writing to other regions without interruption, meeting the requirement for multi-region writes and regional write outage tolerance.

Exam trap

The trap here is that candidates often confuse geo-redundant storage options (like RA-GRS or GRS) with active-active multi-region write capabilities, not realizing that most Azure storage services (including Table Storage and Files) only support writes to a single primary region, whereas Cosmos DB is the only service that natively supports multi-region writes.

How to eliminate wrong answers

Option A is wrong because Azure Table Storage RA-GRS (Read-Access Geo-Redundant Storage) supports read access from a secondary region but only allows writes to the primary region, failing the multi-region write requirement. Option B is wrong because Azure SQL Database serverless is a compute tier for a single-region database; it does not support multi-region writes and cannot tolerate regional write outages. Option D is wrong because Azure Files geo-redundant storage replicates data to a secondary region for durability but only supports writes to the primary region, not multi-region writes.

58
MCQhard

A company needs to store large amounts of unstructured data (log files) for analytics. The data is accessed frequently for the first 30 days, then occasionally for the next 90 days, and rarely after that but must be retained for 7 years for compliance. The data must not be modified or deleted during the retention period, and administrative access must not be able to bypass this restriction. They want to minimize storage costs. Which combination of Azure Blob Storage features should they configure?

A.Configure a lifecycle management policy to move blobs to Cool tier after 30 days and to Archive tier after 120 days. Apply a time-based retention policy with a retention period of 2,555 days and lock it.
B.Enable soft delete and versioning on the storage account, and use a custom script to delete blobs after 7 years. Manually move blobs to Cool and Archive tiers using Azure PowerShell.
C.Set each blob's access tier to Cool on upload, then manually change to Archive after 30 days. Enable Azure Backup on the storage account for retention.
D.Apply a legal hold on the container to prevent deletion, and configure a lifecycle policy to move blobs to Archive after 30 days.
AnswerA

A locked time-based retention policy on the container ensures that blobs cannot be deleted or overwritten for the specified duration (7 years = 2555 days). Lifecycle management moves blobs to cost-efficient tiers. Locking prevents bypass.

Why this answer

It combines a lifecycle management policy to automatically transition blobs from Hot to Cool after 30 days and to Archive after 120 days, minimizing storage costs. The time-based retention policy with a locked retention period of 2,555 days (7 years) ensures that blobs cannot be modified or deleted during the retention period, and locking the policy prevents administrative bypass, meeting the compliance requirement.

Exam trap

The trap here is that candidates often confuse soft delete or legal hold with immutable retention policies, not realizing that only a locked time-based retention policy provides true WORM protection that cannot be bypassed by administrators.

How to eliminate wrong answers

Option B is wrong because soft delete and versioning allow data recovery but do not prevent deletion or modification during the retention period; a custom script to delete blobs after 7 years violates the requirement that data must not be deleted during retention, and manual tier changes are not automated or cost-efficient. Option C is wrong because manually setting access tiers and using Azure Backup does not enforce a write-once-read-many (WORM) policy; Azure Backup retains backups but does not prevent modification or deletion of the original blobs, and manual operations are error-prone and do not meet the compliance requirement for immutability. Option D is wrong because a legal hold prevents deletion but does not prevent modification of blobs, and moving blobs to Archive after 30 days ignores the occasional access requirement for the next 90 days, leading to higher retrieval costs and potential access delays.

59
MCQeasy

A global e-commerce company needs a database solution that can handle high-velocity writes from user transactions across multiple regions. They require multi-region writes with automatic conflict resolution and single-digit millisecond latency for reads and writes. Which Azure data store should they use?

A.Azure Cosmos DB
B.Azure Table Storage
C.Azure SQL Database
D.Azure Redis Cache
AnswerA

Correct. Azure Cosmos DB is a globally distributed, multi-model database service that natively supports multi-region writes (multi-master) with automatic conflict resolution via last-writer-wins or custom conflict resolution policies, ensuring active-active failover across regions. Its turnkey global distribution replicates data to any number of Azure regions, providing single-digit millisecond read and write latency at the 99th percentile, and it exposes multiple consistency models (strong, bounded staleness, session, consistent prefix, eventual) to balance consistency and performance. This makes it the only listed option that directly satisfies the requirement for a database that can handle global writes with automatic conflict resolution.

Why this answer

Azure Cosmos DB is the correct choice because it offers multi-region writes with automatic conflict resolution using last-writer-wins (LWW) or custom conflict resolution policies, and it guarantees single-digit millisecond latency for both reads and writes at the 99th percentile. Its globally distributed, multi-model design is purpose-built for high-velocity transactional workloads that require active-active replication across regions.

Exam trap

The trap here is that candidates often confuse Azure SQL Database's active geo-replication (which supports only read-scale secondaries) with true multi-region writes, or they assume Azure Table Storage's global replication is equivalent to Cosmos DB's active-active capability.

How to eliminate wrong answers

Option B (Azure Table Storage) is wrong because it does not support multi-region writes or automatic conflict resolution; it is a NoSQL key-value store designed for structured, non-relational data with eventual consistency only. Option C (Azure SQL Database) is wrong because it does not natively support multi-region writes; it uses active geo-replication for read-only secondaries and requires manual failover, not active-active writes. Option D (Azure Redis Cache) is wrong because it is an in-memory cache, not a durable database; it does not provide automatic conflict resolution for writes and is not designed for persistent, multi-region transactional storage.

60
MCQeasy

A company uses Azure Cosmos DB for a globally distributed e-commerce application. They need to ensure that write operations in one region are immediately visible in all other regions. Which consistency level should they choose?

A.Session
B.Eventual
C.Strong
D.Bounded staleness
AnswerC

Strong consistency in Cosmos DB ensures that every read returns the most recently committed write, regardless of which region the read is served from. This is achieved by synchronously replicating each write to all regions before acknowledging the transaction, providing linearizable consistency. It is the only level that meets the stated requirement of immediate global visibility of the latest write, though it comes with higher write latency and requires single-region write configuration.

Why this answer

Strong consistency ensures that write operations are synchronously replicated across all regions before acknowledging the write. This guarantees that any read operation in any region returns the most recent write, providing linearizability. For a globally distributed e-commerce application requiring immediate visibility of writes, Strong consistency is the correct choice.

Exam trap

The trap here is that candidates often confuse 'immediate visibility' with 'Session' consistency, assuming that a single session's writes are enough, but the requirement is for all regions and all clients to see the write immediately, which only Strong consistency guarantees.

How to eliminate wrong answers

Option A is wrong because Session consistency guarantees monotonic reads and writes within a single client session but does not provide immediate cross-region visibility for all clients. Option B is wrong because Eventual consistency allows replicas to converge over time without any guarantee of immediate visibility, leading to stale reads. Option D is wrong because Bounded staleness allows reads to lag behind writes by a configurable time interval (e.g., 5 seconds) or number of versions, which does not meet the requirement for immediate visibility.

61
MCQeasy

A company wants to automatically tier data between hot, cool, and archive access tiers based on last access time to optimize costs. Which Azure feature should they implement?

A.Azure Blob Storage lifecycle management
B.Azure Data Box
C.Azure Backup
D.Azure File Sync
AnswerA

Azure Blob Storage lifecycle management is the correct service because it natively applies predefined rules to automatically move blobs between the hot, cool, and archive access tiers based on conditions such as age or last modified time. These lifecycle policies are evaluated daily and can also delete blobs, ensuring storage costs stay optimized without manual intervention. The rules operate at the storage account or container level, giving granular control over both current tier placement and future transitions.

Why this answer

Azure Blob Storage lifecycle management allows you to define policies that automatically move blobs between hot, cool, and archive access tiers based on conditions such as last access time or age. This directly addresses the requirement to optimize costs by tiering data according to access patterns without manual intervention.

Exam trap

The trap here is that candidates may confuse Azure File Sync's 'cloud tiering' feature with blob lifecycle management, but File Sync only tiers between local server and Azure Files (not between hot/cool/archive tiers) and does not use last access time for tiering decisions.

How to eliminate wrong answers

Option B (Azure Data Box) is wrong because it is a physical data transfer service for offline migration of large datasets, not a tool for automated tiering based on access time. Option C (Azure Backup) is wrong because it provides backup and restore capabilities for Azure resources, not data lifecycle management between access tiers. Option D (Azure File Sync) is wrong because it synchronizes on-premises file servers with Azure file shares and can enable cloud tiering, but it does not support moving data between hot, cool, and archive tiers based on last access time; its tiering is limited to local vs. cloud caching.

62
MCQmedium

A healthcare company is designing a data storage solution for its electronic health records (EHR) system. The system must store patient data in Azure SQL Database with high availability. The solution must meet the following requirements: - Data must be stored in the East US region with automatic failover to a secondary region in West US in case of a regional outage. - The Recovery Point Objective (RPO) must be less than 5 seconds. - The Recovery Time Objective (RTO) must be less than 1 hour. - The solution must minimize costs while meeting the RPO and RTO. Which Azure SQL Database configuration should the company recommend?

A.Deploy Azure SQL Database Managed Instance with failover group to a secondary instance in West US.
B.Deploy Azure SQL Database with active geo-replication to a secondary server in West US. Configure automatic failover using a failover group.
C.Deploy Azure SQL Database Business Critical tier with auto-failover group and a secondary replica in a different availability zone within East US.
D.Deploy Azure SQL Database General Purpose tier with zone-redundant configuration.
AnswerB

Active geo-replication asynchronously replicates changes to a secondary server in West US with a 5-second RPO, and when paired with a failover group, failover is automatic—typically completing in less than an hour—so the workload stays available during a regional outage. This is the standard cross-region DR pattern for Azure SQL Database because it supports readable secondaries and allows the RPO/RTO targets to match the strict uptime and data durability requirements common in healthcare.

Why this answer

Active geo-replication with a failover group provides automatic, asynchronous replication to a secondary region (West US) with an RPO of less than 5 seconds and an RTO of less than 1 hour. This configuration meets the high-availability and disaster recovery requirements while minimizing costs compared to higher-tier options.

Exam trap

The trap here is that candidates may choose the Business Critical tier (Option C) thinking it provides the best availability, but it only offers intra-region zone redundancy, not cross-region disaster recovery, which is required for a regional outage.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database Managed Instance does not support active geo-replication or failover groups with an RPO under 5 seconds; its built-in auto-failover groups have a higher RPO and RTO, and it is more expensive than the required solution. Option C is wrong because the Business Critical tier with a secondary replica in a different availability zone within East US does not provide failover to a secondary region (West US), failing the cross-region disaster recovery requirement. Option D is wrong because the General Purpose tier with zone-redundant configuration only protects against zonal failures within a single region, not a regional outage, and its RPO and RTO do not meet the sub-5-second RPO and sub-1-hour RTO requirements.

63
MCQmedium

A company ingests IoT sensor data into Azure Blob Storage. Data is written frequently and is accessed rarely after the first 24 hours. The company must retain the data for exactly 90 days for compliance. They want to minimize storage costs by automatically moving data to the cheapest possible storage tier as soon as possible. Which Azure Blob Storage lifecycle management policy should they implement?

A.Move to Cool tier after 1 day, delete after 90 days
B.Move to Archive tier after 1 day, delete after 90 days
C.Move to Cool tier after 30 days, delete after 90 days
D.Move to Archive tier after 30 days, delete after 90 days
AnswerA

Moving the sensor data to the Cool tier after just one day aligns lifecycle costs with actual access patterns, since IoT telemetry is typically queried only briefly after ingestion. Cool tier provides significantly lower per-GB storage costs than Hot, and because the retention period of 90 days exceeds Cool's 30-day minimum commitment, no early deletion penalty is incurred. This policy satisfies the compliance requirement to delete after 90 days while minimizing the cost of storing data that is rarely read after the first 24 hours.

Why this answer

The data is rarely accessed after 24 hours, so moving it to Cool tier after 1 day minimizes cost while still allowing low-latency access. The 90-day deletion aligns with the compliance retention requirement. Cool tier is the cheapest online tier, and moving data there as soon as possible (after 1 day) reduces costs without incurring the early deletion penalty or retrieval latency of Archive tier.

Exam trap

The trap here is that candidates often choose Archive tier thinking it is the cheapest, but they overlook the 180-day early deletion penalty and the fact that Cool tier is sufficient for 90-day retention with no penalty, making it the true cheapest option for this exact retention window.

How to eliminate wrong answers

Option B is wrong because moving data to Archive tier after 1 day would make it inaccessible for immediate use (Archive has a retrieval latency of up to 15 hours) and incurs a higher cost for early deletion if deleted before 180 days. Option C is wrong because waiting 30 days to move to Cool tier leaves data in the Hot tier for 29 extra days, incurring unnecessary storage costs when it could have been moved after 1 day. Option D is wrong because moving to Archive tier after 30 days still incurs the early deletion penalty (Archive requires a minimum 180-day retention) and the data is rarely accessed, but Cool tier after 1 day is cheaper and more appropriate.

64
MCQeasy

A financial company must store customer transaction records in Azure Blob Storage. Regulatory requirements mandate that the records must not be modified or deleted for 7 years. Even administrators must be unable to alter or remove the blobs during this period. Which Azure Blob Storage feature should they enable?

A.Immutable storage with time-based retention policy
B.Legal hold
C.Soft delete
D.Versioning
AnswerA

Immutable storage with time-based retention policy enforces write-once-read-many (WORM) semantics on Azure Blob Storage, preventing any modification or deletion of blobs for a user-defined retention interval. This fixed-period lock can be set to exactly 7 years, satisfying the regulatory requirement while ensuring data remains tamper-proof for the mandated duration. Unlike legal hold, the time-based policy has a defined expiry, and the protection is enforced at the storage layer independent of user permissions.

Why this answer

Immutable storage with a time-based retention policy (WORM – Write Once, Read Many) ensures that blobs cannot be modified or deleted for a specified duration, even by administrators. This directly satisfies the 7-year regulatory requirement by locking the data at the storage level, overriding any delete or write operations.

Exam trap

The trap here is that candidates often confuse soft delete or versioning with immutable storage, not realizing that only WORM policies (time-based retention or legal hold) provide true, administrator-proof immutability for a defined period.

How to eliminate wrong answers

Option B (Legal hold) is wrong because legal hold is an indefinite, policy-based lock that must be explicitly cleared; it does not enforce a fixed 7-year retention period and is typically used for litigation, not time-bound regulatory compliance. Option C (Soft delete) is wrong because soft delete only protects against accidental deletion by retaining deleted blobs for a configurable period, but it does not prevent modification or deletion by administrators during the retention window. Option D (Versioning) is wrong because versioning preserves previous blob versions but does not prevent deletion or overwrite of the current version; administrators can still delete or modify blobs, and versioning alone does not enforce a write-once, read-many constraint.

65
MCQmedium

Refer to the exhibit. An Azure Policy is assigned to a subscription. A user tries to create a blob container via the Azure portal and receives a deny error. What is the most likely reason?

A.The policy denies creation of blob containers
B.The blob container requires immutable storage
C.The user is trying to enable public access on the container
D.The storage account does not have encryption enabled
AnswerA

The policy definition applies a Deny effect to the action Microsoft.Storage/storageAccounts/blobServices/containers/write and further constrains the condition to requests where the HTTP method is PUT. Since creating a blob container is performed through a PUT request to the containers endpoint, this policy blocks that creation attempt outright. The policy does not evaluate container properties or settings; it simply prevents the write operation itself, so any PUT aimed at creating a container will fail with an authorization/denial error.

Why this answer

The Azure Policy assigned to the subscription includes a policy definition that explicitly denies the creation of blob containers. When the user attempts to create a blob container via the Azure portal, Azure Policy evaluates the request against the assigned policies and returns a deny error because the action violates the policy rule. This is the most direct and likely reason for the denial.

Exam trap

The trap here is that candidates may assume the error is due to a missing feature or configuration (like immutability or encryption) rather than recognizing that Azure Policy can directly deny resource creation actions based on custom or built-in policy definitions.

How to eliminate wrong answers

Option B is wrong because immutable storage is a feature that can be enabled on a blob container after creation, but it does not prevent the creation of the container itself; the deny error is not related to immutability. Option C is wrong because enabling public access is a configuration setting on a container, not a prerequisite for creation, and Azure Policy would not deny creation solely based on the intent to enable public access unless a specific policy targets that setting. Option D is wrong because encryption is enabled by default on all Azure storage accounts using Azure Storage Service Encryption (SSE), and the absence of encryption would not block container creation; it is a separate compliance check.

66
MCQmedium

A global company stores customer profile data in JSON format. The application requires low-latency writes and reads from multiple regions. The solution must support multi-region writes with automatic conflict resolution and provide high availability. Which Azure Cosmos DB configuration should they choose?

A.SQL API with eventual consistency and multi-region writes enabled
B.MongoDB API with strong consistency and multi-region writes enabled
C.Table API with consistent prefix consistency and single-region writes
D.Gremlin API with session consistency and multi-region writes enabled
AnswerA

The SQL API natively stores JSON documents and supports multi-region writes as long as consistency is not set to strong or bounded staleness. Eventual consistency is the default and, along with session and consistent prefix, is compatible with an Azure Cosmos DB account configured for multiple write regions. When multiple write regions are used, Cosmos DB automatically resolves conflicts using last-writer-wins or a custom conflict resolution policy, making this a fully valid configuration.

Why this answer

The scenario demands low-latency multi-region writes with automatic conflict resolution and high availability. Azure Cosmos DB's SQL API supports multi-region writes with eventual consistency, which is the only consistency level that allows multi-region writes. Eventual consistency provides the lowest latency and highest availability, and Cosmos DB's automatic conflict resolution handles concurrent writes across regions using last-writer-wins (LWW) or custom conflict resolution policies.

Exam trap

The trap here is that candidates often assume strong consistency is required for data integrity, but Azure Cosmos DB enforces that multi-region writes only work with eventual consistency, and automatic conflict resolution handles the trade-off between consistency and availability.

How to eliminate wrong answers

Option B is wrong because strong consistency cannot be used with multi-region writes; Cosmos DB restricts multi-region writes to eventual consistency only, as strong consistency would require synchronous replication across regions, defeating low-latency writes. Option C is wrong because single-region writes do not meet the requirement for multi-region writes, and consistent prefix consistency is not the recommended choice for multi-region write scenarios. Option D is wrong because Gremlin API (graph) is not optimized for JSON document storage and multi-region writes with session consistency do not provide automatic conflict resolution; session consistency is scoped to a single client session and does not handle cross-region conflicts.

67
MCQhard

A company needs to store and analyze petabytes of semi-structured data from IoT devices. The data is append-only and written in time order. They need to support fast queries on time ranges and also aggregate data in real-time. Which Azure data service should they use?

A.Azure Data Explorer
B.Azure Cosmos DB
C.Azure SQL Database
D.Azure Table Storage
AnswerA

Azure Data Explorer is a purpose-built analytics engine for petabyte-scale, time-series data that arrives continuously from IoT sources. It ingests semi-structured payloads (JSON, Avro, etc.) without requiring a predefined schema, then applies columnar storage and a distributed sharding architecture that accelerates real-time aggregation and time-window queries. Its Kusto Query Language (KQL) is designed for slicing, rolling averages, and anomaly detection on streaming telemetry, which makes it the correct choice here.

Why this answer

Azure Data Explorer (ADX) is purpose-built for high-performance analysis of large volumes of time-series and semi-structured data. It supports append-only ingestion, optimized time-range queries via its columnar storage and indexing, and real-time aggregation using Kusto Query Language (KQL) with built-in materialized views and update policies.

Exam trap

The trap here is that candidates often confuse Azure Data Explorer with Azure Cosmos DB because both handle semi-structured data, but Cosmos DB is optimized for transactional workloads with point reads and writes, not for petabyte-scale analytical time-series queries.

How to eliminate wrong answers

Option B (Azure Cosmos DB) is wrong because it is a globally distributed, multi-model NoSQL database optimized for low-latency transactional workloads, not for petabyte-scale analytical queries on append-only time-series data; its indexing and query patterns are not designed for high-throughput time-range scans. Option C (Azure SQL Database) is wrong because it is a relational OLTP database that struggles with petabyte-scale semi-structured data and append-only ingestion rates, and its indexing and query engine are not optimized for time-series analytics. Option D (Azure Table Storage) is wrong because it is a key-value store with limited query capabilities (only on partition and row keys), no native support for time-range aggregations, and poor performance for real-time analytics on large datasets.

68
MCQmedium

A software company hosts multiple small databases for different clients on Azure SQL Database. Each database has low average usage but experiences unpredictable spikes. The company wants to minimize cost by pooling resources across databases while allowing each database to consume resources up to a set limit during spikes. They also need the ability to easily add new databases without manual sizing. Which Azure SQL Database deployment option should they choose?

A.Azure SQL Database elastic pool
B.Azure SQL Database single database with reserved capacity
C.Azure SQL Managed Instance
D.SQL Server on Azure Virtual Machines
AnswerA

An Azure SQL Database elastic pool allocates a shared set of eDTUs or vCores across multiple databases, allowing each database to burst beyond its guaranteed minimum during demand spikes while keeping baseline usage low. You pay for the pool's aggregate compute and storage, not per-database sizing, which dramatically lowers cost when workloads have low average utilization but unpredictable peaks. Adding a new database to the pool requires no additional compute provisioning, and per-database settings like max/min eDTUs let you control resource sharing efficiently.

Why this answer

Azure SQL Database elastic pool is the correct choice because it allows multiple databases to share a fixed pool of resources (eDTUs or vCores), which minimizes cost by pooling resources across databases with low average usage and unpredictable spikes. Each database can automatically burst up to a configurable per-database resource limit (e.g., max eDTU per database) during spikes, and new databases can be added to the pool without manual sizing, as they simply consume from the shared pool.

Exam trap

The trap here is that candidates may choose single database with reserved capacity (Option B) thinking it offers cost savings, but they overlook that reserved capacity applies to a single database and does not provide resource pooling or automatic bursting across multiple databases, making it more expensive for the described workload.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database single database with reserved capacity reserves compute resources for a single database, which does not pool resources across multiple databases and would be cost-inefficient for low-average-usage databases with spikes. Option C is wrong because Azure SQL Managed Instance is a fully managed instance of SQL Server with fixed resource limits per instance, not designed for pooling resources across many small databases with unpredictable spikes, and it requires manual sizing for each new database. Option D is wrong because SQL Server on Azure Virtual Machines requires manual management of VM resources, does not provide built-in resource pooling or automatic bursting across databases, and incurs higher operational overhead and cost for many small databases.

69
MCQmedium

A company runs a data analytics workload that processes large amounts of unstructured data (images and videos). The data is accessed frequently for the first month, then rarely. They need to store the data cost-effectively for 7 years to meet compliance. The solution must support fast retrieval of data within the first month. Which Azure storage solution should they recommend?

A.Azure Blob Storage with hot tier for 30 days, then lifecycle management to cool tier for 6 months, then archive tier
B.Azure Blob Storage with premium tier for 30 days, then lifecycle to archive tier
C.Azure Files with lifecycle management
D.Azure Disk Storage with snapshots
AnswerA

This design correctly aligns storage cost with data access patterns over time. During the first 30 days the data is actively processed, so the hot tier's low latency and high throughput are appropriate; lifecycle management then automatically transitions blobs to the cool tier for 6 months, reducing base storage cost while still allowing analytical reads. After that period, moving to the archive tier provides the cheapest per-gigabyte storage for long-term retention, with retrieval latency acceptable for rarely accessed datasets. Azure Blob Storage scales to massive amounts of unstructured data, making this a cost-effective and operationally efficient lifecycle strategy.

Why this answer

Azure Blob Storage with hot tier for the first 30 days meets the fast retrieval requirement for frequently accessed data, while lifecycle management automatically moves data to cool tier for 6 months and then to archive tier for the remaining 7-year compliance period, minimizing cost. The archive tier offers the lowest storage cost for rarely accessed data, and lifecycle policies ensure seamless transitions without manual intervention.

Exam trap

The trap here is that candidates often confuse 'premium' with 'fast retrieval' and overlook that the hot tier already provides low-latency access for frequently used data, while premium is overkill and cost-prohibitive for this workload.

How to eliminate wrong answers

Option B is wrong because the premium tier is designed for low-latency, high-transaction workloads (e.g., IoT, interactive apps) and is unnecessarily expensive for this scenario; it also lacks a cool tier transition, leading to higher costs before archiving. Option C is wrong because Azure Files is a fully managed file share for SMB/NFS protocols, not optimized for large-scale unstructured data like images and videos, and its lifecycle management is limited compared to Blob Storage tiers. Option D is wrong because Azure Disk Storage provides block-level storage for VMs, not cost-effective long-term archival for unstructured data, and snapshots are incremental backups, not a tiered storage solution for compliance.

70
MCQmedium

A company is building a global real-time collaboration platform. The application data is stored as JSON documents and needs to be available for low-latency reads and writes from multiple geographic regions. The application must support multi-region writes so that users can update data from any region with automatic conflict resolution. The company wants a fully managed database service with a guaranteed SLA for availability and throughput. Which Azure data service should they choose?

A.Azure Cosmos DB with SQL API and multiple write regions
B.Azure SQL Database with active geo-replication
C.Azure Table Storage
D.Azure Cache for Redis
AnswerA

Azure Cosmos DB with the SQL API and multiple write regions is the only option that enables true multi-region writes, allowing every regional replica to accept write operations simultaneously. This is essential for a global real-time collaboration platform because users in different parts of the world experience low-latency writes without being forced to a single primary. Cosmos DB automatically handles conflict resolution using policies such as last-writer-wins or custom merge procedures, and its turnkey global distribution provides high availability (99.999% SLA) and multiple well-defined consistency levels, making it the ideal underlying data store for such a workload.

Why this answer

Azure Cosmos DB with SQL API and multiple write regions is the correct choice because it is a fully managed, globally distributed NoSQL database that natively supports multi-region writes with automatic conflict resolution. It provides low-latency reads and writes from any region, a guaranteed SLA for availability (99.999% for multi-region writes) and throughput, and is optimized for JSON document storage, making it ideal for a real-time collaboration platform.

Exam trap

The trap here is that candidates often confuse active geo-replication in Azure SQL Database (which supports only single-region writes) with true multi-region write support, leading them to choose Option B despite its read-only secondary regions.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database with active geo-replication supports only a single writable primary region; secondary regions are read-only, which does not meet the requirement for multi-region writes. Option C is wrong because Azure Table Storage is a key-value store that does not support multi-region writes with automatic conflict resolution and lacks a guaranteed throughput SLA. Option D is wrong because Azure Cache for Redis is an in-memory cache, not a fully managed database service; it does not provide durable storage or native multi-region write capabilities with conflict resolution.

71
MCQmedium

A company ingests millions of IoT sensor data points per second. They need a fully managed analytics service optimized for time-series data that can ingest high-velocity data, perform real-time analytics, and store data for historical analysis. The solution must integrate with Azure Stream Analytics for stream processing. Which Azure data service should they choose?

A.Azure Cosmos DB
B.Azure SQL Database
C.Azure Data Explorer (ADX)
D.Azure Blob Storage
AnswerC

Azure Data Explorer (ADX) is a big data analytics service specifically engineered for time-series and log data, combining a columnar storage engine with a distributed, scale-out architecture. It can ingest millions of events per second from Azure Stream Analytics, IoT Hub, or Event Hubs, and its Kusto Query Language (KQL) provides native time-series functions such as bin(), make-series, and series_decompose for real-time aggregation, anomaly detection, and forecasting. The engine uses automatic indexing, caching, and data compression to deliver rapid query responses over billions of records, making it the correct choice for this IoT scenario.

Why this answer

Azure Data Explorer (ADX) is the correct choice because it is a fully managed, high-performance analytics service optimized for time-series and log data. It can ingest millions of IoT sensor data points per second, perform real-time analytics with sub-second query latency, and store data for historical analysis. ADX natively integrates with Azure Stream Analytics for stream processing, making it ideal for this scenario.

Exam trap

The trap here is that candidates often confuse Azure Data Explorer with Azure Cosmos DB or Azure SQL Database because they all support time-series data, but only ADX is purpose-built for high-velocity ingestion and real-time analytics with native Stream Analytics integration.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL database designed for transactional workloads with multi-model support, not optimized for high-velocity time-series analytics or native integration with Azure Stream Analytics. Option B is wrong because Azure SQL Database is a relational database for OLTP workloads, lacking the columnar storage, ingestion pipeline, and query engine optimized for time-series data at millions of events per second. Option D is wrong because Azure Blob Storage is an object storage service for unstructured data, not an analytics engine; it cannot perform real-time analytics or directly integrate with Azure Stream Analytics for stream processing.

72
Multi-Selectmedium

Which TWO of the following are benefits of using Azure Cosmos DB for a globally distributed application?

Select 2 answers
A.Multiple well-defined consistency levels
B.Full support for SQL Server features like stored procedures
C.Turnkey global distribution across multiple Azure regions
D.Automatic failover to a secondary region without manual intervention
E.Support for only the SQL API
AnswersA, C

Cosmos DB exposes five well-defined consistency levels—Strong, Bounded Staleness, Session, Consistent Prefix, and Eventual—giving you fine-grained control over the trade-off between data freshness and availability/latency. Unlike a fixed default, you can set the consistency level at the account or even at the individual request level, which is a core selling point for globally distributed workloads.

Why this answer

Azure Cosmos DB offers multiple well-defined consistency levels (Strong, Bounded Staleness, Session, Consistent Prefix, Eventual) that allow developers to balance data consistency, availability, and latency according to application requirements. This flexibility is a key benefit for globally distributed applications because different operations may tolerate different levels of staleness while still meeting SLAs.

Exam trap

The trap here is that candidates often confuse 'automatic failover' with 'no manual intervention required'—Azure Cosmos DB requires explicit configuration (enabling automatic failover and setting region priorities) for it to occur automatically, and even then, failover is not instantaneous and may involve a brief period of unavailability.

73
Multi-Selecteasy

Which TWO of the following are features of Azure SQL Database that help ensure high availability? (Select two.)

Select 2 answers
A.Active geo-replication
B.Long-term retention (LTR) backups
C.Automatic tuning
D.Zone-redundant availability
E.Transparent Data Encryption (TDE)
AnswersA, D

Active geo-replication is a correct answer because it replicates your database continuously to a secondary server in a different Azure region, enabling disaster recovery across regional failures. It maintains a readable secondary replica that can be promoted through failover, and you can have up to four secondaries. This directly supports high availability by ensuring data and service remain accessible if the primary region goes down. Because it provides an alternative physical location for the database, it meets the question's criteria.

Why this answer

Active geo-replication (Option A) creates readable secondary replicas of an Azure SQL Database in a paired Azure region, enabling manual or automatic failover to maintain availability during a regional outage. This feature ensures high availability by providing disaster recovery capabilities with a Recovery Point Objective (RPO) of up to 5 seconds and a Recovery Time Objective (RTO) of less than 1 hour, depending on the failover group configuration.

Exam trap

The trap here is that candidates often confuse backup features (like LTR) or security features (like TDE) with high availability mechanisms, but only replication-based solutions (geo-replication and zone-redundancy) directly address availability during failures.

74
MCQhard

A company stores terabytes of archival data that must be retained for 10 years per regulatory requirements. The data is accessed infrequently (once or twice per year) and retrieval latency of up to 5 hours is acceptable. The company wants the lowest storage cost. They also need to ensure data is encrypted at rest and immutability to prevent deletion or modification during the retention period. Which Azure storage solution should they choose?

A.Azure Blob Storage with Hot tier and lifecycle management to Archive tier with WORM policy
B.Azure Blob Storage with Cool tier and lifecycle management to Archive tier with legal hold
C.Azure Blob Storage with Archive tier and immutability policy (time-based retention)
D.Azure Files with premium tier and soft delete
AnswerC

This design places blobs directly in Archive tier, which offers the lowest storage cost of any Blob Storage tier and is specifically designed for long-lived, rarely accessed data. A time-based retention immutability policy on the container can be locked, making it WORM-compliant and preventing blobs from being deleted or overwritten for the configured 10-year period. Because the retention period is enforced automatically and expires on schedule, and because no earlier tier is used, there are no unnecessary transition costs or manual steps.

Why this answer

Azure Blob Storage's Archive tier offers the lowest storage cost for infrequently accessed data, and the immutability policy with time-based retention provides WORM (Write Once, Read Many) compliance to prevent deletion or modification for the required 10-year period. The 5-hour retrieval latency is acceptable for archival data accessed once or twice per year, and encryption at rest is automatically enabled for all Azure Blob Storage tiers.

Exam trap

The trap here is that candidates often confuse legal hold (which is indefinite and does not prevent modification) with time-based retention immutability policy, or they incorrectly choose a higher-cost tier like Hot or Cool thinking lifecycle management will reduce costs, ignoring that the Archive tier itself is the cheapest and directly meets the latency requirement.

How to eliminate wrong answers

Option A is wrong because the Hot tier is the most expensive storage tier and is unnecessary for archival data accessed once or twice per year; lifecycle management to Archive tier adds complexity but the Hot tier cost is wasted. Option B is wrong because legal hold is an indefinite retention mechanism that cannot enforce a specific 10-year retention period, and it does not prevent modification of blobs (only deletion); the Cool tier is also more expensive than Archive. Option D is wrong because Azure Files with premium tier is designed for low-latency file shares and is extremely costly for terabytes of archival data, and soft delete does not provide immutability or prevent modification.

75
MCQeasy

A startup needs a cost-effective data storage solution for its application logs. The logs are accessed infrequently but must be available for audit purposes for up to 3 years. The solution should minimize storage costs while allowing data retrieval within 24 hours when needed. Which Azure storage tier should the company recommend?

A.Azure Blob Storage Cool tier
B.Azure Blob Storage Hot tier
C.Azure Blob Storage Archive tier
D.Azure Blob Storage Premium tier
AnswerC

The Archive tier is Azure's most economical storage option for data that is rarely accessed and can tolerate a retrieval latency of up to 15 hours because the blob must be rehydrated to Hot or Cool before reading. It is ideal for long-term retention, backup archives, and compliance records, with the lowest per-GB storage price. This directly satisfies the startup's need for a cost-effective solution for infrequently accessed data.

Why this answer

The Archive tier is the most cost-effective option for data that is infrequently accessed and requires retrieval times of up to 15 hours (standard) or 24 hours (high-priority). Since the logs must be available within 24 hours and stored for up to 3 years, Archive meets both the cost and retrieval requirements, as it offers the lowest storage cost among Azure Blob Storage tiers.

Exam trap

The trap here is that candidates often confuse the Archive tier's retrieval time with the Hot or Cool tiers, assuming Archive is too slow for any audit requirement, but the 24-hour SLA for high-priority rehydration makes it suitable for this scenario.

How to eliminate wrong answers

Option A is wrong because the Cool tier is designed for data accessed less than once per month, but its storage cost is higher than Archive, and it offers near-instant retrieval, which is unnecessary given the 24-hour retrieval window. Option B is wrong because the Hot tier is optimized for frequent access (multiple times per month) and has the highest storage cost, making it unsuitable for infrequently accessed audit logs. Option D is wrong because the Premium tier is intended for low-latency, high-transaction workloads (e.g., IoT, real-time analytics) and incurs the highest cost, which is not justified for archival audit logs.

Page 1 of 3 · 180 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design data storage solutions questions.