Courseiva

CCNA Design data storage solutions Questions

75 of 180 questions · Page 2/3 · Design data storage solutions · Answers revealed

76
MCQmedium

A healthcare organization stores patient records in Azure SQL Database. They need to ensure that all read queries against the database are directed to a read-only replica to offload the primary. Which feature should you configure?

A.Elastic database queries
B.Failover groups
C.Read scale-out
D.Active geo-replication
AnswerC

Read scale-out in Azure SQL Database uses a readable secondary replica created automatically in the Premium/Business Critical or Hyperscale service tiers, and it routes sessions that specify ApplicationIntent=ReadOnly to that replica. This lets BI and reporting workloads query the secondary while transactional workloads use the primary, and read-only queries are guaranteed to see a transactionally consistent snapshot at the time of the replica's last commit. It is specifically designed to offload reads, not to provide failover or cross-region DR.

Why this answer

Read scale-out in Azure SQL Database allows you to direct read-only queries to a read-only replica, offloading the primary database. By setting the `ApplicationIntent=ReadOnly` connection string parameter, queries are automatically routed to the secondary replica, which is ideal for read-heavy workloads like patient record queries.

Exam trap

The trap here is that candidates confuse Active geo-replication (which also provides readable secondaries) with Read scale-out, but Active geo-replication requires explicit connection string changes per replica, whereas Read scale-out automatically routes read-only queries via the same logical server endpoint.

How to eliminate wrong answers

Option A is wrong because Elastic database queries are used to run distributed queries across multiple databases, not to offload reads to a read-only replica. Option B is wrong because Failover groups provide high availability and geo-replication management, but they do not automatically route read queries to a read-only replica without additional configuration. Option D is wrong because Active geo-replication creates readable secondary replicas in different regions for disaster recovery, but it does not natively support automatic read-only query routing from the primary connection string; it requires manual connection string changes.

77
Multi-Selecthard

Which THREE of the following are valid methods to securely transfer data to Azure Blob Storage? (Select three.)

Select 3 answers
A.Azure Data Box
B.Azure File Sync
C.AzCopy
D.Azure Migrate
E.Azure Import/Export service
AnswersA, C, E

Azure Data Box is a physical, ruggedized storage appliance supplied by Microsoft to accelerate offline transfers of large volumes of data to Azure Blob Storage. You order the device through the portal, copy data to its local SMB/NFS shares, ship it back, and Microsoft uploads the contents to blob storage. The device encrypts data at rest with BitLocker and is irreversibly erased after upload, making it ideal when network transfer would take days or weeks.

Why this answer

Azure Data Box is a physical data transfer solution that allows you to securely transfer large volumes of data to Azure Blob Storage when network transfer is impractical. It uses AES-256 encryption for data at rest and TLS for data in transit, and after the device is shipped back, data is automatically uploaded to your designated storage account.

Exam trap

The trap here is that candidates often confuse Azure File Sync with a general-purpose data transfer tool, but it is strictly for file shares (SMB) and cannot target Blob Storage, while Azure Migrate is mistaken for a data transfer service when it is actually a migration orchestration tool for servers and applications.

78
MCQhard

You are designing a storage solution for a global e-commerce platform that must serve users from multiple regions with low latency. The data includes product catalog (read-heavy, rarely updated) and user session state (write-heavy, short-lived). Which combination of Azure services meets the requirements?

A.Azure Cosmos DB for session state and Azure Front Door with Azure CDN for catalog.
B.Azure Cache for Redis for session state and Azure Front Door for catalog.
C.Azure Table Storage for session state and Azure Front Door for catalog.
D.Azure SQL Database with geo-replication for both.
AnswerA

Azure Cosmos DB is the correct choice for session state because it provides multi-region writes with automatic failover, ensuring globally distributed users can write and read session data with low latency and no single point of failure. Its tunable consistency levels allow you to balance performance against data freshness, while Azure Front Door with Azure CDN delivers the global catalog by routing dynamic traffic intelligently and caching static/mixed content at the edge, offloading origin servers and improving read-heavy catalog performance.

Why this answer

Azure Cosmos DB is ideal for session state because it offers multi-region writes with single-digit-millisecond latency and automatic failover, meeting the write-heavy, short-lived requirements. Azure Front Door with Azure CDN provides global load balancing and caching for the read-heavy, rarely updated product catalog, ensuring low-latency content delivery from the nearest point of presence.

Exam trap

The trap here is that candidates often confuse Azure Cache for Redis as a durable session store, but it is a volatile cache that requires a persistence strategy (e.g., Redis persistence or Azure Cache for Redis with data persistence) to avoid data loss, which is not suitable for session state that must survive restarts.

How to eliminate wrong answers

Option B is wrong because Azure Cache for Redis is an in-memory cache, not a durable storage solution; it would lose session state on restart or scaling events, making it unsuitable for persistent session state in a global e-commerce platform. Option C is wrong because Azure Table Storage is a NoSQL key-value store with higher latency and no native multi-region write support, failing to meet the low-latency write requirements for session state. Option D is wrong because Azure SQL Database with geo-replication is optimized for structured relational data and ACID transactions, not for the high-throughput, schema-flexible session state or the read-heavy catalog caching; it also introduces unnecessary cost and complexity for this workload.

79
MCQhard

A company uses Azure NetApp Files for high-performance file shares accessed by Linux VMs. They need to reduce latency for read-heavy workloads. Which configuration should you implement?

A.Migrate to Azure Files with Azure File Sync
B.Enable read-only cache on the volume
C.Disable the export policy to allow all clients
D.Mount the volume using SMB protocol
AnswerB

Enabling a read-only cache on the volume configures Azure NetApp Files to use local NVMe or SSD storage on the compute cluster as a cache for repeated reads, dramatically reducing latency for read-heavy workloads. This feature is transparent to clients and requires no client-side changes, as cached data is served without hitting the underlying storage tier. It is a targeted, low-friction optimization that directly addresses read performance, unlike cross-service migrations or protocol changes.

Why this answer

Azure NetApp Files supports a read-only cache option on volumes, which stores frequently accessed data in a high-speed cache (SSD-based) local to the compute resources. This reduces read latency for read-heavy workloads by serving data from the cache instead of the underlying storage tier. The cache is transparent to the Linux VMs and requires no application changes.

Exam trap

The trap here is that candidates may confuse Azure NetApp Files with Azure Files, assuming that Azure File Sync or SMB mounting can provide similar performance benefits, when in fact Azure NetApp Files uses NFS and its read-only cache is the specific feature designed for reducing read latency.

How to eliminate wrong answers

Option A is wrong because migrating to Azure Files with Azure File Sync does not provide the same low-latency, high-performance characteristics as Azure NetApp Files, and Azure File Sync is designed for hybrid caching, not for reducing latency within Azure. Option C is wrong because disabling the export policy to allow all clients removes all access controls and security, which is a security risk and does not reduce latency. Option D is wrong because mounting the volume using SMB protocol is not supported for Azure NetApp Files with Linux VMs (it uses NFS), and SMB would introduce additional protocol overhead and compatibility issues, increasing latency rather than reducing it.

80
Drag & Dropmedium

Drag and drop the steps to implement Azure Traffic Manager for geographic routing into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for implementing Azure Traffic Manager for geographic routing is: first create the Traffic Manager profile, then add the endpoints (e.g., Azure regions), then configure the geographic routing mapping to assign regions to endpoints, then update DNS records to point to the Traffic Manager domain name, and finally test the routing. Skipping or reordering these steps can lead to misconfiguration or routing failures.

81
MCQmedium

A media company needs to store large volumes of video files that are processed by an application. The files are accessed via REST APIs and are rarely accessed after the first few days. The company wants to minimize storage costs by automatically moving older files to a cheaper storage tier without any manual intervention. Which Azure storage solution should they use, and which feature should they configure?

A.Azure Blob Storage with lifecycle management policies
B.Azure Files with tiering
C.Azure NetApp Files with capacity pools
D.Azure Disk Storage with managed disks
AnswerA

Azure Blob Storage is the correct choice because it provides REST API access for direct HTTP/HTTPS retrieval of video files, and its lifecycle management policies can automatically move blobs through hot, cool, and archive tiers based on age. This allows a media company to store large volumes of video files cost-effectively, with older content automatically transitioned to cheaper archive storage while still being retrievable on demand. Unlike file or disk storage, Blob Storage scales horizontally for massive unstructured data and integrates with CDNs for streaming.

Why this answer

Azure Blob Storage with lifecycle management policies is the correct solution because it allows you to define rules that automatically move blobs to cooler tiers (e.g., from Hot to Cool to Archive) based on age or last modification time, minimizing storage costs without manual intervention. The REST API access requirement is natively supported by Blob Storage via HTTPS, and the large video file workload fits well within its object storage capabilities.

Exam trap

The trap here is that candidates may confuse Azure Files tiering (which is for hybrid caching with Azure File Sync) with Blob Storage lifecycle management, or assume that any storage service with 'tiering' in its name provides automated cost-optimized tiering for REST-accessible data.

How to eliminate wrong answers

Option B is wrong because Azure Files uses the SMB protocol and does not support REST API access for video file processing; its tiering feature (Azure File Sync cloud tiering) is designed for on-premises caching, not automated cost-optimized tiering of rarely accessed files. Option C is wrong because Azure NetApp Files provides NFS/SMB volumes with capacity pools for high-performance workloads, but it lacks built-in automated lifecycle tiering to cheaper storage and is overkill for rarely accessed video files. Option D is wrong because Azure Disk Storage provides block-level managed disks for VMs, not REST API-accessible object storage, and has no lifecycle management feature to automatically move data to cheaper tiers.

82
MCQhard

A company is building a petabyte-scale data lake for analytics. They need a storage solution that supports a hierarchical namespace, POSIX-like permissions (ACLs), and is optimized for big data analytics workloads using Apache Spark and Hive. The data must be accessible over the Azure Blob Storage API. Which Azure data service should they use?

A.Azure Blob Storage (with flat namespace)
B.Azure Data Lake Storage Gen2
C.Azure NetApp Files
D.Azure HPC Cache
AnswerB

Azure Data Lake Storage Gen2 is the correct choice because it provides a hierarchical namespace atop Blob Storage, enabling POSIX-like ACLs and directory-level operations that Apache Spark and Hive require for efficient metadata-heavy workloads. It offers Hadoop-compatible access (ABFS driver) natively, supports petabyte-scale analytics, and retains Blob Storage API compatibility for existing applications. Unlike a flat namespace, the hierarchical namespace allows atomic, rename-based directory operations and fine-grained security, which are critical for high-throughput analytics pipelines exploring partition pruning and O(1) directory scans.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with POSIX-like ACLs and is natively optimized for big data analytics workloads like Apache Spark and Hive. It exposes data through the Azure Blob Storage API, meeting all stated requirements for petabyte-scale analytics.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage (which is object storage with a flat namespace) with ADLS Gen2, not realizing that the hierarchical namespace and POSIX ACLs are exclusive to ADLS Gen2 and critical for big data analytics engines like Spark and Hive.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with a flat namespace lacks a hierarchical namespace and POSIX-like ACLs, making it unsuitable for Hive and Spark workloads that rely on directory structures and fine-grained permissions. Option C is wrong because Azure NetApp Files provides NFS/SMB access with POSIX permissions but does not support the Azure Blob Storage API, which is a stated requirement. Option D is wrong because Azure HPC Cache is a caching layer for high-performance computing, not a persistent data lake storage service, and it does not provide a hierarchical namespace or native Blob API access.

83
MCQeasy

A small business is migrating its on-premises file server to Azure. The file server contains 2 TB of data that is accessed infrequently. The business wants to minimize costs and only pay for storage used. The solution must support SMB protocol and allow for on-premises caching to reduce latency. Which Azure storage solution should the business recommend?

A.Azure Files Standard tier with Azure File Sync
B.Azure Disk Storage Standard HDD with shared disks
C.Azure NetApp Files Standard tier with cross-region replication
D.Azure Blob Storage Cool tier with Azure Storage Explorer
AnswerA

Azure Files Standard tier with Azure File Sync is the correct replacement for an on-premises file server because it provides fully managed SMB 3.0 file shares that support NTFS ACLs, Active Directory identity-based authentication, and Windows-native access semantics. Azure File Sync goes further by keeping a local cache of the most frequently used files on the existing server, providing low-latency access for on-premises clients while transparently tiering older data to Azure. This delivers the exact file-sharing behavior and caching benefits a small business needs without requiring custom infrastructure or expensive enterprise storage.

Why this answer

Azure Files Standard tier with Azure File Sync is correct because it provides fully managed SMB file shares in the cloud, supports the required SMB protocol, and Azure File Sync enables on-premises caching to reduce latency. The Standard tier is cost-effective for infrequently accessed data, and the pay-as-you-go model minimizes costs by charging only for actual storage used.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with file storage, overlooking that Blob Storage does not support SMB protocol natively, and they may incorrectly choose it for cost savings without considering protocol requirements.

How to eliminate wrong answers

Option B is wrong because Azure Disk Storage Standard HDD with shared disks does not natively support the SMB protocol; it provides block-level storage that requires a VM to host a file server, adding management overhead and cost. Option C is wrong because Azure NetApp Files Standard tier is a premium, high-performance solution that is significantly more expensive than Azure Files, and cross-region replication is unnecessary for a small business with infrequently accessed data. Option D is wrong because Azure Blob Storage Cool tier does not support the SMB protocol natively; it is object storage accessed via REST APIs or tools like Azure Storage Explorer, not a file share solution.

84
MCQeasy

A company wants to store log data from multiple applications for up to 30 days for analysis. The data is append-only, and queries are infrequent but need to be fast when run. Which Azure data storage solution should you recommend?

A.Azure Log Analytics Workspace
B.Azure Table Storage
C.Azure Data Lake Storage Gen2
D.Azure Blob Storage (archive tier)
AnswerA

Log Analytics Workspace ingests append-only log data and retains it for a configurable period, here 30 days. Its Kusto query engine returns fast results on infrequent ad hoc queries, unlike blob storage, which suits archival rather than interactive analysis.

Why this answer

Azure Log Analytics Workspace is the correct choice because it is purpose-built for ingesting, storing, and querying log data from multiple sources. It supports append-only log ingestion, retains data for up to 30 days in its interactive retention tier (configurable), and provides fast Kusto Query Language (KQL) queries for infrequent analysis. The workspace integrates natively with Azure Monitor and other services, making it ideal for centralized log analysis.

Exam trap

The trap here is that candidates often choose Azure Blob Storage (archive tier) for cost savings, overlooking the explicit requirement for fast query performance, which the archive tier cannot provide due to its multi-hour rehydration latency.

How to eliminate wrong answers

Option B is wrong because Azure Table Storage is a NoSQL key-value store designed for structured, transactional data, not for log analytics; it lacks native query capabilities for time-series log data and does not support fast, ad-hoc queries across multiple log sources. Option C is wrong because Azure Data Lake Storage Gen2 is optimized for big data analytics on large volumes of unstructured or semi-structured data, not for low-latency, infrequent queries on append-only logs; it is better suited for batch processing and data lakes. Option D is wrong because Azure Blob Storage (archive tier) is designed for long-term, cold storage with high retrieval latency (hours), not for fast queries on recent log data; it is cost-effective for archival but violates the requirement for fast query performance.

85
Drag & Dropmedium

Drag and drop the steps to deploy a web app using Azure App Service with a custom domain and SSL certificate into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for deploying a web app using Azure App Service with a custom domain and SSL certificate is: create the App Service app, map the custom domain, upload the SSL certificate, bind the certificate to the domain, and finally enforce HTTPS. This sequence ensures that each step has the necessary prerequisites: the app exists before domain mapping, the domain is mapped before certificate upload and binding, and the certificate is bound before enforcing HTTPS.

86
MCQeasy

A company needs to store immutable audit logs for regulatory compliance. The logs must be stored in a write-once, read-many (WORM) state for 7 years. Which Azure storage feature should be used?

A.Azure Blob Storage immutable storage with time-based retention
B.Azure SQL Database temporal tables
C.Azure Blob Storage change feed
D.Azure Blob Storage soft delete
AnswerA

Azure Blob Storage immutable storage with time-based retention enforces a Write-Once-Read-Many (WORM) policy at the container level, preventing any blob from being modified or deleted during a user-defined retention interval. This satisfies regulatory audit-log requirements such as SEC 17a-4(f) because even the storage account owner cannot alter or purge the data until the period expires, and it can optionally be combined with legal holds for indefinite preservation.

Why this answer

Azure Blob Storage immutable storage with time-based retention enforces a WORM (Write Once, Read Many) state, preventing logs from being modified or deleted for a specified retention period. This directly meets the regulatory requirement to store audit logs immutably for 7 years, as the policy locks the data at the container or blob level and cannot be removed until the retention interval expires.

Exam trap

The trap here is that candidates confuse soft delete or change feed with immutable storage, not realizing that only immutable storage enforces a true WORM state that prevents both deletion and overwriting, which is required for regulatory compliance.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database temporal tables track historical changes to data but do not enforce WORM immutability; data can still be physically deleted or altered by privileged users. Option C is wrong because Azure Blob Storage change feed provides a transaction log of blob changes for processing, not a mechanism to prevent modifications or deletions. Option D is wrong because Azure Blob Storage soft delete only offers recovery from accidental deletion within a retention window, but does not prevent overwrites or enforce a write-once state.

87
MCQhard

A company is designing a data storage solution for an IoT pipeline that ingests time-series data from millions of devices. The data is append-only and queried by time range. The solution must support low-latency queries and automated retention policies. Which Azure data store should they choose?

A.Azure SQL Database
B.Azure Cosmos DB
C.Azure Data Explorer (ADX)
D.Azure Blob Storage with Azure Data Lake Storage Gen2
AnswerC

Azure Data Explorer (ADX) is a columnar analytics engine purpose-built for time-series and IoT data, ingesting high-velocity telemetry from Event Hubs and IoT Hub at gigabytes per second with low latency. It automatically compresses and indexes columns, uses Kusto Query Language (KQL) for time-based aggregates, filters, and pattern detection, and stores data in immutable, sharded extents that enable fast scans and retention policies. This is the correct choice for interactive, near-real-time diagnostics and analytics over append-only sensor streams.

Why this answer

Azure Data Explorer (ADX) is purpose-built for interactive analytics on large volumes of streaming, time-series data. It supports append-only ingestion, low-latency queries over time ranges via its Kusto Query Language (KQL), and native automated retention policies (e.g., soft-delete and hard-delete periods) without manual management.

Exam trap

The trap here is that candidates often confuse Cosmos DB's low-latency individual item access with the need for time-series range queries, overlooking that Cosmos DB lacks native time-series indexing and automated retention policies, while ADX is the only Azure service explicitly designed for high-throughput append-only time-series analytics with built-in lifecycle management.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database is a relational OLTP store optimized for transactional workloads with frequent updates, not for high-throughput append-only time-series ingestion or time-range queries at scale. Option B is wrong because Azure Cosmos DB is a multi-model NoSQL database designed for globally distributed, low-latency reads/writes on individual items, but it lacks native time-series optimization, efficient range scans over massive append-only streams, and built-in automated retention policies for time-series data. Option D is wrong because Azure Blob Storage with Azure Data Lake Storage Gen2 provides cheap, scalable object storage for raw data but does not offer low-latency interactive querying or native time-series analytics; it requires additional compute engines (e.g., Azure Synapse) to query, adding latency and complexity.

88
MCQhard

A company is designing a data lake for analytics. The data includes personally identifiable information (PII) that must be anonymized before analysts access it. Which Azure service should they use to automate the anonymization process?

A.Azure Policy
B.Azure SQL Database dynamic data masking
C.Azure Key Vault
D.Microsoft Purview data policies
AnswerD

Microsoft Purview data policies, which include data owner policies and Microsoft Purview access policies, can automatically classify sensitive data across sources like Azure Data Lake Storage and then enforce policies such as masking (column-level or file-level) or access control based on that classification. For a data lake, Purview's scanning engines discover sensitive data using built-in or custom classifiers, and data policies can apply masking to read operations or restrict access to certain users. This makes it the correct choice for a unified, policy-driven approach to protecting sensitive data in a data lake analytics scenario.

Why this answer

Microsoft Purview data policies allow you to define and enforce data access policies that can automatically anonymize or mask sensitive data, such as PII, when accessed by analysts. This service integrates with Azure data lake storage and provides a centralized way to manage data governance and compliance, making it the correct choice for automating anonymization in a data lake scenario.

Exam trap

The trap here is that candidates often confuse Azure SQL Database dynamic data masking (Option B) with a general-purpose anonymization solution, but it only works for relational databases, not for data lakes, and does not automate the process across heterogeneous file formats.

How to eliminate wrong answers

Option A is wrong because Azure Policy is used to enforce organizational standards and assess compliance across Azure resources, not to automate data-level anonymization or masking within a data lake. Option B is wrong because Azure SQL Database dynamic data masking applies masking at the database query level for SQL databases, but it is not designed for data lake storage (e.g., Azure Data Lake Storage Gen2) and does not automate anonymization for file-based analytics. Option C is wrong because Azure Key Vault is a service for securely storing and managing secrets, keys, and certificates, not for applying data anonymization or masking transformations.

89
MCQeasy

A company plans to store operational logs from Azure App Services in a scalable and cost-effective way. The logs must be retained for 90 days and then automatically deleted. Which Azure data storage solution should you recommend?

A.Azure Blob Storage with lifecycle management
B.Azure SQL Database with retention policy
C.Azure Log Analytics Workspace
D.Azure Cosmos DB with TTL
AnswerC

Azure Log Analytics Workspace is the correct choice because it is purpose-built for ingesting, storing, and querying operational logs from Azure resources via diagnostic settings. It provides native Kusto Query Language (KQL) for fast, interactive analysis, an integrated retention and archive policy for balancing cost and compliance, and direct integration with Azure Monitor alerts, workbooks, and dashboards. This makes it the optimal, low-friction service for operational logs that must be searched, correlated, and visualized without additional tooling.

Why this answer

Azure Log Analytics Workspace is the correct choice because it natively ingests operational logs from Azure App Services via diagnostic settings, provides a scalable and cost-effective storage tier with a 90-day retention policy that can be configured to automatically delete data after the retention period expires. It also supports Kusto Query Language (KQL) for analysis and integrates with Azure Monitor for alerting, making it purpose-built for log storage and management.

Exam trap

The trap here is that candidates may choose Azure Blob Storage with lifecycle management because they associate 'scalable and cost-effective' with blob storage, overlooking that operational logs require querying and analysis, which Log Analytics Workspace provides natively, while blob storage would require additional services like Azure Data Explorer or custom indexing to make the logs searchable.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with lifecycle management is designed for storing unstructured data like files or backups, not for operational logs that require querying and analysis; while it can retain and delete blobs after 90 days, it lacks native log ingestion, indexing, and query capabilities. Option B is wrong because Azure SQL Database is a relational database for transactional workloads, not a log storage solution; its retention policy applies to point-in-time restore backups, not to operational log data, and it is significantly more expensive for high-volume log ingestion. Option D is wrong because Azure Cosmos DB with TTL is a NoSQL database for globally distributed, low-latency applications; its time-to-live feature automatically deletes documents after a specified period, but it is not designed for log storage, lacks native integration with Azure App Services diagnostic settings, and incurs high costs for write-heavy log ingestion.

90
Multi-Selectmedium

Which TWO Azure services can be used to host a MongoDB-compatible database with global distribution? (Select two.)

Select 2 answers
A.Azure SQL Database
B.Azure Cosmos DB API for MongoDB
C.Azure Database for PostgreSQL
D.Azure Database for MongoDB (MongoDB Atlas on Azure)
E.Azure Cache for Redis
AnswersB, D

Azure Cosmos DB API for MongoDB is a first-party Azure service that implements the MongoDB wire protocol, allowing existing MongoDB SDKs, drivers, and tools to connect directly. It provides MongoDB-compatible CRUD operations, indexing, aggregation pipelines, and sharding semantics while adding Azure-native capabilities such as global distribution, multi-region writes, automatic failover, and flexible consistency levels. Because it is natively integrated with Azure Portal, ARM templates, and Azure CLI, it is a correct and widely recommended choice for hosting MongoDB-compatible workloads on Azure.

Why this answer

Azure Cosmos DB API for MongoDB is correct because it provides a MongoDB-compatible API layer over Cosmos DB's globally distributed, multi-model database engine. This allows you to use standard MongoDB drivers and tools while benefiting from Cosmos DB's turnkey global distribution, multi-region writes, and 99.999% availability SLA.

Exam trap

The trap here is that candidates may assume only one service can host a MongoDB-compatible database, overlooking that both a native MongoDB service (Atlas) and a protocol-compatible alternative (Cosmos DB API for MongoDB) are valid, and that Azure SQL Database or PostgreSQL are relational databases that cannot serve MongoDB workloads.

91
MCQeasy

A company wants to store raw data from IoT devices, social media feeds, and transactional databases for analytics. They need a storage solution that supports a hierarchical namespace for organizing data into directories and allows fine-grained access control at the directory and file level. They also need to query the data using Azure Synapse Analytics in-place. Which Azure storage solution should they use?

A.A
B.B
C.C
D.D
AnswerB

Azure Data Lake Storage Gen2 is Azure Blob Storage with a hierarchical namespace, enabling directory-level ACLs that integrate with Microsoft Entra ID for fine-grained permission control. It is optimized for large-scale analytics workloads, supports POSIX-like permissions, and integrates natively with Azure Synapse Analytics for in-place querying without data movement. Its ability to organize data into directories and subdirectories while remaining accessible via both Blob and ADLS Gen2 APIs makes it the ideal landing zone for structured and unstructured IoT and social media data.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it provides a hierarchical namespace that organizes data into directories and subdirectories, supports POSIX-like fine-grained access control at the directory and file level via ACLs, and can be queried in-place by Azure Synapse Analytics using its built-in serverless SQL pool or dedicated SQL pool. This combination of hierarchical namespace, granular security, and direct analytics integration makes it ideal for the described raw data storage and analytics scenario.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage (flat namespace, no directory ACLs) with ADLS Gen2 (hierarchical namespace, full ACL support) because both are built on the same underlying storage platform, but only ADLS Gen2 enables the directory-level organization and fine-grained access control required for enterprise analytics workloads.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage does not natively support a hierarchical namespace or fine-grained directory/file-level ACLs; it uses a flat namespace and container-level access policies, which cannot meet the directory organization and granular access control requirements. Option C is wrong because Azure Files provides SMB file shares with directory structure and ACLs, but it is not designed for in-place querying by Azure Synapse Analytics and lacks the scale-out performance and analytics integration needed for big data workloads. Option D is wrong because Azure Cosmos DB is a NoSQL database optimized for transactional and real-time workloads with its own query API (SQL, MongoDB, etc.), not a storage solution for raw data with a hierarchical namespace, and it cannot be queried in-place by Azure Synapse Analytics as a storage layer.

92
MCQmedium

A healthcare analytics platform stores semi-structured JSON documents and requires globally distributed low-latency reads with tunable consistency. Which Azure data platform should be recommended?

A.Azure Cosmos DB
B.Azure Files premium shares
C.Azure Data Factory
D.Azure SQL Managed Instance
AnswerA

Azure Cosmos DB is a globally distributed NoSQL document database with schema-agnostic indexing, making it a natural fit for semi-structured JSON payloads commonly found in healthcare analytics. Its multiple API options (for example, the core SQL API or MongoDB-compatible API) allow direct JSON document storage and querying, while tunable consistency levels and single-digit-millisecond reads satisfy low-latency operational requirements. Multi-region writes and automatic indexing remove the need for manual schema management, which is essential when analytic event shapes evolve over time.

Why this answer

Azure Cosmos DB is the correct choice because it natively supports semi-structured JSON documents, offers globally distributed multi-region writes and reads with low-latency (typically <10 ms at the 99th percentile), and provides tunable consistency levels (from strong to eventual) via its multi-master replication protocol. This directly matches the requirements for a healthcare analytics platform needing global distribution and flexible consistency.

Exam trap

The trap here is that candidates often confuse Azure SQL Managed Instance's JSON support (which can store JSON as text but lacks native document indexing and global distribution) with a true document database, or they mistakenly think Azure Files can serve as a document store because it supports file-based access, ignoring the need for queryable semi-structured data and tunable consistency.

How to eliminate wrong answers

Option B is wrong because Azure Files premium shares provide SMB/NFS file shares with low latency but are not designed for semi-structured JSON document storage or globally distributed low-latency reads with tunable consistency; they are a file-level service, not a document database. Option C is wrong because Azure Data Factory is a cloud-based ETL and data integration service, not a data store; it cannot serve low-latency reads or provide tunable consistency for stored documents. Option D is wrong because Azure SQL Managed Instance is a relational database engine (SQL Server) that stores data in a structured, tabular format, not semi-structured JSON documents natively, and its global distribution capabilities are limited to failover groups with eventual consistency, lacking the tunable consistency levels of Cosmos DB.

93
MCQeasy

You need to design a data storage solution for a mobile app that requires low-latency reads and writes globally. The data is JSON documents with varying schemas. Which Azure service should you choose?

A.Azure Cache for Redis
B.Azure Cosmos DB
C.Azure SQL Database
D.Azure Table Storage
AnswerB

Azure Cosmos DB is the correct choice because it is a globally distributed, multi-model NoSQL database built for mission-critical applications that need low-latency reads and writes anywhere in the world. Its turnkey global distribution with active-active multi-region writes, automatic indexing, and support for native JSON documents directly matches the mobile app's need for frequently varying schemas and fast, scalable access. Cosmos DB offers multiple consistency levels (strong, bounded staleness, session, consistent prefix, eventual) and a 99.999% availability SLA, which is essential for a mobile back end that must serve users across regions without sacrificing availability.

Why this answer

Azure Cosmos DB is the correct choice because it provides native global distribution with multi-region writes and single-digit-millisecond latency at the 99th percentile, making it ideal for a mobile app requiring low-latency reads and writes worldwide. It natively supports JSON documents with varying schemas through its document model and offers multiple consistency levels to balance performance and data integrity.

Exam trap

The trap here is that candidates often choose Azure Cache for Redis because they associate 'low-latency' with caching, but they overlook that the requirement is for a durable, globally distributed primary data store with varying JSON schemas, which Redis as a cache cannot fulfill as a persistent, globally writable database.

How to eliminate wrong answers

Option A is wrong because Azure Cache for Redis is an in-memory cache, not a primary data store, and it does not natively support global distribution with write replication or schema-variant JSON documents as a durable persistence layer. Option C is wrong because Azure SQL Database requires a fixed relational schema and does not natively handle varying JSON schemas without complex workarounds, nor does it offer the same low-latency global write distribution as Cosmos DB. Option D is wrong because Azure Table Storage is a key-value store that stores data as entities with a fixed schema (partition key and row key), not as flexible JSON documents, and it lacks native global distribution with multi-region writes.

94
MCQhard

Your company stores sensitive customer data in Azure Blob Storage. You must ensure that data is encrypted at rest using customer-managed keys (CMK) and that key rotation is automated. You also need to prevent data from being accessed by any Microsoft administrator. Which solution should you implement?

A.Use Azure Key Vault (Standard) to store customer-managed keys and enable automatic key rotation.
B.Use Azure Disk Encryption with customer-managed keys stored in Azure Key Vault.
C.Use Azure Key Vault Managed HSM with customer-managed keys and enable double encryption with infrastructure encryption.
D.Enable Azure Storage Service Encryption with platform-managed keys.
AnswerC

Azure Key Vault Managed HSM is a dedicated, tenant-isolated HSM service that gives you exclusive control over the HSM itself, with hardware-backed key generation and no direct Microsoft operator access. Storing customer-managed keys in Managed HSM lets you enforce your own key lifecycle and comply with strict regulatory mandates. Enabling infrastructure encryption adds a second, independent AES-256 encryption layer at the storage infrastructure level, resulting in double encryption of blobs at rest with keys you govern—this fully satisfies the question's need.

Why this answer

Azure Key Vault Managed HSM provides FIPS 140-2 Level 3 validated hardware security modules (HSMs) for storing customer-managed keys (CMK), supports automated key rotation, and enables double encryption via infrastructure encryption. This ensures that data is encrypted at rest with a customer-controlled key, and the use of Managed HSM prevents Microsoft administrators from accessing the key material, as the HSM is isolated and Microsoft has no export or visibility permissions.

Exam trap

The trap here is that candidates often confuse Azure Key Vault (Standard) with Managed HSM, assuming both provide the same level of isolation and security, but only Managed HSM offers FIPS 140-2 Level 3 HSM-backed keys and prevents Microsoft administrator access, which is critical for sensitive customer data scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Key Vault (Standard) uses software-backed keys (not HSM-backed) and does not provide the same level of isolation to prevent Microsoft administrators from accessing key material; it also does not support double encryption with infrastructure encryption. Option B is wrong because Azure Disk Encryption is designed for encrypting virtual machine disks, not Azure Blob Storage data, and it does not address the requirement to prevent Microsoft administrator access to the keys. Option D is wrong because Azure Storage Service Encryption with platform-managed keys uses Microsoft-managed keys, not customer-managed keys, and thus does not meet the CMK requirement or provide isolation from Microsoft administrators.

95
MCQeasy

A company wants to migrate its on-premises file server to Azure with minimal application changes. The application accesses files over the SMB protocol and requires identity-based access using the existing on-premises Active Directory Domain Services (AD DS). They need the solution to be fully managed with low latency. Which Azure storage solution should they choose?

A.Azure Files
B.Azure NetApp Files
C.Azure Blob Storage with NFS 3.0
D.Azure Disk Storage
AnswerA

Azure Files is the correct choice because it delivers fully managed SMB file shares natively in Azure, allowing the on-premises file server to be lifted and shifted without any application changes. It supports authentication with existing on-premises Active Directory Domain Services identity, so users and permissions map directly, and being a PaaS service, it requires no dedicated network infrastructure like delegated subnets or capacity pools to maintain.

Why this answer

Azure Files is the correct choice because it provides fully managed SMB file shares that can be accessed over the SMB protocol with identity-based authentication using on-premises AD DS via Azure Files AD DS integration. This allows the application to connect with minimal changes, as it continues to use SMB and existing domain credentials, while Azure Files offers low-latency access when deployed in the same region as the application.

Exam trap

The trap here is that candidates often confuse Azure NetApp Files with Azure Files, assuming that because NetApp Files supports SMB and AD DS, it is the best choice, but they overlook the 'fully managed' requirement and the fact that Azure Files is the simpler, more cost-effective PaaS solution for standard file server migrations.

How to eliminate wrong answers

Option B is wrong because Azure NetApp Files is a high-performance, enterprise-grade file service that supports SMB and AD DS, but it is not fully managed in the same sense as Azure Files (it requires provisioning of capacity pools and has a different pricing model); it also introduces unnecessary complexity for a standard file server migration. Option C is wrong because Azure Blob Storage with NFS 3.0 does not support the SMB protocol, and it lacks native identity-based access with on-premises AD DS, requiring different authentication mechanisms. Option D is wrong because Azure Disk Storage provides block-level storage attached to a VM, not a shared file service; it would require the application to be rewritten or run on a VM with a file server role, increasing management overhead and not meeting the fully managed requirement.

96
Drag & Dropmedium

Drag and drop the steps to migrate an on-premises SQL Server database to Azure SQL Database using the Data Migration Assistant (DMA) into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for migrating an on-premises SQL Server database to Azure SQL Database using the Data Migration Assistant is: first, install the DMA tool; second, run an assessment to identify compatibility issues; third, fix the identified issues; and finally, perform the migration and monitor the process. This order ensures that all potential problems are resolved before migration, reducing the risk of downtime or data loss.

97
MCQmedium

Your organization needs to share large files (up to 100 GB) with external partners securely. The solution must allow partners to access files for a limited time and track who accessed which file. Which Azure solution should you use?

A.Azure Data Box.
B.Azure Blob Storage with shared access signatures (SAS).
C.Azure Files with SMB protocol.
D.Azure Blob Storage with public access.
AnswerB

Azure Blob Storage with shared access signatures (SAS) provides granular, time-limited, and permission-scoped access to specific blobs or containers, enabling external partners to upload/download files up to 100 GB without exposing the storage account publicly. SAS tokens can be revoked, support IP restrictions, and integrate with Azure Storage analytics logging to track exactly who accessed what and when, fulfilling both access control and audit requirements.

Why this answer

Azure Blob Storage with shared access signatures (SAS) is correct because it allows you to generate time-limited, permission-restricted URIs that grant external partners secure access to large files (up to 100 GB) without exposing the storage account key. SAS tokens can be configured with an expiration time and, when combined with Azure Storage analytics logging, enable tracking of who accessed which file by correlating the SAS identifier with log entries.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with public access (anonymous) as a quick sharing method, overlooking that SAS tokens provide the necessary time-limited, auditable access control required for secure external file sharing.

How to eliminate wrong answers

Option A is wrong because Azure Data Box is a physical data transfer device designed for offline bulk data migration (typically 40 TB+), not for sharing files online with external partners. Option C is wrong because Azure Files with SMB protocol requires network-level access (VPN or ExpressRoute) and does not natively support time-limited, auditable sharing with external partners over the internet. Option D is wrong because Azure Blob Storage with public access allows anonymous read access to containers or blobs without any authentication, expiration, or per-user tracking, violating both the security and audit requirements.

98
Matchingmedium

Match each Azure disaster recovery feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Orchestrates replication and failover of VMs

Cloud-based backup for Azure and on-premises workloads

Physically separate datacenter within a region

Logical grouping for fault and update domains

Another Azure region for cross-region replication

Why these pairings

Azure disaster recovery features include Site Recovery for replication and failover, Backup for retention, Availability Zones for datacenter failure protection, and Paired Regions for region-level disaster recovery. Common confusions involve mixing the roles of Site Recovery and Backup.

99
MCQmedium

A company is building a new application that requires a fully managed relational database. The application has varying workloads across different databases. The company wants to pool resources to optimize cost and allow each database to scale as needed. They also need automated backups with point-in-time restore and geo-replication for disaster recovery. Which Azure data service should they use?

A.Azure SQL Database
B.Azure SQL Managed Instance
C.Azure Database for MySQL
D.Azure Database for PostgreSQL
AnswerA

Azure SQL Database is correct because its elastic pool model lets multiple databases share a fixed pool of eDTUs or vCores, so databases can burst above their individual allocation as long as the pool's total capacity is not exceeded. This supports cost optimization for varying workloads across separate databases while still delivering automated backups, point-in-time restore, and active geo-replication. As a fully managed service, Azure SQL Database handles patching, backups, and high availability without manual infrastructure management.

Why this answer

Azure SQL Database is a fully managed relational database service that supports elastic pools, which allow you to pool resources across multiple databases to optimize cost and enable each database to scale independently based on demand. It also provides automated backups with point-in-time restore (PITR) and active geo-replication for disaster recovery, meeting all the stated requirements.

Exam trap

The trap here is that candidates often confuse Azure SQL Database with Azure SQL Managed Instance, assuming Managed Instance also supports elastic pools, but it does not—elastic pools are exclusive to Azure SQL Database.

How to eliminate wrong answers

Option B (Azure SQL Managed Instance) is wrong because it is designed for lift-and-shift migrations requiring near 100% SQL Server compatibility and does not support elastic pools for resource pooling across databases; it uses a fixed resource model per instance. Option C (Azure Database for MySQL) is wrong because it is a fully managed MySQL service but does not support elastic pools or the same geo-replication capabilities as Azure SQL Database; its geo-replication is limited to read replicas in paired regions without active failover. Option D (Azure Database for PostgreSQL) is wrong because it is a fully managed PostgreSQL service but lacks elastic pool functionality and its geo-replication is based on read replicas, not active geo-replication with automatic failover.

100
MCQmedium

You need to design a disaster recovery strategy for an Azure SQL Database that supports a critical financial application. The recovery point objective (RPO) is 5 seconds and recovery time objective (RTO) is 30 seconds. Which option should you choose?

A.Use failover groups with manual failover.
B.Use long-term retention (LTR) backups.
C.Configure active geo-replication with auto-failover groups.
D.Enable geo-restore (geo-redundant backup).
AnswerC

Configuring active geo-replication with auto-failover groups replicates every committed transaction asynchronously to a readable secondary in a paired region, providing an RPO of 5 seconds and an RTO of 30 seconds without requiring manual intervention. The auto-failover group constantly monitors the primary and automatically changes the secondary to become primary upon outage detection, ensuring end-to-end availability with minimal data loss. This is the correct choice when a demanding recovery SLA is required.

Why this answer

Active geo-replication with auto-failover groups is the correct choice because it provides continuous data replication to a secondary region with an RPO of 5 seconds (asynchronous replication) and an RTO of 30 seconds when auto-failover is enabled. This meets the stringent requirements for a critical financial application, as failover groups handle both database and server-level failover automatically, ensuring minimal data loss and rapid recovery.

Exam trap

The trap here is that candidates often confuse geo-restore (which uses backups and has a much higher RPO/RTO) with active geo-replication, or they assume manual failover can meet strict RTOs, but only auto-failover groups provide the sub-minute RTO and near-zero RPO required for critical applications.

How to eliminate wrong answers

Option A is wrong because manual failover cannot achieve a 30-second RTO, as it requires human intervention to trigger the failover, which introduces unpredictable delays. Option B is wrong because long-term retention backups are designed for archival and compliance purposes, not for rapid recovery, with RPOs measured in hours or days and RTOs in hours. Option D is wrong because geo-restore from geo-redundant backups has an RPO of 1 hour (backups are taken every 5-10 minutes but replicated asynchronously) and an RTO of several hours, far exceeding the 5-second RPO and 30-second RTO requirements.

101
Multi-Selecthard

Which THREE of the following are best practices for designing a data storage solution using Azure Cosmos DB?

Select 3 answers
A.Store large binary data (e.g., images) directly as documents
B.Use the appropriate consistency level based on application requirements
C.Choose a partition key that evenly distributes request units (RU) across partitions
D.Enable autoscale on containers with unpredictable traffic patterns
E.Use manual provisioned throughput for all containers to control costs
AnswersB, C, D

Choosing the appropriate consistency level for each application requirement is a core Cosmos DB design practice because consistency directly impacts throughput and latency. Strong consistency requires more RUs and may have higher latency across regions, while session, eventual, or bounded staleness can reduce cost and improve performance. This decision must be made deliberately: banking transactions need strong consistency, while IoT telemetry or product catalog reads can tolerate eventual consistency to save resources.

Why this answer

Azure Cosmos DB offers five well-defined consistency levels (strong, bounded staleness, session, consistent prefix, and eventual). Choosing the appropriate level based on application requirements is a best practice, as it balances data consistency guarantees against latency and throughput. For example, session consistency is ideal for multi-user applications where each user reads their own writes, while strong consistency ensures linearizability but reduces availability and increases latency.

Exam trap

The trap here is that candidates often assume manual throughput is always more cost-effective, but Azure Cosmos DB's autoscale is designed to handle unpredictable workloads without the risk of throttling or over-provisioning, making it a best practice for such scenarios.

102
MCQeasy

You are designing a storage solution for a globally distributed application that requires low-latency read access from multiple regions. Which Azure storage solution should you recommend?

A.Azure Blob Storage with read-access geo-redundant storage (RA-GRS)
B.Azure SQL Database with active geo-replication
C.Azure Files with Azure File Sync
D.Azure Cosmos DB with multi-region writes and multiple read regions
AnswerD

Azure Cosmos DB is designed for active-active global distribution: every region can accept both reads and writes, and data is automatically replicated to all regions associated with the account, with tunable consistency levels and conflict-resolution policies. This enables single-digit-millisecond read and write latencies at the 99th percentile for any region where the app is deployed, backed by SLAs for availability, latency, throughput, and consistency. For a globally distributed application, it provides the required multi-region write capability and near-local read performance that the storage options above cannot deliver.

Why this answer

Azure Cosmos DB with multi-region writes and multiple read regions is the correct choice because it provides turnkey global distribution with single-digit-millisecond latency for reads and writes from any Azure region. This solution directly addresses the requirement for low-latency read access from multiple regions, as Cosmos DB automatically replicates data to all configured regions and offers multiple consistency models to balance performance and data freshness.

Exam trap

The trap here is that candidates often confuse RA-GRS (which provides read access to only one secondary region, not multiple regions) with true multi-region active-active reads. While RA-GRS does allow reads from the secondary at any time, it cannot serve reads from multiple secondary regions and does not support multi-region writes, making Cosmos DB the better solution for global low-latency reads.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with RA-GRS provides read access from a secondary region only during failover or if the primary region is unavailable, and it does not offer active-active multi-region reads with low-latency guarantees; the secondary region is read-only and not designed for simultaneous low-latency access from multiple regions. Option B is wrong because Azure SQL Database with active geo-replication is designed for disaster recovery and read-scale workloads, but it does not support multi-region writes and typically incurs higher latency for cross-region reads compared to a globally distributed NoSQL solution like Cosmos DB. Option C is wrong because Azure Files with Azure File Sync is optimized for file sharing and caching on-premises or in a single region, not for globally distributed low-latency read access from multiple Azure regions; it relies on sync intervals and does not provide native multi-region read endpoints.

103
MCQhard

You are designing a data lake for advanced analytics in Azure. The data includes structured, semi-structured, and unstructured data. The solution must support schema-on-read and have the ability to query using SQL. Which Azure service should you choose?

A.Azure Blob Storage.
B.Azure SQL Database.
C.Azure Data Lake Storage Gen2.
D.Azure Cosmos DB.
AnswerC

Azure Data Lake Storage Gen2 (ADLS Gen2) is built on Azure Blob Storage but adds a hierarchical namespace, giving it file system semantics such as atomic directory renames and POSIX-like access control lists. It supports every data type and applies schema-on-read, meaning raw data is ingested without ETL and can be queried on demand by engines like Azure Synapse, Databricks, and PolyBase. Its native integration with SQL querying, including serverless SQL pools, makes it the optimal foundation for a scalable, high-performance data lake for advanced analytics.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) combines Blob Storage with a hierarchical namespace, enabling schema-on-read for structured, semi-structured, and unstructured data. It supports SQL-based querying via Azure Synapse Analytics, Azure Databricks, or PolyBase, making it ideal for advanced analytics scenarios.

Exam trap

The trap here is that candidates confuse Azure Blob Storage's object storage capabilities with the hierarchical namespace and SQL query support of ADLS Gen2, or they mistakenly choose Azure SQL Database for its SQL familiarity without recognizing it requires a predefined schema.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage lacks a hierarchical namespace and native SQL querying capabilities; it requires additional services like Azure Data Lake Analytics for SQL queries. Option B is wrong because Azure SQL Database is a relational database requiring a fixed schema (schema-on-write), not schema-on-read, and is not designed for unstructured or semi-structured data at scale. Option D is wrong because Azure Cosmos DB is a NoSQL database optimized for low-latency, globally distributed workloads with schema-on-read via SQL API, but it is not a data lake solution and does not natively support unstructured data like large files or binary objects.

104
Multi-Selecthard

Which THREE considerations are important when designing a storage solution for Azure Virtual Desktop (AVD) user profiles using FSLogix? (Choose three.)

Select 3 answers
A.Use Azure Files as the storage solution.
B.Use a public endpoint for profile storage.
C.Provision sufficient IOPS for user profiles.
D.Enable geo-redundant storage (GRS) for disaster recovery.
E.Ensure low latency between session hosts and storage.
AnswersA, C, E

Azure Files is the correct storage solution for Azure Virtual Desktop (AVD) because it provides fully managed SMB 3.0 file shares, which are a prerequisite for FSLogix profile containers. FSLogix loads user profiles as VHDX files mounted over SMB, and Azure Files natively supports this with identity-based authentication via Active Directory Domain Services or Microsoft Entra ID. This integration allows you to keep profiles in a secure, cloud-native share that scales with your session host environment.

Why this answer

Azure Files is the recommended storage solution for FSLogix profile containers in AVD because it supports SMB protocol, which FSLogix requires for proper locking and concurrent access. It also integrates natively with Azure Active Directory for identity-based access control, eliminating the need for domain-joined storage. This ensures seamless user profile roaming across session hosts with minimal latency when deployed in the same region.

Exam trap

The trap here is that candidates often confuse geo-redundant storage (GRS) as a necessary disaster recovery feature for user profiles, but FSLogix containers are stateless or backed up via alternative methods, and GRS introduces consistency risks that are incompatible with the real-time locking requirements of FSLogix.

105
MCQmedium

You need to design a storage solution for a global e-commerce application that requires low-latency access to product catalog data across multiple Azure regions. The data is read-heavy and updates are rare. Which service should you use for the primary data store?

A.Azure SQL Database with active geo-replication
B.Azure Table Storage
C.Azure Redis Cache
D.Azure Cosmos DB
AnswerD

Azure Cosmos DB is the correct choice because it provides turnkey global distribution with the ability to add any number of read and write regions around the world, and it offers multiple well-defined consistency levels that let you balance strong consistency and low latency per request. Each region is fully manageable, writes are accepted anywhere and conflict resolution can be configured to handle concurrent updates, giving single-digit millisecond latencies while maintaining high availability through automatic failover. This makes it a natural fit for a global e-commerce platform that needs fast, reliable access from anywhere.

Why this answer

Azure Cosmos DB is the correct choice because it provides globally distributed, multi-region writes and reads with turnkey data replication and guaranteed single-digit-millisecond latency at the 99th percentile. Its multi-homing API and automatic failover capabilities make it ideal for a read-heavy, rarely updated global e-commerce catalog that requires low-latency access across multiple Azure regions.

Exam trap

The trap here is that candidates often confuse a caching layer (Redis) with a globally distributed primary store, or assume that a relational database with geo-replication (Azure SQL) is suitable for any multi-region scenario, ignoring the specific read-heavy, rare-update pattern that Cosmos DB is optimized for.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database with active geo-replication is designed for transactional workloads with frequent writes and strong consistency, not for a read-heavy, rarely updated catalog; its geo-replication adds latency and cost overhead for read-only scenarios. Option B is wrong because Azure Table Storage is a NoSQL key-value store that lacks native global distribution and multi-region replication, resulting in higher latency for cross-region reads and no built-in low-latency guarantees. Option C is wrong because Azure Redis Cache is an in-memory cache, not a durable primary data store; it is used to accelerate reads from a backing database, not to serve as the authoritative source of truth for product catalog data.

106
MCQmedium

A company is migrating a large on-premises SQL Server database to Azure SQL Managed Instance. They need to minimize downtime during migration. The database is 500 GB and the network link is 1 Gbps. Which migration approach should they recommend?

A.Use Azure Database Migration Service with online migration
B.Perform offline backup and restore
C.Use transactional replication
D.Export BACPAC and import
AnswerA

Azure Database Migration Service online mode performs an initial full copy of your schema and data, then continuously replays changes from the source SQL Server transaction log to keep the target Azure SQL database synchronized. This allows you to run the source in production while the subscription catches up, and you can manually cut over with a controlled stop of writes, limiting downtime to minutes. It is specifically designed for large databases like 500 GB because it avoids a single, protracted offline export and uses a scalable staging area in Azure Blob Storage.

Why this answer

Azure Database Migration Service (DMS) with online migration mode uses continuous change data capture (CDC) to synchronize ongoing changes from the on-premises SQL Server to Azure SQL Managed Instance, minimizing downtime to a brief cutover window. This approach is ideal for a 500 GB database over a 1 Gbps link, as it avoids the lengthy full data transfer required by offline methods.

Exam trap

The trap here is that candidates often assume offline backup and restore is the simplest and fastest method, but they overlook the 'minimize downtime' requirement, which makes online migration via DMS the only correct choice despite its added complexity.

How to eliminate wrong answers

Option B is wrong because offline backup and restore requires taking the source database offline for the entire duration of the backup transfer and restore, which for a 500 GB database over 1 Gbps would cause significant downtime (hours), failing the minimize-downtime requirement. Option C is wrong because transactional replication requires manual setup of publishers, distributors, and subscribers, and while it can reduce downtime, it is more complex to configure and manage for a full database migration compared to DMS, and it does not natively handle schema changes or large-scale migrations as efficiently. Option D is wrong because exporting a BACPAC file involves a full database export and import, which locks tables during export and requires the database to be mostly offline, resulting in substantial downtime for a 500 GB database over 1 Gbps.

107
MCQeasy

You need to design a storage solution for a large-scale media streaming application. The application serves video files to users worldwide. The solution must minimize latency for end-users and optimize content delivery costs. Which Azure service combination should you use?

A.Azure Cosmos DB with multi-region writes
B.Azure NetApp Files with Azure Front Door
C.Azure Blob Storage with Azure Content Delivery Network (CDN)
D.Azure Files with Azure File Sync
AnswerC

Azure Blob Storage is object storage designed for petabytes of unstructured data, making it ideal for hosting video files, with support for HTTP range requests, lifecycle tiering, and secure streaming via SAS or anonymous read-only containers. Azure Content Delivery Network (CDN) caches video content at point-of-presence (PoP) edge locations, so users receive low-latency playback and at the same time egress from the origin blob storage is reduced, lowering network transfer costs. Together they deliver scale-to-zero bandwidth, high availability, and cost-efficient global media distribution. This is the only option that matches both storage semantics and content acceleration needs.

Why this answer

Azure Blob Storage is optimized for storing large, unstructured data like video files, and when paired with Azure Content Delivery Network (CDN), it caches content at edge nodes worldwide. This combination minimizes latency for global users by serving videos from the nearest point of presence (PoP) and reduces egress costs by offloading traffic from the origin storage to the CDN's distributed network.

Exam trap

The trap here is that candidates confuse Azure Front Door (a global load balancer with HTTP caching) with a full CDN, but for static video content, Azure CDN (or Azure Front Door's CDN profile) is the correct service because it provides dedicated edge caching and egress cost optimization, whereas Front Door's primary role is application acceleration and routing.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL database designed for transactional workloads with multi-region writes, not for storing and serving large binary video files; it lacks the cost-effective blob storage and CDN integration needed for media streaming. Option B is wrong because Azure NetApp Files provides high-performance NFS/SMB file shares for enterprise applications, not a globally distributed content delivery mechanism; Azure Front Door is a global load balancer and application accelerator, not a caching CDN optimized for static content like video files. Option D is wrong because Azure Files with Azure File Sync is designed for hybrid file sharing and synchronization across on-premises and cloud, not for low-latency global video streaming; it lacks edge caching and does not optimize egress costs for large-scale media delivery.

108
MCQhard

A financial services company is migrating its on-premises SAP HANA database to Azure. The database requires high IOPS and low latency with a capacity of 4 TB. They need to choose a storage solution that supports SAP HANA certified configurations. Which Azure storage solution should they use?

A.Azure Premium SSD v2
B.Azure Ultra Disk Storage
C.Azure Standard HDD
D.Azure NetApp Files
AnswerB

Azure Ultra Disk Storage is the correct choice because it is certified for SAP HANA and delivers the extreme performance the service expects: IOPS, throughput, and latency can be independently provisioned and dynamically adjusted without downtime. This lets a financial services company configure a volume that matches SAP's performance benchmarks for transaction workloads, with sub-millisecond read latency and up to thousands of IOPS. Ultra Disk is the only Azure managed disk besides Premium SSD v1 that meets SAP HANA's production support requirements.

Why this answer

Azure Ultra Disk Storage is the correct choice because it is the only Azure managed disk that is SAP HANA certified for high IOPS and sub-millisecond latency, which is critical for SAP HANA workloads. It supports up to 300,000 IOPS and 2,000 MB/s throughput per disk, and can be provisioned with up to 64 TB capacity, easily covering the 4 TB requirement. Premium SSD v2 is not SAP HANA certified for production databases, and Azure NetApp Files, while offering high performance, is not a managed disk and requires specific NFS configurations that may not meet SAP HANA's strict certification requirements for block storage.

Exam trap

The trap here is that candidates often assume Premium SSD v2 is the best choice for all high-performance workloads, but SAP HANA has specific certification requirements that exclude Premium SSD v2 for production databases, making Ultra Disk the only correct option among the managed disks listed.

How to eliminate wrong answers

Option A is wrong because Azure Premium SSD v2, despite offering high IOPS and low latency, is not certified by SAP for SAP HANA production workloads; SAP HANA requires specific disk types like Ultra Disk or Premium SSD (v1) for certified configurations. Option C is wrong because Azure Standard HDD provides low IOPS and high latency, which cannot meet the performance demands of SAP HANA databases requiring high IOPS and low latency. Option D is wrong because Azure NetApp Files is a file-based NFS storage solution, not a block storage managed disk, and while it can be used with SAP HANA, it requires additional configuration and is not the direct Azure managed disk solution that is SAP HANA certified for high IOPS and low latency block storage.

109
MCQhard

Contoso Ltd. is a global retail company with headquarters in New York and operations in Europe and Asia. They are migrating their on-premises SQL Server databases to Azure. The databases include a customer database (500 GB), an orders database (2 TB), and a product catalog database (100 GB). The customer database requires high read throughput with sub-10 ms latency for global users. The orders database must support complex queries and reporting with point-in-time restore capability up to 35 days. The product catalog is updated infrequently but must be available for read-heavy workloads with strong consistency. Contoso wants to minimize costs while meeting performance and compliance requirements. They also need to support hybrid deployments for databases that must remain on-premises due to data sovereignty laws. You need to design a data storage solution. Which combination of Azure services and configurations should you recommend?

A.Azure SQL Managed Instance for all databases with geo-replication for customer DB; use failover groups for global distribution; Azure Data Sync for hybrid
B.Azure SQL Database Hyperscale for all databases; use geo-replication for customer DB; Azure SQL Server on Azure VMs for hybrid
C.Azure Cosmos DB with multiple write regions for customer DB; Azure SQL Database Business Critical for orders; Azure SQL Database serverless for product catalog; Azure SQL Managed Instance with managed instance link for hybrid
D.Azure SQL Database Business Critical for customer DB with geo-replication; Azure SQL Database Hyperscale for orders; Azure SQL Database serverless for product catalog; Azure SQL Managed Instance for hybrid
AnswerC

Azure Cosmos DB with multiple write regions gives every regional endpoint the ability to accept reads and writes with single-digit millisecond latency, enabling the global customer database to meet sub-10 ms performance through multi-homing and tunable consistency. Business Critical tier for orders provides SQL Server-compatible T-SQL, ACID transactions, and low-latency local Always On availability, which is appropriate for complex order queries and strict transactional guarantees. Serverless product catalog avoids fixed compute costs for an intermittently queried reference dataset, while Managed Instance with the managed instance link provides near-real-time bidirectional replication between Azure and existing on-premises SQL Server to satisfy the hybrid footprint.

Why this answer

It matches each database's workload to the optimal Azure service: Cosmos DB with multiple write regions provides global low-latency reads and writes for the customer DB; Azure SQL Database Business Critical offers the complex query support and point-in-time restore up to 35 days for the orders DB; Azure SQL Database serverless minimizes cost for the infrequently updated product catalog; and Azure SQL Managed Instance with managed instance link enables hybrid deployment for on-premises databases subject to data sovereignty laws.

Exam trap

The trap here is that candidates often assume Azure SQL Database Hyperscale is a one-size-fits-all solution for large databases, overlooking its limitations with point-in-time restore duration and complex query performance, and fail to recognize that Cosmos DB is the only Azure service designed for global low-latency reads with multiple write regions.

How to eliminate wrong answers

Option A is wrong because Azure SQL Managed Instance does not support geo-replication or failover groups for global distribution; those features are for Azure SQL Database, not Managed Instance. Option B is wrong because Azure SQL Database Hyperscale does not support point-in-time restore up to 35 days (max is 7 days by default, extendable to 35 only with additional configuration that increases cost) and is not optimal for complex queries and reporting due to its page server architecture. Option D is wrong because Azure SQL Database Business Critical for the customer DB lacks the global low-latency read throughput that Cosmos DB provides, and Azure SQL Database Hyperscale for the orders DB does not natively support point-in-time restore up to 35 days without extra cost and complexity.

110
Multi-Selecteasy

Which TWO Azure services provide native support for change data capture (CDC) to stream database changes to other systems?

Select 2 answers
A.Azure Table Storage
B.Azure Cosmos DB
C.Azure Cache for Redis
D.Azure SQL Database
E.Azure Synapse Link for Azure Cosmos DB
AnswersB, D

Azure Cosmos DB is a correct answer because it exposes a native change feed directly from the container, implemented as an append-only, ordered per logical partition log that captures item inserts, updates, and deletes. This change feed is consumed via the Cosmos DB SDK, Azure Functions trigger, or the Change Feed Processor library, delivering at-least-once semantics and automatic paging. This is a first-class CDC facility for a multi-model NoSQL database, distinct from a SQL-based CDC implementation.

Why this answer

Azure Cosmos DB provides native change feed support, which is a persistent, ordered log of changes (inserts, updates, deletes) that can be streamed to downstream systems via the Change Feed processor or Azure Functions. This makes it a correct answer for change data capture (CDC) scenarios.

Exam trap

The trap here is that candidates may confuse Azure Synapse Link for Azure Cosmos DB (an analytical store) with a native CDC service, when in fact it relies on the underlying change feed but is not itself a CDC streaming solution.

111
MCQmedium

A company is migrating a MongoDB-compatible application to Azure. The application requires low-latency reads and writes globally. It needs to support multi-region writes so that updates can be made from any region with automatic conflict resolution. The data is JSON documents that can vary in schema. The company wants a fully managed database service with native support for MongoDB APIs. Which Azure data service should they choose?

A.Azure SQL Database
B.Azure Cosmos DB with the API for MongoDB
C.Azure Database for MongoDB
D.Azure Cache for Redis
AnswerB

Azure Cosmos DB with the API for MongoDB is a native implementation of the MongoDB wire protocol on a globally distributed, multi-model NoSQL database service. It enables existing MongoDB drivers to connect directly while gaining Cosmos DB's turnkey global distribution, multiple consistency levels, and SLA-backed performance. It supports both shared and dedicated throughput, and features like automatic indexing and conflict resolution for multi-region writes.

Why this answer

Azure Cosmos DB with the API for MongoDB is the correct choice because it provides a fully managed, globally distributed database service that natively supports the MongoDB wire protocol. It offers multi-region writes with automatic conflict resolution using last-writer-wins (LWW) or custom conflict resolution policies, ensuring low-latency reads and writes globally. Its schema-agnostic nature handles JSON documents with varying schemas, meeting all stated requirements.

Exam trap

The trap here is that candidates may confuse 'Azure Database for MongoDB' (which does not exist) with Azure Cosmos DB's API for MongoDB, or incorrectly assume that a relational database like Azure SQL Database can handle schema-flexible JSON documents with global multi-region writes.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database is a relational database that does not support MongoDB APIs, JSON document storage with varying schemas, or multi-region writes with automatic conflict resolution. Option C is wrong because Azure Database for MongoDB does not exist as a native Azure service; the correct service is Azure Cosmos DB with the API for MongoDB, and this option represents a common misconception of a separate service. Option D is wrong because Azure Cache for Redis is an in-memory caching service, not a fully managed database for persistent JSON document storage, and it does not support MongoDB APIs or multi-region writes.

112
MCQeasy

A company is deploying a containerized microservices application on Azure Kubernetes Service (AKS). The application requires persistent storage that can be attached to pods and supports dynamic provisioning. Which Azure storage solution should they use?

A.Azure Blob Storage
B.Azure Files
C.Azure NetApp Files
D.Azure Disks
AnswerD

Azure Disks are managed block-storage volumes that integrate natively with AKS through the built-in managed-csi StorageClass, allowing persistent volume claims to be dynamically created and attached. They provide consistent, low-latency performance with configurable SKUs, which is exactly what a containerized microservices application needs for stateful workloads. Since each pod can have its own disk and the CSI driver automates provisioning, Azure Disks is the correct and most common choice for AKS persistent volumes.

Why this answer

Azure Disks is the correct choice because it provides block-level storage volumes that can be dynamically provisioned via the AKS built-in StorageClass, supporting ReadWriteOnce access mode required for a single pod in a containerized microservices application. Azure Disks integrate directly with Kubernetes PersistentVolumeClaims (PVCs) for dynamic provisioning, offering low-latency, high-performance storage suitable for stateful workloads.

Exam trap

The trap here is that candidates often confuse Azure Files (shared file storage) with Azure Disks (block storage), assuming that 'persistent storage' always means file shares, but for single-pod dynamic provisioning in AKS, Azure Disks are the native and optimal choice.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage is object storage accessed via HTTP/HTTPS, not block storage, and does not support direct attachment to pods via Kubernetes PV/PVC without a CSI driver or sidecar, making it unsuitable for dynamic provisioning in AKS. Option B is wrong because Azure Files provides SMB/NFS file shares that support ReadWriteMany access, but for a single-pod persistent storage scenario, Azure Disks offer lower latency and are more cost-effective; Azure Files is typically used for shared access across multiple pods, not single-pod dynamic provisioning. Option C is wrong because Azure NetApp Files is a premium enterprise-grade file service with high cost and complexity, overkill for standard AKS persistent storage, and requires additional configuration for dynamic provisioning compared to the native Azure Disks integration.

113
MCQeasy

Your company needs to store configuration data (key-value pairs) for applications in a highly scalable and low-latency manner. The data is accessed frequently. Which Azure service should you choose?

A.Azure Cosmos DB.
B.Azure Cache for Redis.
C.Azure SQL Database.
D.Azure Table Storage.
AnswerB

Azure Cache for Redis is a managed in-memory data store that delivers sub-millisecond read latency and native support for key-value pairs, making it ideal for frequently accessed configuration data. Unlike disk-backed services, it holds the working set entirely in RAM, and its automatic scaling and built-in data expiration policies simplify lifecycle management. For simple get/set lookups, this purpose-built caching tier minimizes both latency and operational overhead compared to general-purpose databases.

Why this answer

Azure Cache for Redis is the correct choice because it provides an in-memory data store that delivers extremely low-latency access (typically sub-millisecond) and high throughput for frequently accessed key-value configuration data. It supports common data structures like strings, hashes, and lists, and can be used as a distributed cache or session store, making it ideal for high-frequency read workloads where persistence is not the primary concern.

Exam trap

The trap here is that candidates often confuse Azure Cache for Redis with Azure Cosmos DB or Azure Table Storage, assuming any key-value store is equivalent, but the exam emphasizes the specific requirement for 'highly scalable and low-latency' access, which only an in-memory cache like Redis can deliver for frequently read configuration data.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a globally distributed, multi-model NoSQL database designed for complex queries, indexing, and transactional consistency, which introduces higher latency and overhead compared to an in-memory cache for simple key-value lookups. Option C is wrong because Azure SQL Database is a relational database with full ACID compliance and disk-based storage, resulting in higher read latency and cost for simple key-value access patterns that do not require relational features. Option D is wrong because Azure Table Storage is a NoSQL key-value store but operates on disk-based storage with higher latency (typically 10-50 ms) and lacks the sub-millisecond performance and advanced caching features (like TTL, eviction policies) that Azure Cache for Redis provides.

114
MCQhard

Your company plans to store sensitive customer data in Azure Blob Storage. The data must be encrypted at rest and in transit. Additionally, access must be audited and restricted based on user identity. Which configuration meets these requirements?

A.Use shared access signatures (SAS) for access control.
B.Use Azure RBAC for access and Azure Monitor logs for auditing.
C.Configure network firewalls and use private endpoints.
D.Enable customer-managed keys (CMK) and use SAS.
AnswerB

Azure RBAC, integrated with Microsoft Entra ID, precisely restricts access to Blob Storage based on user identity by assigning specific roles with defined permissions, directly addressing the requirement for identity-based access control. Concurrently, Azure Monitor logs provide comprehensive auditing by capturing detailed records of all management and data plane operations performed on the storage account, ensuring that access is fully auditable as stipulated.

Why this answer

Azure RBAC provides identity-based access control using Azure Active Directory, which meets the requirement to restrict access based on user identity. Azure Monitor logs (specifically the Azure Activity Log and Storage Analytics logs) capture all read/write operations for auditing. Encryption at rest is automatically provided by Azure Storage Service Encryption (SSE) using Microsoft-managed keys by default, and encryption in transit is enforced via HTTPS when accessing Blob Storage.

Together, these satisfy all stated requirements without additional configuration.

Exam trap

The trap here is that candidates often confuse SAS tokens with identity-based access control, thinking that a signed URI provides user-level restriction, when in fact SAS only delegates permissions to anyone holding the token, not to a specific user identity.

How to eliminate wrong answers

Option A is wrong because shared access signatures (SAS) provide time-limited, delegated access based on a token, not on user identity; SAS tokens do not support Azure AD-based authentication or RBAC, and auditing is limited to the SAS token itself, not the user. Option C is wrong because network firewalls and private endpoints control network-level access and eliminate public internet exposure, but they do not provide identity-based access control or auditing of user actions; they also do not inherently enforce encryption in transit beyond the network boundary. Option D is wrong because customer-managed keys (CMK) only control encryption at rest (via Azure Key Vault) and do not provide access control or auditing based on user identity; SAS tokens again lack identity-based restriction and auditing granularity.

115
MCQmedium

A company deploys a web application on Azure VMs. The application stores session state and frequently accessed product data. They need a low-latency, in-memory cache to reduce database load and improve response times. The cache must be managed and support data persistence with replication across availability zones within the region. Which Azure service and tier should they choose?

A.Azure Cache for Redis (Premium tier)
B.Azure Cache for Redis (Basic tier)
C.Azure Cache for Redis (Standard tier)
D.Azure Cache for Redis (Enterprise tier)
AnswerA

Azure Cache for Redis Premium tier is the appropriate choice because it uniquely combines zone-redundant replication—spreading the primary and replica nodes across Azure availability zones—with built-in data persistence options (RDB snapshots and AOF append-only file). This gives you both high availability and durability of cached data, enabling you to survive an entire zone failure without losing data. Being fully managed, it also supports Redis clustering for scaling out beyond the memory limit of a single node, which is why it meets the production requirements.

Why this answer

Azure Cache for Redis Premium tier is the correct choice because it supports data persistence (RDB/AOF), replication across availability zones via zone redundancy, and provides low-latency, in-memory caching for session state and product data. The Basic tier lacks replication and persistence, Standard tier offers replication but not zone redundancy or persistence, and Enterprise tier is overkill for this scenario, adding unnecessary cost and complexity.

Exam trap

The trap here is that candidates often confuse the Standard tier's replication (which is within a single datacenter) with zone redundancy, or assume Enterprise tier is always better for persistence, when Premium tier specifically offers both persistence and zone redundancy at a lower cost.

How to eliminate wrong answers

Option B (Basic tier) is wrong because it provides no replication, no data persistence, and no SLA, making it unsuitable for high-availability or durable caching needs. Option C (Standard tier) is wrong because while it offers replication within a single datacenter, it does not support zone redundancy across availability zones or built-in data persistence (RDB/AOF). Option D (Enterprise tier) is wrong because it is designed for advanced scenarios like active geo-replication and Redis modules (RediSearch, RedisBloom), which are not required here, and it incurs higher cost without providing additional benefit for basic session state and product caching.

116
MCQeasy

A company needs to store and analyze petabytes of IoT telemetry data. The data is append-only and rarely updated. They require SQL-based querying and columnar storage for fast analytics. Which Azure storage solution should you choose?

A.Azure Cosmos DB with analytical store
B.Azure SQL Database with columnstore indexes
C.Azure Blob Storage with Azure Cognitive Search
D.Azure Data Lake Storage Gen2 with Azure Synapse SQL pool
AnswerD

Azure Data Lake Storage Gen2 is the correct storage foundation because it blends the object storage scalability of Blob Storage with a hierarchical namespace, POSIX permissions, and built-in support for storing data in open formats like Parquet—making it ideal for petabyte- and exabyte-scale IoT telemetry ingestion. Azure Synapse SQL pool (dedicated or serverless) provides a distributed, massively parallel processing (MPP) engine that executes T-SQL directly over the files in ADLS Gen2, enabling schema-on-read analytics without moving and re-loading data. This architecture natively handles append-only telemetry streams, accelerates queries via partition elimination and columnar storage, and separates storage from compute to independently scale ingestion throughput and query concurrency.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) provides hierarchical namespace and petabyte-scale storage optimized for big data analytics. When combined with Azure Synapse SQL pool (formerly SQL DW), it enables SQL-based querying over columnar storage (using PolyBase or CETAS) for fast analytics on append-only IoT telemetry data. This combination supports massive data volumes, append-only workloads, and columnar storage for high-performance analytical queries.

Exam trap

The trap here is that candidates often choose Azure SQL Database with columnstore indexes (Option B) because they focus on the 'SQL-based querying and columnar storage' requirement without considering the petabyte-scale constraint, which exceeds Azure SQL Database's maximum storage capacity.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB with analytical store is designed for globally distributed, multi-model NoSQL data with automatic indexing, not for petabyte-scale append-only IoT telemetry requiring SQL-based columnar analytics; its analytical store uses Azure Synapse Link but is optimized for operational data, not bulk append-only streams. Option B is wrong because Azure SQL Database with columnstore indexes is a relational OLTP database with a maximum size of 4 TB (or 128 TB with Hyperscale), which cannot handle petabytes of data, and columnstore indexes are best for read-mostly workloads but the service lacks the distributed scale-out architecture needed for petabyte-scale analytics. Option C is wrong because Azure Blob Storage with Azure Cognitive Search provides object storage and full-text search capabilities, not SQL-based querying or columnar storage; Cognitive Search is for indexing and searching unstructured text, not for analytical queries on structured IoT data.

117
MCQhard

A company runs a large-scale write-intensive application that requires a horizontally scalable relational database. They need to distribute data across multiple nodes to handle high write throughput while supporting SQL queries, including joins and transactions. The solution must be fully managed and provide elastic scaling. Which Azure database service should they choose?

A.Azure SQL Database Hyperscale
B.Azure Cosmos DB
C.Azure Database for PostgreSQL Hyperscale (Citus)
D.Azure SQL Managed Instance
AnswerC

Azure Database for PostgreSQL Hyperscale (Citus) is a managed relational database that horizontally shards tables across worker nodes by choosing a distribution column. Writes are distributed to multiple workers in parallel, so write throughput can scale out as worker nodes are added. It preserves full PostgreSQL SQL semantics, including distributed joins, foreign keys, and ACID transactions, making it the only option that combines relational integrity with horizontal write scaling.

Why this answer

Azure Database for PostgreSQL Hyperscale (Citus) is the correct choice because it provides horizontal scaling (sharding) across multiple worker nodes using the Citus extension, which distributes data and parallelizes SQL queries. It supports full SQL, including joins and transactions, while offering elastic scaling for write-intensive workloads. This makes it ideal for large-scale relational databases that need high write throughput and horizontal scalability.

Exam trap

The trap here is that candidates often confuse 'horizontal scaling' with 'hyperscale' or 'managed instance' options, assuming any 'scalable' database service supports distributed writes, but only Citus provides true horizontal sharding for relational workloads with full SQL and transaction support.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database Hyperscale is designed for read-intensive workloads with fast scaling of compute and storage, but it does not distribute data across multiple nodes for horizontal write scaling; it uses a single primary node with page servers for storage. Option B is wrong because Azure Cosmos DB is a NoSQL database that does not support full relational SQL features like joins and transactions across multiple documents in the same way a relational database does; it is schema-agnostic and not a relational database. Option D is wrong because Azure SQL Managed Instance is a fully managed instance of SQL Server that provides vertical scaling but not horizontal scaling across multiple nodes; it is limited to a single instance and does not distribute data across nodes for high write throughput.

118
Multi-Selecthard

Which THREE considerations are important when designing a data storage solution for a high-throughput IoT ingestion pipeline in Azure?

Select 3 answers
A.Network latency between devices and Azure
B.Ingestion throughput limits of the storage service
C.Data retention and archival policies
D.Partitioning strategy to distribute load
E.Data consistency levels required by downstream consumers
AnswersB, C, D

Every Azure storage service, such as Blob Storage or Data Lake Storage Gen2, publishes specific scalability targets for ingress requests per second and bandwidth. Although Azure can consume high volumes, a streaming data lake intake must be verified against peak event rates; otherwise, the service throttles writes, causing backlog and data loss if IoT devices have limited buffering. Choosing partition layouts, multiple storage accounts, or premium capacity is directly tied to these limits.

Why this answer

Azure Storage services like Blob Storage and Event Hubs have defined ingestion throughput limits (e.g., up to 20 MB/s per partition or 1 MB/s per ingress for standard-tier Event Hubs). Exceeding these limits causes throttling (HTTP 429 errors) and data loss, making throughput capacity a critical design consideration for high-throughput IoT pipelines.

Exam trap

The trap here is confusing network-level considerations (latency, bandwidth) with storage-level design constraints (throughput limits, partitioning), leading candidates to select Option A instead of focusing on the storage service's inherent ingestion capacity.

119
MCQhard

Refer to the exhibit. You need to enable public access to the storage account for a specific IP address while keeping the default action as Deny. What should you do?

A.Set the bypass to None to allow all traffic.
B.Set the networkAcls to an empty list to remove restrictions.
C.Add an IP rule with the specific IP address to the ipRules array.
D.Change the defaultAction to Allow and remove the Deny rule.
AnswerC

With defaultAction set to Deny, only traffic explicitly matched by an IP rule in the ipRules array is allowed. Adding a rule with the specific public IP address (or CIDR range) and action Allow creates a narrow exception for that source, while all other public traffic continues to be denied. This is the standard way to enable public access for a particular client while maintaining a secure, deny-by-default posture; the rule permits only the specified IP and does not alter the default behavior.

Why this answer

The Azure Storage account firewall allows you to create IP rules that grant access to specific public IP addresses or ranges while keeping the default action as Deny. By adding an IP rule with the specific IP address to the `ipRules` array, you explicitly allow that IP through the firewall, and all other traffic is denied by the default rule. This is the standard method to enable selective public access without changing the default deny behavior.

Exam trap

The trap here is that candidates often think they must change the default action to Allow and then add a Deny rule, but Azure Storage firewall does not support explicit Deny rules for IP addresses—only Allow rules—so the correct approach is to keep the default as Deny and add an Allow rule for the specific IP.

How to eliminate wrong answers

Option A is wrong because setting the bypass to 'None' would not allow all traffic; it would actually prevent any Azure services from bypassing the firewall, but it does not affect IP-based access rules and would still require explicit IP rules to allow traffic. Option B is wrong because setting the `networkAcls` to an empty list would remove all network ACL rules, including any IP rules, leaving only the default action (Deny) in effect, which would block all traffic including the specific IP address. Option D is wrong because changing the `defaultAction` to Allow would permit all public traffic, which violates the requirement to keep the default action as Deny and only allow the specific IP address.

120
MCQeasy

You need to design a storage solution for a website that hosts static content (HTML, CSS, JavaScript) and requires low-cost, scalable storage with integrated CDN delivery. Which Azure service should you use?

A.Azure Files with SMB protocol
B.Azure Content Delivery Network only
C.Azure Blob Storage with static website hosting and Azure CDN
D.Azure App Service
AnswerC

Blob Storage with static website hosting natively serves HTML, CSS, JavaScript, and images over HTTPS from a public endpoint, with configurable index and error documents. Adding Azure CDN in front provides global edge caching, custom domain support, automated TLS, and DDoS mitigation. This combination is cost-effective for static assets because storage and bandwidth scale elastically while requiring no virtual machines or always-on application runtime.

Why this answer

Azure Blob Storage with static website hosting provides a cost-effective, scalable storage solution for static content (HTML, CSS, JavaScript). By enabling Azure CDN on top of the storage account, you achieve low-latency global content delivery and offload traffic from the origin, reducing costs and improving performance for end users.

Exam trap

The trap here is that candidates often confuse Azure Files (a managed file share) with Blob Storage (object storage) for static web hosting, or mistakenly think Azure CDN alone can store content without an origin service.

How to eliminate wrong answers

Option A is wrong because Azure Files with SMB protocol is designed for file shares that require SMB access (e.g., lift-and-shift apps, legacy file servers), not for serving static web content with CDN integration. Option B is wrong because Azure Content Delivery Network alone is a delivery service, not a storage service; it requires an origin (like Blob Storage) to cache and serve content. Option D is wrong because Azure App Service is a PaaS compute service for hosting web applications, not a dedicated static content storage solution, and it incurs higher costs and unnecessary overhead for purely static content.

121
MCQmedium

A company stores large amounts of log data in Azure Blob Storage. Logs are accessed frequently for the first 30 days, then rarely accessed afterward, but must be retained for 7 years for compliance. The company wants to minimize storage costs. They need to configure automatic data movement and retention policies. Which combination of Azure Blob Storage access tiers and lifecycle management policy should they use?

A.Use Hot tier for 30 days, then use Cool tier for 7 years, with a lifecycle rule to delete after 7 years.
B.Use Hot tier for 30 days, then use Archive tier for the remaining period, with a lifecycle rule to delete after 7 years.
C.Use Cool tier for 30 days, then use Archive tier for 7 years, no lifecycle rule needed.
D.Use Archive tier immediately, with a lifecycle rule to delete after 7 years.
AnswerB

Hot tier provides low-latency access during the frequent access period. Archive tier provides the lowest storage cost for data that is rarely accessed. A lifecycle policy can automatically move data from Hot to Archive after 30 days and delete it after 7 years.

Why this answer

It uses the Hot tier for the first 30 days to handle frequent access, then automatically moves data to the Archive tier via a lifecycle management rule to minimize costs for rarely accessed data, and finally deletes the blobs after 7 years to meet compliance retention requirements. The Archive tier offers the lowest storage cost for long-term retention, making it ideal for logs that are rarely accessed after the initial period.

Exam trap

The trap here is that candidates often choose the Cool tier for long-term retention because they underestimate the cost savings of the Archive tier for data that is rarely accessed over many years, or they forget that a lifecycle rule is necessary to enforce deletion after the compliance period.

How to eliminate wrong answers

Option A is wrong because moving data to the Cool tier after 30 days does not minimize storage costs as effectively as the Archive tier for 7 years of rare access; the Cool tier has higher storage costs than Archive and is intended for data accessed less frequently but still with some latency requirements, not for long-term archival. Option C is wrong because starting with the Cool tier for the first 30 days is suboptimal since logs are accessed frequently during that period, and the Hot tier is more cost-effective for frequent access; additionally, a lifecycle rule is required to delete data after 7 years to enforce compliance retention. Option D is wrong because placing data directly into the Archive tier from the start incurs high retrieval costs and latency for the first 30 days when logs are accessed frequently, violating the requirement to minimize costs and access performance.

122
MCQhard

Refer to the exhibit. A company is analyzing Azure Storage diagnostic logs using this KQL query. They notice a high number of GetBlob operations on BlockBlobs. The storage account is used for a web application that serves static content. What should they recommend to reduce the number of GetBlob operations?

A.Implement Azure Blob Storage life cycle management to move data to the archive tier.
B.Use Azure File Sync to cache files on-premises.
C.Enable Azure CDN or Azure Front Door to cache content.
D.Enable Azure Storage Analytics logging to track operations.
AnswerC

Placing Azure CDN or Azure Front Door in front of the blob storage account caches frequently requested content at edge locations, so clients are served cached copies without contacting the storage account. This reduces the number of direct read operations against the blob endpoint, lowering transaction costs and improving response latency. Cache headers, such as Cache-Control, determine the duration and effectiveness of the cache, making this a practical solution for repeated content access.

Why this answer

Enabling Azure CDN or Azure Front Door caches static content at edge locations, reducing the number of direct GetBlob operations against the storage account. This offloads repeated requests from the origin storage, lowering both operational costs and latency for the web application.

Exam trap

The trap here is that candidates may confuse logging (Option D) or lifecycle management (Option A) as solutions to reduce operations, when they only provide monitoring or cost optimization for infrequently accessed data, not a reduction in read requests.

How to eliminate wrong answers

Option A is wrong because lifecycle management moves data to the archive tier, which is designed for cold data and incurs high retrieval costs and latency—it does not reduce GetBlob operations for frequently accessed static content. Option B is wrong because Azure File Sync caches files on-premises for hybrid scenarios, but the question involves a web application serving static content from Azure Storage, not on-premises file sharing; it does not reduce GetBlob operations in Azure. Option D is wrong because enabling Storage Analytics logging tracks operations but does not reduce them; it only provides visibility into existing traffic.

123
MCQmedium

A company uses Azure SQL Database (Premium tier) for their application. They need to offload reporting queries to a read-only copy of the database to reduce load on the primary. The read-only copy must be kept in sync synchronously within the same Azure region. They also need automated failover to the read-only copy if the primary fails. Which Azure SQL Database feature should they enable?

A.Active geo-replication
B.Auto-failover groups
C.Read Scale-Out
D.Database copy
AnswerC

Read Scale-Out uses the built-in, always-on secondary replica that is automatically maintained in the same region for Premium and Business Critical service tiers. The replica is kept synchronously updated with the primary, meaning reporting queries can be routed to the read-only endpoint with minimal lag. This feature also supports automatic failover, so the read-only replica can become the new primary if the current primary fails, making it a proper solution for in-region read offload.

Why this answer

Read Scale-Out is the correct feature because it offloads reporting queries to a read-only replica that stays synchronously committed within the same Azure region. It also provides automated failover to the read-only replica if the primary database fails, meeting both the synchronous sync and failover requirements for Premium-tier Azure SQL Database.

Exam trap

The trap here is that candidates confuse cross-region disaster recovery features (Active geo-replication and Auto-failover groups) with in-region high availability and read-scale capabilities, overlooking that Read Scale-Out is the only option that provides synchronous replication and automated failover within the same Azure region.

How to eliminate wrong answers

Option A is wrong because Active geo-replication creates asynchronous replicas in different Azure regions, not synchronous replicas within the same region, and it does not support automated failover. Option B is wrong because Auto-failover groups rely on Active geo-replication and are designed for cross-region failover with asynchronous replication, not for synchronous in-region read-only offloading. Option D is wrong because Database copy creates a point-in-time snapshot that is not kept in sync synchronously and does not provide automated failover.

124
MCQmedium

A company runs a SQL Server database on an Azure virtual machine. They need to increase the storage capacity and improve I/O performance for their transaction log. The current data disk is a standard HDD. They want to achieve higher IOPS and throughput without increasing the size of the VM (the VM size supports up to 8 data disks). The database workload is write-intensive on the transaction log. Which configuration should they implement?

A.Add additional standard HDD disks and configure a storage pool with simple (striping) layout
B.Replace the standard HDD disk with a premium SSD disk for the log drive
C.Add a premium SSD disk and configure a storage space with mirroring for the log drive
D.Use Azure Disk Encryption to improve performance
AnswerB

Replacing the Standard HDD with a Premium SSD for the log drive directly addresses the bottleneck because SQL Server transaction log writes are serial and must be durable before a transaction is acknowledged; even modest write latency directly lengthens commit times. Azure Premium SSDs deliver per-disk IOPS and throughput up to an order of magnitude higher than Standard HDDs, with consistent single-digit-millisecond latencies (and sub-millisecond with burst). This change also guarantees predictable performance levels via the Azure disk SLA, allowing the log I/O path to keep pace with checkpoint and commit activity without introducing any additional software layers. It is the most appropriate, focused action for a write-intensive log workload on an Azure VM.

Why this answer

Replacing the standard HDD with a premium SSD directly addresses the need for higher IOPS and throughput for a write-intensive transaction log. Premium SSDs provide consistent low-latency performance and significantly higher IOPS/throughput compared to standard HDDs, without requiring a VM size change. Since the VM supports up to 8 data disks, a single premium SSD can meet the performance requirements more effectively than adding more HDDs.

Exam trap

The trap here is that candidates may think striping (Option A) or mirroring (Option C) with premium disks is needed for performance, but for a single transaction log file, a single premium SSD is sufficient and simpler, while mirroring adds unnecessary write overhead and striping with HDDs still yields poor IOPS.

How to eliminate wrong answers

Option A is wrong because adding more standard HDD disks and striping them in a storage pool still uses slow HDDs, which cannot deliver the required IOPS and throughput for a write-intensive transaction log; striping improves throughput but not latency or IOPS per disk. Option C is wrong because adding a premium SSD with mirroring (instead of using it as a single log drive) introduces unnecessary redundancy that does not improve write performance for a transaction log, and mirroring reduces usable capacity and can add write overhead. Option D is wrong because Azure Disk Encryption only provides encryption at rest and does not affect I/O performance; it can even introduce a slight CPU overhead for encryption/decryption operations.

125
MCQmedium

A company stores JSON documents for a mobile app backend. The data needs to be accessible from multiple global regions with low latency writes from any region. The app uses a client-side library that supports automatic conflict resolution for concurrent updates. Which Azure data service should they choose?

A.Azure Cosmos DB
B.Azure SQL Database
C.Azure Database for PostgreSQL
D.Azure Table Storage
AnswerA

Azure Cosmos DB is the correct choice because it provides native multi-region writes, enabling the same JSON document to be written and updated from any Azure region with automatic conflict resolution to handle concurrent edits. Its flexible schema and JSON-native indexing make it purpose-built for storing and querying mobile app backend documents, and it offers well-defined consistency levels and an SLA for availability and latency.

Why this answer

Azure Cosmos DB is correct because it provides multi-region writes with automatic conflict resolution, which directly matches the requirement for low-latency writes from any global region. Its multi-master replication model allows any region to accept writes, and the client-side library can use last-writer-wins (LWW) or custom conflict resolution policies to handle concurrent updates seamlessly.

Exam trap

The trap here is that candidates often confuse Azure SQL Database or Azure Database for PostgreSQL's read replicas with write capability, failing to recognize that only Cosmos DB offers true multi-region writes with built-in conflict resolution.

How to eliminate wrong answers

Option B (Azure SQL Database) is wrong because it does not natively support multi-region writes; it relies on a single primary region for writes, and geo-replication is read-only, so it cannot achieve low-latency writes from multiple regions. Option C (Azure Database for PostgreSQL) is wrong because it also uses a single-writer primary architecture; while read replicas can be distributed, writes must go to the primary region, introducing latency for global writes. Option D (Azure Table Storage) is wrong because it does not support multi-region writes; it offers only a single write region with read-only geo-redundant storage, and it lacks built-in conflict resolution for concurrent updates.

126
MCQmedium

A company needs to store sensor data from IoT devices. Each device sends a message every second. The data is time-series and will be queried for real-time dashboards and historical analysis. The solution must support high ingestion rates and low-latency queries on recent data. Which Azure service should they use?

A.Azure Blob Storage with Azure Data Lake Storage Gen2
B.Azure Cosmos DB with SQL API
C.Azure Event Hubs and Azure Data Explorer
D.Azure Table Storage
AnswerC

Azure Event Hubs and Azure Data Explorer form the native Azure pattern for IoT sensor data because Event Hubs offers high-throughput, low-latency event streaming with partitioning and auto-inflate, easily handling millions of sensor messages per second. Azure Data Explorer (ADX) is a purpose-built analytics engine for time-series and log data, using columnar storage and an optimized ingestion pipeline that can directly consume streams from Event Hubs. ADX's KQL query language delivers real-time aggregations over large temporal windows in sub-second latency, making it ideal for live dashboards. This combination decouples ingestion from analytics while providing end-to-end scalability and low operational overhead.

Why this answer

Azure Event Hubs is designed for high-throughput data ingestion from millions of IoT devices, capable of handling millions of events per second. Azure Data Explorer (ADX) is optimized for time-series data, providing sub-second query latency on recent data and efficient historical analysis. Together, they form a serverless pipeline that ingests sensor data via Event Hubs and stores it in ADX for real-time dashboards and long-term analytics.

Exam trap

The trap here is that candidates often choose Azure Cosmos DB (Option B) because they associate it with 'low latency' and 'IoT', but they overlook that Cosmos DB is not purpose-built for time-series data and lacks the ingestion throughput and query optimizations that Azure Data Explorer provides for this specific workload.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with Data Lake Storage Gen2 is optimized for batch analytics and large file storage, not for high-frequency time-series ingestion or low-latency queries on recent data; it lacks native time-series indexing and real-time query capabilities. Option B is wrong because Azure Cosmos DB with SQL API is a multi-model NoSQL database designed for transactional workloads with flexible schemas, but it is not optimized for time-series data at high ingestion rates and can incur high RU costs for continuous writes; it also lacks native time-series functions like binning or retention policies. Option D is wrong because Azure Table Storage is a key-value store with limited query capabilities (only on partition and row keys), no support for time-series-specific operations, and high latency for range scans over timestamps, making it unsuitable for real-time dashboards and high-ingestion IoT workloads.

127
MCQmedium

Refer to the exhibit. You are deploying an ARM template with the above parameters. After deployment, you need to ensure that the storage account automatically moves blobs that are not accessed for 30 days to the archive tier. What should you do?

A.Enable soft delete for blobs.
B.Change the 'accessTier' parameter value to 'Archive'.
C.Change the 'replication' parameter value to 'GRS'.
D.Add a lifecycle management policy rule to the storage account.
AnswerD

Adding a lifecycle management policy rule to the storage account is the precise mechanism required. These policies enable automated tiering of blobs based on user-defined rules. A specific rule can be configured to identify blobs that have not been accessed for 30 days and then automatically transition them to the archive tier, directly satisfying the requirement for automatic movement based on access time. This ensures efficient cost management for infrequently accessed data.

Why this answer

Azure Storage lifecycle management policies allow you to automatically move blobs to cooler tiers (like Archive) based on age or last access time. By adding a rule with a filter for blobs not accessed in 30 days and an action to tier to Archive, you meet the requirement without manual intervention or changing the default access tier.

Exam trap

The trap here is that candidates often confuse setting the default access tier (via 'accessTier' parameter) with automating tier transitions based on age, leading them to choose Option B instead of recognizing that lifecycle management policies are required for time-based auto-tiering.

How to eliminate wrong answers

Option A is wrong because soft delete for blobs protects against accidental deletion by retaining deleted blobs for a specified period; it does not move blobs to a different access tier. Option B is wrong because changing the 'accessTier' parameter to 'Archive' would set the default tier for new blobs, but it does not automatically move existing blobs that are not accessed for 30 days; lifecycle management is needed for time-based tier transitions. Option C is wrong because changing replication to GRS (geo-redundant storage) affects durability and disaster recovery, not the access tier of blobs based on access patterns.

128
MCQmedium

An application requires a highly available key-value store with sub-millisecond read and write latencies across multiple Azure regions. The data model is simple and does not require complex queries. Which Azure data store should they choose?

A.Azure SQL Database
B.Azure Table Storage
C.Azure Cosmos DB
D.Azure Cache for Redis
AnswerC

Azure Cosmos DB is a globally distributed, multi-model database purpose-built for key-value workloads, offering turnkey multi-region writes and a 99.999% availability SLA for multiple-region configurations. Requests are served with single-digit millisecond latencies, and you can select from multiple consistency levels (eventual, session, bounded staleness, strong) to trade consistency for performance. Cosmos DB supports key-value schemas through its core (SQL), Table API, Cassandra API, and MongoDB API, making it the only option that fully satisfies the combination of global scale, high availability, and low latency.

Why this answer

Azure Cosmos DB is the correct choice because it provides a globally distributed, multi-region key-value store with guaranteed sub-10-millisecond read and write latencies at the 99th percentile, and supports multiple consistency models including eventual consistency for even lower latency. Its turnkey global distribution enables active-active replication across Azure regions, meeting the high availability and sub-millisecond performance requirements without complex query support.

Exam trap

The trap here is that candidates often confuse Azure Cache for Redis as a primary data store due to its sub-millisecond performance, but it lacks global distribution and durability guarantees, making Cosmos DB the correct choice for a highly available, multi-region key-value store.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database is a relational database that requires complex schema design, does not natively support sub-millisecond key-value access patterns, and its geo-replication is not designed for active-active multi-region writes with single-digit millisecond latencies. Option B is wrong because Azure Table Storage is a NoSQL key-value store but it is not globally distributed by default, has higher latency (typically 10-50 ms), and does not offer sub-millisecond performance or multi-region write capabilities. Option D is wrong because Azure Cache for Redis is an in-memory cache that does not provide native multi-region replication or persistence guarantees required for a durable key-value store, and its primary use case is caching, not a fully managed globally distributed data store.

129
MCQmedium

A company needs to store audit logs for 7 years to meet compliance requirements. The logs are generated at a high volume and must be cost-effective. They need to run occasional queries on recent logs (less than 30 days old) but rarely on older ones. Which Azure storage solution should they recommend?

A.Azure Blob Storage with lifecycle management to Archive tier
B.Azure SQL Database
C.Azure Cosmos DB
D.Azure Log Analytics
AnswerA

Azure Blob Storage is an object storage service designed to hold massive amounts of unstructured data, making it ideal for high-volume audit logs. Lifecycle management can automatically move blobs from Hot to Cool to Archive based on age or last-modification time, so after 7 years the logs reside in the Archive tier, which offers the lowest storage cost. The Archive tier provides acceptable retrieval latency (minutes to hours) for compliance access, and optional immutability policies prevent tampering.

Why this answer

Azure Blob Storage with lifecycle management to the Archive tier is the correct solution because it provides a cost-effective storage hierarchy for high-volume audit logs. Lifecycle management can automatically move logs from the Hot or Cool tier to the Archive tier after 30 days, aligning with the requirement to keep recent logs queryable while minimizing costs for older logs that are rarely accessed. The Archive tier offers the lowest storage cost, making it ideal for 7-year retention of audit data.

Exam trap

The trap here is that candidates often choose Azure Log Analytics (Option D) because it is associated with logs, but they overlook its retention limits and high cost for long-term storage, failing to recognize that Azure Blob Storage with lifecycle management is the correct archival solution for compliance-driven retention.

How to eliminate wrong answers

Option B (Azure SQL Database) is wrong because it is a relational database designed for transactional workloads and structured queries, not for cost-effective storage of high-volume, append-only audit logs; its storage costs are significantly higher than blob storage for large data volumes. Option C (Azure Cosmos DB) is wrong because it is a NoSQL database optimized for low-latency, globally distributed applications, not for long-term, cost-efficient archival of audit logs; its provisioned throughput and storage costs make it prohibitively expensive for this use case. Option D (Azure Log Analytics) is wrong because it is a monitoring and analytics service designed for real-time log ingestion and querying, not for long-term archival storage; its retention limits (default 30 days, up to 2 years with additional cost) cannot meet the 7-year compliance requirement cost-effectively.

130
Multi-Selecteasy

Which TWO Azure services can be used to store unstructured data such as documents, images, and videos?

Select 2 answers
A.Azure Blob Storage
B.Azure Files
C.Azure SQL Database
D.Azure Data Lake Storage Gen2
E.Azure Cosmos DB
AnswersA, D

Azure Blob Storage is Microsoft's object storage solution, specifically engineered to store and serve massive amounts of unstructured data—such as images, videos, documents, logs, and backup files—at global scale. It exposes REST-based HTTP(S) endpoints, supports lifecycle management across hot/cool/archive access tiers, and provides cost-effective redundancy options. Because each object is addressed by a unique URL and stored without a required schema, Blob Storage is the canonical service for unstructured data in Azure.

Why this answer

Azure Blob Storage is designed for storing massive amounts of unstructured data, such as documents, images, and videos, as objects (blobs) in a flat namespace. It supports three types of blobs (block, append, and page) and provides REST APIs for access, making it ideal for scalable, cost-effective storage of binary and text data.

Exam trap

The trap here is that candidates often confuse Azure Files (a file share service) with unstructured storage, but Azure Files is for structured file sharing with SMB/NFS, not for object storage of documents, images, and videos.

131
Multi-Selecteasy

Which TWO of the following are true about Azure Blob Storage access tiers?

Select 2 answers
A.The cool access tier has lower storage costs but higher access costs compared to the hot tier
B.The cool access tier is designed for data that is accessed more frequently than the hot tier
C.The archive access tier is suitable for data that is accessed daily
D.The archive access tier has the lowest storage costs but the highest retrieval latency
E.The hot access tier has the lowest storage costs
AnswersA, D

Cool is a lower-cost storage tier for data expected to remain for at least 30 days and be accessed only occasionally. It reduces capacity charges compared with Hot, but compensates with higher per-GB read/write and early-deletion fees, so access-heavy workloads become more expensive on Cool.

Why this answer

Azure Blob Storage's cool access tier is designed for infrequently accessed data, offering lower storage costs than the hot tier but higher access costs (per GB read/write) to compensate for the reduced storage price. This cost trade-off aligns with typical usage patterns where data is stored long-term but accessed less often.

Exam trap

The trap here is confusing the cost trade-off between storage and access—candidates often assume 'cool' means cheaper overall, but they miss that access costs are higher, and they mistakenly think archive supports daily access due to its low storage cost.

132
MCQmedium

A financial services company needs to store transaction logs for regulatory compliance. The logs must be stored in a cost-effective manner, and they must be immutable to prevent tampering. The logs are accessed infrequently but must be retained for 7 years. Which Azure storage solution should you recommend?

A.Azure Cosmos DB with time-to-live (TTL)
B.Azure Blob Storage with immutable storage policy and cool access tier
C.Azure SQL Database with long-term retention backup
D.Azure Files with share snapshots
AnswerB

Azure Blob Storage with an immutable storage policy (WORM) ensures that blobs cannot be modified or deleted for a user-specified retention interval, which directly meets the compliance requirements for tamper-proof financial transaction logs. The cool access tier offers low storage costs for data that is infrequently accessed—ideal for logs retained for regulatory audits—while still allowing blob versioning and lifecycle management for eventual archival or deletion. This combination delivers durable, scalable, and cost-effective storage optimised for append-only log workloads.

Why this answer

Azure Blob Storage with an immutable storage policy (WORM) ensures that transaction logs cannot be modified or deleted during the retention period, meeting compliance requirements. The cool access tier is cost-effective for infrequently accessed data, and the 7-year retention aligns with the policy's time-based retention. This combination provides both immutability and low-cost storage for long-term archival.

Exam trap

The trap here is that candidates may confuse Azure SQL Database long-term retention (which is for backup recovery, not immutable storage) with true immutability, or assume that any snapshot or TTL mechanism can satisfy regulatory immutability requirements when they actually allow deletion or modification.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB with TTL automatically deletes data after the TTL expires, which does not provide immutability and would delete logs before the 7-year retention period ends. Option C is wrong because Azure SQL Database long-term retention backup is designed for database recovery, not for storing immutable transaction logs, and it does not prevent tampering at the storage level. Option D is wrong because Azure Files share snapshots are point-in-time copies that can be deleted by the administrator, offering no immutability guarantee, and they are not cost-optimized for infrequent access over 7 years.

133
MCQmedium

You are designing a globally distributed application that requires low-latency reads and writes for a web application with user session data. The solution must support multi-master writes and provide 99.999% availability. Which Azure data service meets these requirements?

A.Azure SQL Database
B.Azure Cosmos DB
C.Azure Cache for Redis
D.Azure Table Storage
AnswerB

Cosmos DB is the correct choice because it natively supports multiple write regions for a single database account, enabling active-active writes from any Azure region. This multi-master capability, combined with service-managed replication and configurable consistency levels (Strong, Bounded Staleness, Session, etc.), allows you to meet the 99.999% availability SLA when you enable multi-region writes. It is a fully durable, globally distributed NoSQL database, making it perfect for globally distributed applications that need write access in multiple regions and continuous availability.

Why this answer

Azure Cosmos DB is the correct choice because it natively supports multi-master writes across multiple regions, enabling low-latency reads and writes globally. It offers a 99.999% availability SLA when configured with multiple write regions, and its turnkey global distribution ensures user session data is replicated with consistency options tailored for web applications.

Exam trap

The trap here is that candidates often confuse Azure Cache for Redis's low-latency caching with a durable, multi-master data store, overlooking that it lacks persistence guarantees and multi-master write support required for 99.999% availability.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database supports only a single writable primary replica (active geo-replication provides readable secondaries but not multi-master writes), and its maximum availability SLA is 99.995% for Business Critical tier, not 99.999%. Option C is wrong because Azure Cache for Redis is an in-memory cache, not a durable data store; it does not support multi-master writes natively and its SLA is 99.9% for Standard tier, far below 99.999%. Option D is wrong because Azure Table Storage is a NoSQL key-value store that does not support multi-master writes; it offers only single-region writes with read-access geo-redundant storage (RA-GRS) for reads, and its SLA is 99.99% for reads but only 99.9% for writes, insufficient for the required availability.

134
MCQmedium

A company needs a fully managed NoSQL database for a JSON document-oriented application that requires low latency (single-digit milliseconds) for reads and writes at any scale. The application will run globally and needs multi-region writes with automatic failover. Which Azure data store should they use?

A.Azure Cosmos DB
B.Azure Table Storage
C.Azure SQL Database
D.Azure Cache for Redis
AnswerA

Azure Cosmos DB is the correct choice because it is a fully managed, multi-model NoSQL database with native JSON document support, schema-agnostic indexing, and an SQL-like query engine. It uniquely delivers multi-region writes with automatic failover, elastic horizontal partitioning and tunable consistency, backed by an industry-leading SLA of 99.999% availability and single-digit millisecond read/write latency at the 99th percentile. These capabilities are purpose-built for globally distributed JSON workloads requiring both durability and low-latency access.

Why this answer

Azure Cosmos DB is the correct choice because it is a fully managed NoSQL database that natively supports JSON documents, offers single-digit millisecond latency for reads and writes at any scale, and provides multi-region writes with automatic failover through its multi-master replication capability. Its global distribution model allows you to configure multiple write regions, ensuring high availability and low latency worldwide.

Exam trap

The trap here is that candidates often confuse Azure Table Storage (a simple key-value store) with a fully managed NoSQL database, overlooking that it lacks native JSON support, multi-region writes, and automatic failover capabilities required for global, low-latency applications.

How to eliminate wrong answers

Option B (Azure Table Storage) is wrong because it is a key-value store that does not natively support JSON documents or multi-region writes with automatic failover; it offers only eventual consistency and lacks the global distribution features required. Option C (Azure SQL Database) is wrong because it is a relational database that does not support JSON as a native document model and cannot provide multi-region writes with automatic failover; it is not a NoSQL solution. Option D (Azure Cache for Redis) is wrong because it is an in-memory cache, not a fully managed NoSQL database; it does not persist JSON documents durably and lacks multi-region write capabilities with automatic failover.

135
MCQeasy

A company stores website static assets in Azure Blob Storage. The assets are updated weekly and must be available for immediate access for 30 days. After 30 days, older versions can be moved to the Cool tier to save costs but must still be accessible within seconds. They want an automated solution. What should they configure?

A.Set the access tier to Cool on the container
B.Use Azure Blob Storage lifecycle management rules
C.Manually change the access tier every 30 days
D.Use Azure Policy to enforce tier changes
AnswerB

Azure Blob Storage lifecycle management lets you define JSON rules with a filter (e.g., prefix or blob index tag) and conditions using the age in days from last modification; setting daysAfterModificationGreaterThan: 30 with a tierToCool action automatically moves qualifying blobs to Cool while leaving newer blobs in Hot. The rule is evaluated asynchronously within 24 hours, which precisely satisfies the 30-day retention requirement without manual intervention or downtime.

Why this answer

Azure Blob Storage lifecycle management rules allow you to automate tier transitions based on age or last modification time. By configuring a rule to move blobs to the Cool tier 30 days after creation, you meet the requirement for immediate access (Cool tier offers sub-second latency) while optimizing costs without manual intervention.

Exam trap

The trap here is confusing Azure Policy (which enforces configuration at resource creation) with lifecycle management (which automates transitions based on time), leading candidates to choose Policy when only lifecycle rules can schedule tier changes.

How to eliminate wrong answers

Option A is wrong because setting the access tier to Cool on the container applies to all blobs immediately, not after 30 days, and would prevent the required immediate access for the first 30 days. Option C is wrong because manually changing the access tier every 30 days is not automated and violates the requirement for an automated solution. Option D is wrong because Azure Policy can enforce compliance rules (e.g., requiring a specific tier) but cannot schedule or automate tier transitions based on age or time.

136
MCQmedium

Contoso, Ltd. is migrating a legacy on-premises application to Azure. The application uses a SQL Server database with complex queries and requires read-heavy workloads with sub-10-millisecond latency. The solution must support geo-replication for disaster recovery. Which Azure data service should you recommend?

A.Azure Cosmos DB for NoSQL
B.Azure SQL Database Business Critical
C.Azure SQL Database Hyperscale
D.Azure SQL Managed Instance Business Critical
AnswerB

Azure SQL Database Business Critical uses a premium storage and compute architecture based on Always On Availability Groups, providing multiple readable secondary replicas that can serve read-only traffic for low-latency read-heavy workloads. It also supports active geo-replication across Azure regions, giving disaster recovery and regional read access without changing the application's T-SQL code, and its fully compatible relational engine makes it the best fit for a legacy application that needs both read scaling and minimal migration risk.

Why this answer

Azure SQL Database Business Critical is correct because it uses SQL Server database engine with full T-SQL support for complex queries, provides read-heavy workloads with sub-10-millisecond latency via in-memory OLTP and local SSD storage, and supports active geo-replication for disaster recovery. This tier offers a readable secondary replica in a different Azure region, meeting both latency and geo-replication requirements.

Exam trap

The trap here is that candidates often choose Hyperscale for its scalability and geo-replication features, overlooking that its page server architecture introduces higher read latency for small, frequent queries compared to the local SSD-based Business Critical tier.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB for NoSQL does not support SQL Server T-SQL complex queries and uses a NoSQL API, making it incompatible with the existing SQL Server database. Option C is wrong because Azure SQL Database Hyperscale is optimized for large databases and high throughput but does not guarantee sub-10-millisecond latency for read-heavy workloads due to its page server architecture and potential cache misses. Option D is wrong because Azure SQL Managed Instance Business Critical supports geo-replication only via failover groups with limited read-scale capabilities, and it introduces additional management overhead compared to Azure SQL Database, which is more suitable for a simple migration of a legacy application.

137
MCQhard

AdventureWorks is a global retailer with a cloud-native architecture. They have a microservices application deployed on Azure Kubernetes Service (AKS). Each microservice needs to store its own data. The data requirements vary: (1) Shopping cart service: key-value data with high write throughput and low latency, data can be lost if not critical; (2) Order service: transactional data with strong consistency and ACID compliance; (3) Product catalog service: semi-structured product data that supports complex queries and is globally distributed for low-latency reads. The solution must use Azure PaaS services and minimize operational overhead. You need to design the data storage for each microservice. What should you recommend?

A.Azure Cosmos DB for all three services.
B.Azure Table Storage for shopping cart, Azure SQL Database for orders, Azure Cosmos DB for product catalog.
C.Azure Cache for Redis for shopping cart, Azure SQL Database for orders, Azure Cosmos DB for product catalog.
D.Azure SQL Database for all three services.
AnswerC

This combination correctly applies the polyglot persistence pattern to match each workload's access requirements. Azure Cache for Redis is an in-memory data store with sub-millisecond latency and built-in TTL, making it ideal for a transient, write-heavy shopping cart that must survive user sessions but not act as a durable system of record. Azure SQL Database provides full ACID compliance, relational integrity, and rich indexing, which are mandatory for order processing because every order transaction must be atomic and isolated. Azure Cosmos DB's flexible document model, tunable consistency levels, and global distribution allow a product catalog to be cached at edge regions and served with low latency while accommodating evolving product attributes. Together they address latency, consistency, and scalability where each technology is strongest.

Why this answer

Azure Cache for Redis provides a high-throughput, low-latency key-value store ideal for the shopping cart service where data loss is acceptable. Azure SQL Database offers full ACID compliance and strong consistency required for transactional order data. Azure Cosmos DB supports semi-structured data with global distribution and complex querying via its SQL API, meeting the product catalog's needs while minimizing operational overhead as a fully managed PaaS service.

Exam trap

The trap here is that candidates often assume Azure Cosmos DB can handle all workloads due to its multi-model nature, overlooking that it lacks native ACID compliance for transactional data and is overkill for simple key-value stores, while also forgetting that Azure Cache for Redis is a PaaS service suitable for high-throughput, loss-tolerant scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB, while versatile, does not natively provide ACID compliance across multiple documents without using transactional batches, and its multi-model nature adds unnecessary complexity and cost for the shopping cart's simple key-value needs; it also lacks the native relational integrity required for the order service. Option B is wrong because Azure Table Storage is a NoSQL key-value store with limited throughput and no native support for high write throughput or low latency at the scale required for a shopping cart, and it does not offer the sub-millisecond latency of an in-memory cache like Redis. Option D is wrong because Azure SQL Database is a relational database that is not optimized for high-write-throughput key-value workloads like the shopping cart, and it cannot natively handle semi-structured data with complex queries or global distribution for low-latency reads as effectively as Cosmos DB.

138
MCQmedium

A multinational corporation is designing a data storage solution for its global customer data. The data must be stored in the Azure region closest to each customer to minimize latency, but all data must be accessible from a central analytics platform for reporting. The solution must also comply with data residency regulations that require customer data to remain in the country of origin. Which Azure storage solution should the company recommend?

A.Azure Cosmos DB with multi-master writes and conflict resolution
B.Azure Data Lake Storage Gen2 with geo-zone-redundant storage (GZRS)
C.Azure Blob Storage with geo-redundant storage (GRS)
D.Azure SQL Database with active geo-replication
AnswerD

Azure SQL Database active geo-replication is correct because you create a database per customer and configure a readable secondary in the region that customer requires; replication is at the database level so isolation is clean. Even though it replicates the entire database rather than individual rows, that granularity matches the per-customer isolation model. You control both the primary and secondary locations, ensuring data residency while maintaining an active failover endpoint.

Why this answer

Azure SQL Database with active geo-replication allows the creation of a primary database in a central region and readable secondary databases in other regions. This enables low-latency reads for customers by serving data from the closest secondary while respecting data residency because the primary remains in the country of origin and replicas can be limited to the same country. The central analytics platform can query the primary database for reporting.

This solution avoids the global replication that would violate residency requirements.

Exam trap

Candidates may be tempted to choose Azure Cosmos DB with multi-master writes for global distribution, but multi-master replicates data across regions, violating data residency regulations. The correct solution involves keeping data localized via per-country databases with geo-replication limited to the same country.

How to eliminate wrong answers

Option B is wrong because Azure Data Lake Storage Gen2 with GZRS provides geo-zone-redundant storage that replicates data to a secondary region, but it does not support multi-region writes or per-region data isolation for residency compliance; data is replicated as a single copy, not independently stored per country. Option C is wrong because Azure Blob Storage with GRS replicates data to a paired region, which violates data residency requirements by moving customer data out of the country of origin, and it does not offer multi-region write capabilities. Option D is wrong because Azure SQL Database with active geo-replication creates readable secondaries in other regions but only supports writes in the primary region, failing to minimize write latency for customers outside that region, and it does not inherently enforce per-country data isolation without complex sharding.

139
MCQeasy

You are designing a solution to store large binary files (videos) that are accessed infrequently but must be retained for 7 years for compliance. The solution must minimize storage costs while allowing retrieval within 24 hours. Which Azure storage tier should you use?

A.Premium tier
B.Cool tier
C.Hot tier
D.Archive tier
AnswerD

The Archive tier has the lowest per-gigabyte storage cost in Azure Blob Storage, making it the designated choice for long-term retention where data is rarely accessed. It requires rehydration to a Hot or Cool tier before reading, with a retrieval latency of up to 15 hours (typically a few hours), which is acceptable for archival scenarios. A 180-day minimum storage period and higher per-GB retrieval fees are the trade-offs, but for large binaries stored for years, the storage cost savings dominate.

Why this answer

The Archive tier is the correct choice because it is the lowest-cost storage tier for infrequently accessed data that must be retained for long periods (7 years). It allows retrieval within 24 hours via standard rehydration, meeting the compliance requirement while minimizing storage costs. The other tiers (Premium, Hot, Cool) are more expensive and designed for higher-frequency access, making them unsuitable for this cost-optimization scenario.

Exam trap

The trap here is that candidates often choose Cool tier because they see 'infrequent access' and '24-hour retrieval' and mistakenly think Archive's retrieval time is too slow, but the question explicitly allows up to 24 hours, making Archive the correct cost-optimized choice.

How to eliminate wrong answers

Option A is wrong because the Premium tier is designed for low-latency, high-frequency access (e.g., Azure Virtual Machine disks) and incurs the highest storage costs, which is unnecessary for infrequently accessed videos. Option B is wrong because the Cool tier is optimized for data accessed less than once per month but still has higher storage costs than Archive and is not the most cost-effective for 7-year retention with 24-hour retrieval. Option C is wrong because the Hot tier is intended for frequent access (multiple times per month) and has the highest storage costs among standard tiers, contradicting the goal of minimizing costs for infrequently accessed data.

140
MCQhard

A company needs to store sensitive customer data in Azure Blob Storage with encryption at rest using customer-managed keys (CMK) stored in a hardware security module (HSM). Which Azure service should they use to manage the keys?

A.Azure Key Vault (Premium tier)
B.Azure Information Protection
C.Azure Key Vault (Standard tier)
D.Azure Key Vault Managed HSM
AnswerD

Azure Key Vault Managed HSM is the correct service for storing sensitive customer data encryption keys because it is a fully managed, single-tenant, FIPS 140-2 Level 3 validated hardware security module. It provides HSM-backed keys suitable for customer-managed keys (CMK) used in Azure encryption at rest, ensuring keys are protected in dedicated hardware partitions inaccessible to other tenants. Managed HSM also supports more granular access control, powerful Rbac for key management, and full key lifecycle management, making it the appropriate choice for high-security and compliance-driven environments.

Why this answer

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant HSM that is FIPS 140-2 Level 3 validated. It allows you to store customer-managed encryption keys (CMKs) in a hardware security module (HSM) for Azure Storage encryption at rest, meeting the requirement for HSM-backed key storage. The Premium tier of Azure Key Vault also supports HSM-backed keys, but the question specifies 'stored in a hardware security module (HSM)', and Managed HSM provides dedicated HSM partitions with stronger isolation and compliance.

Exam trap

The trap here is that candidates often confuse the Azure Key Vault Premium tier (which supports HSM keys but in a shared multi-tenant HSM) with the dedicated HSM requirement, leading them to select Option A instead of the more appropriate Managed HSM.

How to eliminate wrong answers

Option A is wrong because Azure Key Vault (Premium tier) does support HSM-backed keys, but it is a multi-tenant service with shared HSM pools, not a dedicated HSM; the question's phrasing 'stored in a hardware security module (HSM)' implies a dedicated HSM solution, which Managed HSM provides. Option B is wrong because Azure Information Protection is a classification and labeling service for data protection, not a key management service for encryption at rest. Option C is wrong because Azure Key Vault (Standard tier) uses software-protected keys (FIPS 140-2 Level 1), not HSM-backed keys, and thus cannot meet the requirement for storing keys in an HSM.

141
MCQhard

A company is building a petabyte-scale data lake for analytics. The workload includes Apache Spark and Hive jobs that read and write large files. The storage solution must support a hierarchical namespace for efficient directory operations, POSIX-like access control lists (ACLs) for fine-grained permissions, and must be accessible via the Azure Blob Storage API for compatibility with existing tools. Furthermore, the solution should be optimized for analytics workloads with high throughput. Which Azure data service should they choose?

A.Azure Data Lake Storage Gen2
B.Azure Data Lake Storage Gen1
C.Azure Blob Storage
D.Azure Files
AnswerA

Azure Data Lake Storage Gen2 is correct because it layers a hierarchical namespace onto Blob Storage, providing POSIX ACLs, atomic directory renaming, and a Hadoop-compatible `abfs://` filesystem that Spark, Hive, and Presto can use directly. It also fully supports the Blob API and Azure SDKs, so existing tooling works unchanged, while delivering the scale, encryption, and lifecycle policies needed to run petabyte-scale analytics workloads.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with POSIX-like ACLs and is accessible via the Azure Blob Storage API. This service is specifically optimized for analytics workloads like Apache Spark and Hive, providing high throughput for petabyte-scale data lakes. The hierarchical namespace enables efficient directory operations, while the Blob Storage API ensures compatibility with existing tools.

Exam trap

The trap here is that candidates may confuse Azure Data Lake Storage Gen1 with Gen2, overlooking that Gen1 lacks Blob Storage API compatibility, or they may assume Azure Blob Storage with hierarchical namespace enabled is a separate service, but ADLS Gen2 is the specific offering that combines all required features.

How to eliminate wrong answers

Option B (Azure Data Lake Storage Gen1) is wrong because it uses its own REST API, not the Azure Blob Storage API, breaking compatibility with existing tools that rely on Blob Storage APIs. Option C (Azure Blob Storage) is wrong because it does not support a hierarchical namespace by default (only flat namespace) and lacks POSIX-like ACLs, making it unsuitable for efficient directory operations and fine-grained permissions. Option D (Azure Files) is wrong because it is designed for SMB file shares and shared file access, not for petabyte-scale analytics workloads with high throughput, and it does not support the Blob Storage API or a hierarchical namespace optimized for Spark/Hive.

142
MCQhard

Refer to the exhibit. A custom Azure RBAC role is defined as shown. A user assigned this role is unable to delete blobs in a container. What is the most likely reason?

A.The role is scoped to the storage account but not to the container
B.The role does not include read permission on blobs
C.The role does not include any dataActions
D.The role does not include delete permission on blobs
AnswerD

This is correct: the custom role's DataActions list only includes read and write permissions for blobs, notably omitting Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete. Without the delete action, a user assigned this role cannot delete blobs or containers. Therefore, any attempt to delete blob data will be denied, making the missing delete permission the precise reason why the role is insufficient for deletion tasks.

Why this answer

The custom RBAC role definition shown in the exhibit includes 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete' under the 'Actions' section, but this permission is a control plane action, not a data plane action. To delete blobs, the role must include the corresponding data action 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete/action' under 'DataActions'. Without it, the user lacks the necessary data plane permission to perform blob deletion, even though the control plane permission is present.

Exam trap

The trap here is that candidates see 'delete' in the Actions list and assume it covers blob deletion, missing the critical distinction between control plane and data plane permissions in Azure RBAC.

How to eliminate wrong answers

Option A is wrong because the scope of the role (storage account vs. container) does not affect the fundamental requirement for dataActions; the issue is the missing data action, not the scope. Option B is wrong because read permission on blobs (Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read) is not required to delete blobs; the delete operation only requires the delete data action. Option C is wrong because the role does include dataActions in the definition (as shown in the exhibit), but the specific delete data action is missing; the problem is not the absence of all dataActions.

143
Multi-Selecthard

Which TWO of the following are requirements for using Azure SQL Database auto-failover groups? (Select two.)

Select 2 answers
A.Both servers must be in the same Azure region.
B.The primary and secondary servers must be in different Azure regions.
C.The secondary server must have the same logical server name.
D.The databases must be in different elastic pools.
E.The databases must use the same service tier.
AnswersB, E

Primary and secondary servers must be in different regions to ensure geo-redundancy and disaster recovery. This is correct.

Why this answer

Option B is correct because auto-failover groups are designed for geo-replication and disaster recovery, requiring the primary and secondary logical servers to reside in different Azure regions to provide regional failover capability. Option E is correct because the databases in the failover group must be on the same service tier (and same compute tier/edition) so that the secondary can properly host the replicated databases and maintain consistent performance characteristics. Option A is incorrect because placing both servers in the same region defeats the purpose of geo-failover and is not a requirement.

Option C is incorrect because the secondary server must have a different logical server name; it is the failover group listener that provides a stable connection endpoint, not identical server names. Option D is incorrect because elastic pool membership is not a requirement for auto-failover groups; databases can be in elastic pools or single databases, and they do not need to be in different pools.

Exam trap

Candidates often mistakenly think the secondary server must have the same logical server name as the primary, but in fact it must be different. Also, the requirement for servers to be in different regions is strict; they cannot be in the same region.

144
Multi-Selecteasy

A company is designing a storage solution for its backup data. The backups must be stored for 10 years for compliance reasons. The solution should minimize storage costs while ensuring data durability. Which two Azure services should the company consider? (Choose two.)

Select 2 answers
A.Azure Blob Storage Archive tier
B.Azure Files with snapshots
C.Azure NetApp Files with cross-region replication
D.Azure Disk Storage with incremental snapshots
E.Azure Backup with long-term retention policy
AnswersA, E

Azure Blob Storage Archive tier is the correct choice because it offers the lowest storage cost per GiB for data that is rarely accessed, such as backups retained for decades. Archive tier supports long-term retention with configurable lifecycle policies, and it provides secure storage with encryption and optional immutability to meet compliance. While data retrieval may require hours of rehydration, for infrequent backup restores this trade-off is acceptable.

Why this answer

Azure Blob Storage Archive tier is correct because it provides the lowest-cost storage for data that is rarely accessed, with a 10-year retention period meeting compliance requirements. It offers 11 nines of durability (99.999999999%) by storing multiple copies across Azure regions, ensuring data integrity over the long term.

Exam trap

The trap here is that candidates often confuse Azure Backup with long-term retention (which is a service that manages backup lifecycle and can use Archive tier) with other Azure storage services that are not designed for cost-effective, long-term archival, such as Azure Files or Azure NetApp Files.

145
MCQmedium

A company manages a fleet of millions of IoT devices that send telemetry data every minute. The data must be stored for 10 years to meet compliance requirements. For the first 30 days, data is accessed frequently for real-time dashboards and alerting. After 30 days, data is only accessed occasionally for historical analysis and reporting. The solution must be cost-effective and support high ingestion rates. Which Azure service should the company use to store and query this data?

A.Azure Blob Storage with Azure Data Lake Storage Gen2
B.Azure Data Explorer
C.Azure SQL Database
D.Azure Cosmos DB with SQL API
AnswerB

Azure Data Explorer is the only service here built specifically for high-fidelity time-series analytics: its columnar engine ingests millions of events per second, automatically creates inverted indexes, and uses a hot/cold cache with data tiering to balance performance and cost. KQL natively supports time-based operations such as bin(), summarize, anomaly detection, and lag/lead calculations, which can run on both streaming and historical data. This makes it the appropriate choice for a fleet of millions of devices where real-time visibility and long-term retention are required.

Why this answer

Azure Data Explorer (ADX) is designed for high-ingestion, time-series telemetry data and supports real-time dashboards and alerting on fresh data, while also providing cost-effective long-term storage for historical queries. Its columnar storage and indexing enable fast analytics on billions of records, making it ideal for IoT scenarios with millions of devices sending data every minute and a 10-year retention requirement.

Exam trap

The trap here is that candidates often choose Azure Blob Storage or Cosmos DB because they associate them with 'storage' or 'IoT,' but they fail to recognize that Azure Data Explorer is the only service purpose-built for high-velocity time-series analytics with built-in hot/cold tiering and native support for real-time alerting and long-term retention at scale.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage with Azure Data Lake Storage Gen2 is optimized for batch analytics and large file storage, not for real-time querying and alerting on high-velocity telemetry data; it lacks native time-series indexing and low-latency query capabilities. Option C is wrong because Azure SQL Database is a relational OLTP system that cannot cost-effectively handle the ingestion rate of millions of events per minute or the 10-year retention of massive telemetry volumes without significant performance degradation and high costs. Option D is wrong because Azure Cosmos DB with SQL API is a globally distributed NoSQL database designed for low-latency reads/writes on operational data, but it is not optimized for high-throughput time-series ingestion and analytical queries over long retention periods, and its cost would be prohibitive for storing billions of telemetry records for 10 years.

146
MCQmedium

A company is designing a data storage solution for a global e-commerce platform that requires low-latency access to product catalog data from multiple Azure regions. The data is read-heavy, with occasional updates. Which Azure data store should they recommend?

A.Azure Cache for Redis
B.Azure Blob Storage
C.Azure SQL Database
D.Azure Cosmos DB
AnswerD

Azure Cosmos DB is a fully managed NoSQL database purpose-built for turnkey global distribution with multi-region writes and reads at single-digit millisecond latency. Each container can be mapped to multiple Azure regions, and data is replicated with multiple consistency models—from strong to eventual—giving developers predictable latency and availability trade-offs. With automatic failover and an SLA-backed 99.999% availability, Cosmos DB is the only option here engineered specifically as a distributed, low-latency, globally redundant data store.

Why this answer

Azure Cosmos DB is the correct choice because it provides globally distributed, multi-region writes with tunable consistency levels and single-digit-millisecond latency for read-heavy workloads. Its ability to replicate data across Azure regions and serve reads from the nearest region directly addresses the requirement for low-latency global access to product catalog data with occasional updates.

Exam trap

The trap here is that candidates often choose Azure Cache for Redis (Option A) because they associate low-latency with caching, but fail to recognize that the question requires a durable, globally distributed primary data store, not a cache layer that depends on an underlying database.

How to eliminate wrong answers

Option A is wrong because Azure Cache for Redis is an in-memory cache, not a durable primary data store; it would require an underlying persistent store and cannot serve as the authoritative source for product catalog data that needs occasional updates. Option B is wrong because Azure Blob Storage is optimized for unstructured blob data (images, videos, backups) and does not support low-latency, sub-second queries on structured product catalog data with indexing and consistency guarantees. Option C is wrong because Azure SQL Database is a relational database that, while supporting read replicas, does not natively provide multi-region, multi-master replication with automatic failover and tunable consistency for global low-latency reads; it requires complex manual configuration and has higher latency for cross-region access.

147
Multi-Selectmedium

Which Azure service can be used to implement a globally distributed database that supports multi-region writes and provides low-latency access to users worldwide?

Select 1 answer
A.Azure Storage with geo-redundant storage (GRS).
B.Azure Cache for Redis with geo-replication.
C.Azure Cosmos DB with multi-master enabled.
D.Azure Database for PostgreSQL with geo-replication.
E.Azure SQL Database with active geo-replication and failover groups.
AnswersC

Correct. Azure Cosmos DB with multi-master enabled natively supports multi-region writes with automatic conflict resolution and low-latency access worldwide.

Why this answer

Azure Cosmos DB with multi-master enabled (Option C) is the only Azure service among the options that natively supports multi-region write operations, allowing data to be written to any Azure region simultaneously with automatic conflict resolution and low-latency access globally. Azure SQL Database with active geo-replication and failover groups (Option E) does not support concurrent multi-region writes; it enables read-only replicas in secondary regions and failover to a single writable region, which does not meet the requirement for multi-region writes. Other options either don't support multi-region writes or aren't database services.

Exam trap

The trap is that candidates may mistake Azure SQL Database's active geo-replication and failover groups as supporting multi-region writes. However, it only allows writes in one region at a time after failover, not concurrent writes. Azure Cosmos DB with multi-master is the only service that provides true multi-region write capability.

148
MCQmedium

A SaaS company uses Azure SQL Database for a multi-tenant application. They have 80 tenant databases, each with varying and unpredictable usage patterns. The company wants to optimize costs without sacrificing performance and wants the ability to easily add new tenant databases without over-provisioning. Which deployment option should they use?

A.Azure SQL Database elastic pool
B.Single Azure SQL Database per tenant
C.Azure SQL Managed Instance
D.Azure SQL Database Hyperscale
AnswerA

For a multi-tenant SaaS workload, elastic pools let you purchase a shared set of eDTUs or vCores that is distributed across many Azure SQL databases. This model excels when tenant usage is intermittent and peaks do not align, so the aggregate resource consumption is far lower than the sum of individual peak requirements, reducing overall cost while maintaining predictable per-database pricing.

Why this answer

Azure SQL Database elastic pool is the correct choice because it allows multiple tenant databases to share a fixed set of resources (DTUs or vCores), automatically absorbing the unpredictable usage spikes of individual tenants without over-provisioning. This model optimizes cost by paying for the pooled resources rather than each database's peak capacity, and new tenant databases can be added seamlessly to the pool without upfront resource allocation.

Exam trap

The trap here is that candidates often choose Single Azure SQL Database per tenant (Option B) because they think it provides isolation and simplicity, but they overlook the cost inefficiency of over-provisioning for unpredictable peaks, which is exactly the problem elastic pools solve.

How to eliminate wrong answers

Option B (Single Azure SQL Database per tenant) is wrong because it requires provisioning each database for its peak load, leading to significant over-provisioning and higher costs when tenants have unpredictable, varying usage patterns. Option C (Azure SQL Managed Instance) is wrong because it is a fully managed instance of SQL Server with fixed resource limits per instance, designed for lift-and-shift scenarios, not for cost-efficient multi-tenant elasticity with many small databases. Option D (Azure SQL Database Hyperscale) is wrong because it is optimized for very large databases (up to 100 TB) with high throughput and rapid scaling, not for pooling many small, unpredictable tenant databases; it would be unnecessarily expensive and complex for this workload.

149
MCQhard

A company runs a high-performance computing (HPC) workload that requires low-latency access to large files (hundreds of GB) from thousands of Azure VMs concurrently. The files must be accessible via the NFS protocol and the solution must be a fully managed, POSIX-compliant file system that can scale throughput linearly with capacity. Which Azure storage solution should they choose?

A.Azure NetApp Files
B.Azure Files (premium tier)
C.Azure Blob Storage with NFS 3.0 support
D.Azure HPC Cache
AnswerA

Azure NetApp Files is a fully managed, enterprise-grade file service built on NetApp ONTAP, providing both NFS and SMB protocols with POSIX-compliant semantics. It is engineered for high-performance computing, offering sub-millisecond latencies, tens of thousands of IOPS, and multi-GiB/s throughput that scales linearly by adding capacity. It also supports advanced data management features like snapshots, clones, and near-instantaneous resizing, making it the optimal choice for demanding HPC workloads.

Why this answer

Azure NetApp Files is the correct choice because it provides a fully managed, POSIX-compliant NFS file system that can scale throughput linearly with capacity. It is designed for HPC workloads requiring low-latency access to large files from thousands of concurrent VMs, offering sub-millisecond latency and high throughput that increases as you add capacity.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with NFS support as a fully POSIX-compliant file system, overlooking its lack of full POSIX compliance and linear throughput scaling, or they assume Azure Files premium tier can match the performance and scalability of Azure NetApp Files for HPC workloads.

How to eliminate wrong answers

Option B is wrong because Azure Files (premium tier) uses SMB protocol by default and, while it supports NFS, it does not provide the linear throughput scaling with capacity required for HPC workloads; its performance is capped per share and does not scale linearly. Option C is wrong because Azure Blob Storage with NFS 3.0 support is not a fully POSIX-compliant file system; it lacks features like hard links and directory rename operations, and its throughput does not scale linearly with capacity in the same way as a true file system. Option D is wrong because Azure HPC Cache is a caching service that accelerates access to existing storage (e.g., on-premises or Azure Blob), not a fully managed, POSIX-compliant file system itself; it does not provide a native NFS file system with linear throughput scaling.

150
MCQhard

Your company, Contoso Ltd., is a global financial services firm with a primary data center in London and a disaster recovery site in Paris. They are migrating their on-premises SQL Server databases to Azure. The databases include: (1) a 2-TB customer database with high transaction throughput, requiring an RPO of 5 seconds and an RTO of 30 seconds; (2) a 500-GB reporting database that is read-only and can tolerate an RPO of 1 hour and an RTO of 2 hours; (3) a 100-GB archival database that is accessed once a month. The solution must minimize costs while meeting requirements. You need to recommend a storage and database strategy for each database. What should you recommend?

A.Use Azure SQL Managed Instance for all databases with auto-failover groups.
B.Use Azure SQL Database with active geo-replication for the customer database, geo-restore for the reporting database, and long-term retention for the archival database.
C.Use Azure Cosmos DB for the customer database, Azure SQL Database for reporting, and Azure Blob Storage for archival.
D.Use Azure SQL Database with active geo-replication for all databases.
AnswerB

Active geo-replication on the customer database continuously replicates transactions to a readable secondary in another region, giving you a low RPO and fast failover for the mission-critical transactional workload. Geo-restore for the reporting database uses geo-redundant backups to recover to another region only when a disaster occurs, avoiding the cost of maintaining a live secondary. Long-term retention on the archival database supports configurable backup retention up to ten years at blob storage pricing, satisfying compliance requirements without continuous replication. This tiered strategy pairs the right recovery and retention mechanism with each database's functional and cost requirements.

Why this answer

It aligns the recovery objectives and cost constraints for each database. The customer database requires an RPO of 5 seconds and RTO of 30 seconds, which active geo-replication can meet by continuously replicating transactions to a secondary region with an RPO of 5 seconds and RTO of 30 seconds (including failover time). The reporting database tolerates an RPO of 1 hour and RTO of 2 hours, making geo-restore (which restores from geo-redundant backups with up to 1-hour RPO) a cost-effective choice.

The archival database is accessed monthly, so long-term retention (LTR) backups stored in Azure Blob Storage minimize cost while meeting the infrequent access pattern.

Exam trap

The trap here is that candidates often assume all databases need the highest availability feature (active geo-replication) without considering cost optimization, or they mistakenly think Azure SQL Managed Instance can achieve sub-minute RPO, when in fact its auto-failover groups have a 5-minute RPO limit due to the use of distributed availability groups.

How to eliminate wrong answers

Option A is wrong because Azure SQL Managed Instance with auto-failover groups cannot achieve an RPO of 5 seconds (auto-failover groups have a maximum RPO of 5 minutes) and is more expensive than necessary for the reporting and archival databases. Option C is wrong because Azure Cosmos DB is a NoSQL database and does not support SQL Server workloads or the required ACID transactions for the customer database; Azure Blob Storage for archival lacks native SQL querying and backup restore capabilities needed for the archival database. Option D is wrong because using active geo-replication for all databases incurs unnecessary cost for the reporting database (which only needs geo-restore) and the archival database (which only needs LTR), and active geo-replication does not support the read-only reporting database's lower RPO/RTO requirements efficiently.

← PreviousPage 2 of 3 · 180 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design data storage solutions questions.