Courseiva

CCNA Design infrastructure solutions Questions

75 of 241 questions · Page 3/4 · Design infrastructure solutions · Answers revealed

151
MCQmedium

Your company plans to migrate on-premises file servers to Azure. The solution must support SMB protocol and integrate with Microsoft Entra ID for authentication. You need to choose a service that provides fully managed file shares accessible from multiple Azure regions. Which Azure service should you use?

A.Azure Disk Storage
B.Azure Files
C.Azure NetApp Files
D.Azure Blob Storage
AnswerB

Azure Files is a fully managed file share service that supports both SMB and NFS protocols, enabling users to map shares in Windows or Linux without managing underlying infrastructure. It integrates with Microsoft Entra ID for Kerberos-based authentication and Azure RBAC for share-level permissions, and it offers features like Azure File Sync to extend on-premises file servers. Its simplicity, low operational overhead, and protocol compatibility make it the ideal PaaS choice for migrating typical on-premises file servers to Azure.

Why this answer

Azure Files provides fully managed SMB file shares that can be accessed from multiple Azure regions using the SMB 3.0 protocol. It integrates natively with Microsoft Entra ID (formerly Azure AD) for Kerberos-based authentication, allowing on-premises identities to access shares without additional domain controllers. This makes it the correct choice for migrating on-premises file servers to a multi-region, identity-aware managed file service.

Exam trap

The trap here is that candidates often confuse Azure NetApp Files (which also supports SMB and Entra ID) as the fully managed option, but Azure NetApp Files is a first-party NetApp service requiring more administrative overhead and is not as straightforward for simple multi-region file shares as Azure Files.

How to eliminate wrong answers

Option A is wrong because Azure Disk Storage provides block-level volumes attached to a single VM, not managed file shares accessible via SMB from multiple regions. Option C is wrong because Azure NetApp Files offers NFS and SMB protocols but is a high-performance, enterprise-grade file service that is not fully managed in the same sense as Azure Files and requires a delegated subnet, making it less suitable for simple multi-region file share scenarios. Option D is wrong because Azure Blob Storage is an object storage service that does not support the SMB protocol natively (it uses REST APIs or NFS 3.0 preview) and cannot integrate with Microsoft Entra ID for SMB authentication.

152
MCQeasy

A company deploys a web application on Azure VMs. They need to distribute incoming HTTP and HTTPS traffic based on the URL path: requests to /api/* go to one VM pool, requests to /images/* go to another pool. They also need to offload SSL/TLS termination. Which Azure load balancing solution should they use?

A.Azure Load Balancer
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a Layer 7 web traffic load balancer that provides advanced application-level features, including URL path-based routing, SSL/TLS termination, cookie-based session affinity, and an optional Web Application Firewall (WAF). It allows traffic to be routed to different backend pools based on URL patterns, which directly meets the stated requirement. This makes it the correct choice for regional Azure VM web applications needing path-based routing and SSL offload.

Why this answer

Azure Application Gateway is a layer-7 load balancer that can route traffic based on URL path (e.g., /api/* vs /images/*) and provides SSL/TLS termination at the gateway, offloading the decryption from the backend VMs. This matches both requirements exactly, whereas other solutions either lack layer-7 path-based routing or are designed for global traffic distribution.

Exam trap

The trap here is that candidates often confuse Azure Application Gateway (regional layer-7 routing) with Azure Front Door (global layer-7 routing) or Azure Load Balancer (layer-4), failing to recognize that only Application Gateway provides both URL path-based routing and SSL termination for a single-region deployment.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at layer 4 (TCP/UDP) and cannot route based on URL path or perform SSL/TLS termination; it only distributes traffic by IP and port. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic load balancer that routes based on DNS queries, not URL paths, and does not offload SSL/TLS termination. Option D is wrong because Azure Front Door is a global layer-7 service that can route by URL path and offload SSL, but it is designed for global distribution across regions, not for routing within a single region to VM pools; Application Gateway is the correct regional solution for this scenario.

153
MCQhard

You are designing a backup strategy for Azure VMs running critical business applications. The solution must support application-consistent backups and allow for restoration to a different region. Which Azure service and configuration should you use?

A.Azure Backup with application-consistent backup policy and geo-redundant storage
B.Azure Disk Encryption with Azure Backup
C.Azure Snapshot with cross-region copy
D.Azure Site Recovery with replication to secondary region
AnswerA

Azure Backup is the correct choice because it leverages the Volume Shadow Copy Service (VSS) to capture application-consistent recovery points, ensuring that databases and applications are in a consistent state before the backup is taken. Geo-redundant storage (GRS) in the Recovery Services vault replicates backup data to a paired Azure region, enabling geo-restore if the primary region is lost. Azure Backup also offers 99.9% RPO compliance, encrypted backups, and long-term retention policies, making it a comprehensive, managed backup solution for critical VMs.

Why this answer

Azure Backup with an application-consistent backup policy uses the Volume Shadow Copy Service (VSS) on Windows or pre/post-scripts on Linux to ensure that all in-memory data and pending I/O operations are flushed before the snapshot is taken. By configuring the Backup vault with geo-redundant storage (GRS), the backup data is replicated to a paired region, enabling restoration to a different region in the event of a regional disaster.

Exam trap

The trap here is confusing Azure Site Recovery (disaster recovery) with Azure Backup (backup), and assuming that any snapshot or replication mechanism automatically provides application consistency and point-in-time restore capabilities.

How to eliminate wrong answers

Option B is wrong because Azure Disk Encryption provides encryption at rest for managed disks but does not create backups or support application-consistent snapshots, nor does it enable cross-region restoration. Option C is wrong because Azure Snapshot with cross-region copy can copy a snapshot to another region, but snapshots are crash-consistent by default and do not guarantee application consistency without additional scripting or coordination with VSS. Option D is wrong because Azure Site Recovery is designed for disaster recovery and replication of VMs to a secondary region, not for backup; it does not natively support application-consistent backups for point-in-time restoration and is not a backup service.

154
MCQeasy

A company plans to deploy a web application on Azure virtual machines. They want to protect against a datacenter failure within a region. The VMs must be distributed across multiple physically separate locations with independent power, cooling, and networking. Which deployment option should they use?

A.Availability Set
B.Availability Zones
C.Virtual Machine Scale Set
D.Proximity Placement Group
AnswerB

Availability Zones are physically separate locations inside an Azure region, each with its own independent power, cooling, and networking, and each containing at least one datacenter. By placing VMs in different zones, you ensure that no single datacenter failure can bring down all instances, because the zones are designed as isolated failure domains with no shared infrastructure. This is why zone-redundant deployment is the direct answer to protecting against a full datacenter outage.

Why this answer

Availability Zones are physically separate datacenters within an Azure region, each with independent power, cooling, and networking. By deploying VMs across multiple zones, the application is protected against a single datacenter failure, meeting the requirement for fault isolation at the datacenter level.

Exam trap

The trap here is that candidates often confuse Availability Sets (which protect against rack-level failures within a single datacenter) with Availability Zones (which protect against entire datacenter failures), leading them to select the wrong option when the question explicitly requires physically separate locations with independent infrastructure.

How to eliminate wrong answers

Option A is wrong because an Availability Set protects against failures within a single datacenter (rack-level faults) by distributing VMs across update and fault domains, not across physically separate datacenters. Option C is wrong because a Virtual Machine Scale Set is primarily for auto-scaling and managing identical VMs; while it can use Availability Zones, the scale set itself is not a deployment option that guarantees distribution across physically separate locations without explicit zone configuration. Option D is wrong because a Proximity Placement Group is designed to reduce network latency by co-locating VMs close together, which is the opposite of distributing them across physically separate locations.

155
MCQmedium

Your company has an Azure subscription with multiple virtual networks connected via VNet peering. You need to design a solution to allow VMs in different peered VNets to resolve each other's private IP addresses using custom DNS suffixes. The solution must minimize administrative overhead. What should you implement?

A.Deploy custom DNS servers on Azure VMs and configure VNets to use those servers.
B.Configure Azure DNS to use a custom domain name and update each VM's DNS suffix.
C.Use Azure Firewall as a DNS proxy with custom DNS settings.
D.Create an Azure Private DNS Zone linked to each VNet with auto-registration enabled.
AnswerD

Creating an Azure Private DNS Zone and linking it to each VNet with auto-registration enabled provides fully managed, automatic name resolution for VMs across the entire peered network topology. When auto-registration is turned on, Azure automatically creates and maintains A records for every VM as they are generated or deleted, eliminating manual record management. By linking the zone to all VNets involved in peering, nodes in any linked VNet can resolve each other's hostnames using the same private DNS namespace, making this the correct, scalable, and administration-free solution.

Why this answer

Azure Private DNS Zone with auto-registration enables VMs in peered VNets to resolve each other's private IP addresses using custom DNS suffixes without deploying or managing custom DNS servers. When auto-registration is enabled, Azure automatically creates and updates A records for VMs in the linked VNet, and VNet peering propagates DNS resolution across peered VNets. This minimizes administrative overhead because no manual DNS server configuration or VM-level DNS suffix updates are needed.

Exam trap

The trap here is that candidates often assume custom DNS servers or Azure Firewall DNS proxy are needed for custom DNS suffixes, but Azure Private DNS Zone with auto-registration provides a fully managed, zero-maintenance solution for private DNS resolution across peered VNets.

How to eliminate wrong answers

Option A is wrong because deploying custom DNS servers on Azure VMs introduces significant administrative overhead for patching, scaling, and high availability, contradicting the requirement to minimize overhead. Option B is wrong because Azure DNS custom domain names apply to public DNS resolution, not private IP resolution across peered VNets, and updating each VM's DNS suffix manually is not scalable. Option C is wrong because Azure Firewall as a DNS proxy does not provide custom DNS suffix resolution for private IP addresses across peered VNets; it only forwards DNS queries to a specified DNS server and does not create or manage DNS records.

156
MCQeasy

A company is deploying a new application on Azure Kubernetes Service (AKS). The application requires persistent storage that can be dynamically provisioned and accessed by multiple pods simultaneously. Which Azure storage solution should the company use?

A.Azure Blob Storage
B.Azure Files
C.Azure Disk
D.Azure NetApp Files
AnswerB

Azure Files provides fully managed SMB 3.0 file shares that can be mounted by many clients concurrently, giving it native ReadWriteMany (RWX) support. The Azure Files CSI driver dynamically provisions persistent volumes in Kubernetes, and it can integrate with AAD identity for per-share access control. This makes it the ideal choice for a single, shared filesystem that multiple pods across different nodes can access simultaneously.

Why this answer

Azure Files provides SMB and NFS file shares that can be mounted concurrently by multiple pods in Azure Kubernetes Service (AKS), meeting the requirement for persistent storage that is dynamically provisioned and accessible by multiple pods simultaneously. Azure Files supports the ReadWriteMany (RWX) access mode, which is essential for multi-pod access, and can be dynamically provisioned using a StorageClass with the `provisioner: file.csi.azure.com`.

Exam trap

The trap here is that candidates often confuse Azure Disk (RWO) with Azure Files (RWX) because both are block or file storage, but Azure Disk cannot be shared across pods, which is a critical distinction for multi-pod access scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage is an object storage solution that does not support standard file system semantics like concurrent multi-pod access via POSIX or SMB protocols; it is designed for unstructured data and accessed via REST APIs, not as a shared file system for pods. Option C is wrong because Azure Disk supports only the ReadWriteOnce (RWO) access mode, meaning it can be mounted by only a single pod at a time, which fails the requirement for multiple pods to access storage simultaneously. Option D is wrong because Azure NetApp Files, while supporting ReadWriteMany (RWX), is a premium enterprise file service that is overkill for this scenario and is not the standard or most cost-effective choice for AKS dynamic provisioning; Azure Files is the recommended and simpler solution for general multi-pod shared storage.

157
MCQhard

A company deploys Azure VNets in multiple regions and has on-premises data centers. They need to connect all VNets to each other and to on-premises sites using the Microsoft global network for optimal routing. They also want to simplify management by using a single orchestration interface. Which Azure service should they use?

A.Azure Virtual Network peering
B.Azure VPN Gateway with multi-site connections
C.Azure ExpressRoute Gateway
D.Azure Virtual WAN
AnswerD

Azure Virtual WAN is a Microsoft-managed, hub-and-spoke networking service that connects VNets and on-premises branches through a global mesh over the Microsoft backbone. Each regional virtual hub contains a scalable router that automatically computes routes between all attached VNets and remote sites, and hubs in different regions are automatically interconnected to provide any-to-any connectivity. It supports Site-to-Site VPN, Point-to-Site VPN, and ExpressRoute, all managed from a single pane of glass, which dramatically simplifies multi-region and multi-site administration. Because it centralizes routing, security policies (via Virtual WAN Secured Hubs and Azure Firewall Manager), and connectivity, it is the correct choice for a company with VNets in multiple regions plus on-premises locations.

Why this answer

Azure Virtual WAN (D) is correct because it provides a hub-and-spoke architecture that connects VNets across multiple regions and on-premises sites using the Microsoft global network for optimal routing. It offers a single orchestration interface (the Virtual WAN portal/API) to manage all connectivity, including site-to-site VPN, ExpressRoute, and VNet-to-VNet traffic, simplifying management and ensuring traffic traverses Microsoft's backbone rather than the public internet.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN with a simple VPN gateway or peering solution, overlooking that Virtual WAN is specifically designed for large-scale, multi-region, multi-site connectivity with a single management plane, while the other options are point solutions that require complex manual configuration to achieve the same result.

How to eliminate wrong answers

Option A is wrong because Azure Virtual Network peering only connects two VNets directly and does not provide a single orchestration interface for multiple VNets and on-premises sites; it also does not inherently use the Microsoft global network for routing between peered VNets in different regions (traffic may traverse the internet unless ExpressRoute or VPN is added). Option B is wrong because Azure VPN Gateway with multi-site connections can connect multiple on-premises sites to a single VNet, but it does not connect multiple VNets to each other natively (requires additional VPN gateways or peering) and lacks a unified orchestration interface for all connectivity. Option C is wrong because Azure ExpressRoute Gateway provides dedicated private connectivity to on-premises but only connects a single VNet to on-premises; it does not interconnect multiple VNets across regions or offer a single management interface for multi-site and multi-VNet topologies.

158
Multi-Selecthard

A company is designing hub-and-spoke networking. Spoke VNets must use a central Azure Firewall for outbound internet traffic. Which two configurations are required?

Select 2 answers
A.Enable public IP addresses on all workload VMs
B.Peer each spoke VNet with the hub VNet
C.Associate a route table to spoke subnets with a default route to the firewall private IP
D.Deploy a NAT gateway in every spoke subnet
AnswersB, C

VNet peering is the required control-plane foundation of the hub-spoke topology: it creates a private, low-latency bidirectional link between each spoke and the hub without traversing the internet, VPN tunnels, or ExpressRoute. Peering is not transitive, so the hub must be peered with every spoke to relay spoke-to-spoke and spoke-to-on-premises traffic through the hub firewall or gateway. When the hub hosts a VPN/ExpressRoute gateway, the spoke peering should also enable "Use remote gateways" so spoke traffic reaches on-premises through the hub without deploying its own gateway.

Why this answer

B is correct because VNet peering is required to establish connectivity between the spoke VNets and the hub VNet, enabling traffic to flow through the central Azure Firewall. Without peering, the spoke VNets would be isolated and unable to route traffic to the hub. C is correct because a route table with a default route (0.0.0.0/0) pointing to the firewall's private IP ensures that all outbound internet traffic from spoke subnets is forced through the firewall for inspection and control.

Exam trap

The trap here is that candidates often assume a NAT gateway or public IPs on VMs are needed for outbound internet, but the correct design forces all traffic through the firewall using UDRs and peering, not direct egress.

159
MCQeasy

A company needs to connect its on-premises data center to Azure for hybrid workloads. The connection must be private, dedicated, and provide guaranteed bandwidth. Which Azure service should they use?

A.Azure VPN Gateway
B.Azure ExpressRoute
C.Azure Virtual WAN
D.Azure Peering Service
AnswerB

Azure ExpressRoute provides a dedicated, private logical connection between on-premises infrastructure and Azure through a co-location facility or independent cloud exchange, entirely bypassing the public internet. It supports enterprise-grade SLAs, committed bandwidth tiers, and lower, consistent latency, making it the correct choice for workloads requiring guaranteed network performance. ExpressRoute circuits are resilient (active/passive or active/active) and can carry multiple VLANs.

Why this answer

Azure ExpressRoute provides a private, dedicated connection from on-premises to Azure, bypassing the public internet. It offers guaranteed bandwidth, higher reliability, and lower latency compared to VPN-based solutions, making it ideal for hybrid workloads requiring consistent performance.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway's 'dedicated tunnel' concept with true dedicated bandwidth, overlooking that VPNs still traverse the public internet and cannot guarantee performance, while ExpressRoute provides a physically isolated connection with contractual bandwidth guarantees.

How to eliminate wrong answers

Option A is wrong because Azure VPN Gateway uses encrypted tunnels over the public internet, which cannot provide dedicated bandwidth or guaranteed performance. Option C is wrong because Azure Virtual WAN is a networking orchestration service that can aggregate VPN, ExpressRoute, and SD-WAN connections, but it does not itself provide a dedicated, private connection with guaranteed bandwidth. Option D is wrong because Azure Peering Service is designed to optimize connectivity to Microsoft cloud services over the internet via partner ISPs, not to provide a dedicated private link with guaranteed bandwidth.

160
MCQmedium

A company has two on-premises data centers and an Azure subscription. They need to connect each data center to Azure with a private, high-bandwidth, and reliable connection. They also want a low-cost backup connection for each data center in case the primary connection fails. Which combination of connectivity options should they recommend?

A.A
B.B
C.C
D.D
AnswerA

This is the correct design because each data center establishes its own dedicated ExpressRoute circuit as the primary path, ensuring predictable, high-bandwidth, and low-latency connectivity to Azure with an SLA-backed private link. The site-to-site VPN for each data center acts as an IPsec-based backup over the internet, providing a cost-effective failover path that automatically kicks in if the ExpressRoute circuit fails. This active/passive redundancy model is a best practice for hybrid networking, as it avoids a single point of failure while keeping operational costs reasonable.

Why this answer

Azure ExpressRoute provides a private, high-bandwidth, and reliable connection from on-premises data centers to Azure, bypassing the public internet. To meet the low-cost backup requirement, Azure VPN Gateway (Site-to-Site VPN) offers a secure, encrypted connection over the internet as a failover path, which is significantly cheaper than a second ExpressRoute circuit. This combination ensures primary connectivity via ExpressRoute and cost-effective redundancy via VPN.

Exam trap

The trap here is that candidates often assume two ExpressRoute circuits are needed for redundancy, overlooking the cost-effective VPN backup option that still meets the 'low-cost' requirement while providing private connectivity only for the primary link.

How to eliminate wrong answers

Option B is wrong because using two ExpressRoute circuits for primary and backup is not low-cost; it doubles the recurring expense and is unnecessary for a backup path. Option C is wrong because using two Site-to-Site VPN connections for both primary and backup does not provide the high-bandwidth, reliable, private connection required; VPNs are internet-based and subject to latency and bandwidth limitations. Option D is wrong because using a single ExpressRoute circuit without any backup fails the requirement for a backup connection in case of failure.

161
MCQmedium

A company deploys a web application on Azure virtual machines (VMs) across multiple availability zones. The application needs to automatically distribute incoming HTTPS traffic, offload SSL/TLS termination, and provide session persistence. Additionally, the solution must include a Web Application Firewall (WAF) to protect against common web vulnerabilities. Which Azure load balancing solution should they use?

A.Azure Load Balancer
B.Azure Traffic Manager
C.Azure Application Gateway
D.Azure Front Door
AnswerC

Azure Application Gateway is a regional Layer 7 load balancer that routes HTTP/S traffic intelligently using URL paths, host headers, or other HTTP attributes, and it terminates SSL/TLS connections at the gateway to offload encryption from backend VMs. It provides cookie-based session affinity so a user's session sticks to the same server, and its built-in Web Application Firewall (WAF) blocks common exploits such as SQL injection and cross-site scripting. Autoscaling and availability-zone support make it a robust choice for production web workloads, delivering all the needed features in one regional service.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that can route HTTPS traffic, offload SSL/TLS termination, and provide session persistence (cookie-based affinity). It also natively integrates a Web Application Firewall (WAF) to protect against common web vulnerabilities like SQL injection and cross-site scripting.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway because both offer WAF and SSL offload, but Front Door is optimized for global multi-region traffic management, not for intra-region zone-resilient load balancing with session persistence, which is the specific requirement in this question.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL/TLS termination, session persistence based on application cookies, or provide a WAF. Option B is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes traffic at the DNS level (Layer 3/4) and does not handle SSL/TLS termination, session persistence, or WAF capabilities. Option D is wrong because Azure Front Door is a global Layer 7 load balancer and CDN that can offload SSL and provide WAF, but it is designed for global HTTP(S) traffic distribution across regions, not for intra-region multi-zone distribution with session persistence; Application Gateway is the appropriate choice for regional, zone-resilient deployments.

162
MCQmedium

You are designing a solution to store sensitive documents in Azure Blob Storage. The data must be encrypted at rest and access must be audited. You need to ensure that the encryption keys are managed by your organization and that access to the keys is logged. Which combination of Azure services should you use?

A.Azure Storage encryption with customer-managed keys in Azure Key Vault and Azure Monitor
B.Azure Disk Encryption with Azure Key Vault
C.Azure Storage encryption with Microsoft-managed keys and Azure Monitor
D.Azure Information Protection and Azure Sentinel
AnswerA

Azure Storage encryption always encrypts data at rest, but with customer-managed keys (CMK) in Azure Key Vault, you control key rotation, permissions, and lifecycle, which is essential for sensitive documents. Enabling Key Vault diagnostics and routing those logs to Azure Monitor provides auditable access trails, letting you detect unauthorized key usage. This combination meets compliance requirements that demand both cryptographic control and monitoring.

Why this answer

Azure Storage encryption with customer-managed keys in Azure Key Vault meets the requirement for organization-managed encryption keys, while Azure Monitor (specifically the Azure Activity Log or diagnostic settings) captures access logs for both the storage account and Key Vault operations, enabling full auditability of key usage and data access.

Exam trap

The trap here is that candidates often confuse Azure Disk Encryption (which encrypts VM disks) with Azure Storage encryption (which encrypts blob data), leading them to select Option B despite it not addressing blob storage encryption or audit logging requirements.

How to eliminate wrong answers

Option B is wrong because Azure Disk Encryption encrypts VM disks, not Azure Blob Storage data, and does not provide the required storage-level encryption or audit logging for blob access. Option C is wrong because Microsoft-managed keys do not allow your organization to manage the encryption keys, violating the requirement for organization-managed keys. Option D is wrong because Azure Information Protection is a classification and labeling service, not a storage encryption solution, and Azure Sentinel is a SIEM that ingests logs but does not itself provide encryption key management or storage encryption.

163
Multi-Selecthard

You are designing a backup and disaster recovery strategy for a SQL Server database hosted on an Azure virtual machine. The database is critical and has a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 4 hours. Which TWO services should you include in the solution?

Select 2 answers
A.Azure Backup
B.Azure SQL Database backup
C.Azure Files
D.Azure Site Recovery
E.Azure SQL Database auto-failover groups
AnswersA, D

Azure Backup satisfies the 15-minute RPO by capturing SQL Server transaction log backups every 15 minutes through the workload-aware backup extension, and restores within the 4-hour RTO. It provides the granular, point-in-time recovery the database demands.

Why this answer

Azure Backup (A) is correct because it provides application-consistent, agent-based backups of SQL Server running on an Azure VM, supporting frequent log backups that can meet a 15-minute RPO and enabling restore within the 4-hour RTO. Azure Site Recovery (D) is correct because it replicates the entire VM (including the SQL Server instance and OS) to a secondary region or target, enabling orchestrated failover and recovery of the virtual machine within the RTO window. Azure SQL Database backup (B) does not apply because the database is hosted on an Azure VM (IaaS), not as an Azure SQL Database (PaaS) service.

Azure Files (C) is a managed SMB/NFS file share service and is not a backup or disaster recovery mechanism for a SQL Server VM. Azure SQL Database auto-failover groups (E) are also a PaaS feature for Azure SQL Database/Managed Instance and cannot be used for SQL Server on an Azure VM.

Exam trap

The trap here is confusing PaaS services (Azure SQL Database backup and auto-failover groups) with IaaS solutions for SQL Server on Azure VMs, leading candidates to select options that are incompatible with the stated hosting model.

164
MCQhard

An organization is designing a storage solution for Azure VMs running a database that requires low latency and high IOPS. The data is critical and must be durable with automatic replication across multiple datacenters in the same region. Which Azure managed disk type and redundancy option should they choose?

A.Standard SSD with GRS
B.Premium SSD with ZRS
C.Ultra Disk with LRS
D.Premium SSD v2 with LRS
AnswerB

Premium SSDs provide high IOPS (up to 20,000 per disk, depending on size) and low single-digit millisecond latencies, ideal for I/O-intensive workloads. With ZRS, the disk synchronously writes three replicas across three Azure availability zones within the same region, so the VM can survive an entire datacenter or zone failure while retaining the performance characteristics needed. This combination is directly supported for managed disks and precisely satisfies the stated requirement for high performance and replication across multiple datacenters.

Why this answer

Premium SSD with ZRS is correct because the database requires low latency and high IOPS, which Premium SSD provides, and ZRS (Zone-Redundant Storage) automatically replicates data synchronously across three Azure availability zones within the same region, ensuring durability and high availability without the cross-region latency of GRS.

Exam trap

The trap here is that candidates often confuse ZRS with GRS, assuming that 'redundancy across multiple datacenters' requires geo-replication, but ZRS provides intra-region zone redundancy without the latency penalty of asynchronous geo-replication.

How to eliminate wrong answers

Option A is wrong because Standard SSD does not deliver the low latency and high IOPS required for a database workload, and GRS (Geo-Redundant Storage) replicates data asynchronously to a paired region, not within the same region, adding latency and complexity. Option C is wrong because Ultra Disk offers extreme performance but only supports LRS (Locally Redundant Storage), which replicates data within a single datacenter and does not provide automatic replication across multiple datacenters in the same region. Option D is wrong because Premium SSD v2, while offering high performance, also only supports LRS, lacking the cross-zone replication needed for durability across multiple datacenters within the same region.

165
MCQmedium

You are designing a backup and disaster recovery strategy for an Azure SQL Database instance that runs a critical business application. The database is 500 GB and experiences high transaction rates. The recovery point objective (RPO) is 1 minute and recovery time objective (RTO) is 1 hour. What should you recommend?

A.Enable geo-redundant backup storage and use geo-restore in the secondary region.
B.Configure automated backups with locally-redundant storage (LRS) and enable point-in-time restore.
C.Configure active geo-replication to a secondary region in the same Azure geography.
D.Export the database to a bacpac file daily and store it in Azure Blob Storage.
AnswerC

Active geo-replication continuously replicates transactions from a primary database to one or more readable secondary databases in a paired or chosen secondary region, achieving an RPO of typically 5 seconds and an RTO of under 1 minute when paired with automatic failover groups. Because the secondary is always online and kept nearly synchronized, a failover merely changes the role and does not require copying or restoring data. This is the only option that satisfies both the aggressive 1-minute RPO and the minutes-level RTO while also providing cross-region redundancy.

Why this answer

Active geo-replication for Azure SQL Database provides a continuously synchronized readable secondary replica in a different Azure region, enabling failover with an RPO of 1 minute (due to synchronous replication) and an RTO of 1 hour (since failover is manual or can be automated). This meets the critical business application's requirements for high transaction rates and low data loss.

Exam trap

The trap here is that candidates often confuse geo-redundant backup storage (which provides backup redundancy but not real-time replication) with active geo-replication (which provides near-real-time data synchronization for DR), leading them to choose Option A despite its insufficient RPO.

How to eliminate wrong answers

Option A is wrong because geo-redundant backup storage (RA-GRS) only protects against regional disasters by restoring from the last full/differential/log backup, which can have an RPO of up to 12 hours for log backups, far exceeding the 1-minute requirement. Option B is wrong because locally-redundant storage (LRS) for automated backups does not provide any cross-region disaster recovery, so a regional outage would result in complete data loss. Option D is wrong because exporting to a bacpac file daily provides an RPO of up to 24 hours, which is far too high, and the export process can be slow and disruptive for a 500 GB database with high transaction rates.

166
MCQmedium

A company has multiple Azure virtual networks (VNets) in different regions connected via VNet peering. They also have an on-premises data center connected to Azure via ExpressRoute. They need to provide internet-bound traffic from all Azure VNets through a single, centralized network virtual appliance (NVA) in the hub VNet for security inspection. They also need to ensure that traffic between VNets and on-premises is routed optimally without going through the internet. Which Azure solution should they implement?

A.Implement VNet peering with user-defined routes (UDRs) to force traffic through the NVA
B.Use Azure Firewall in each VNet to inspect traffic locally
C.Deploy an Azure Virtual WAN with a secured hub (Azure Firewall) and route traffic through it
D.Use Azure Route Server to propagate routes to all VNets
AnswerC

Azure Virtual WAN with a secured hub (Azure Firewall) is the correct choice because it provides automatic transitive routing between all connected VNets across regions, so you don't need to manage UDRs or individual peerings. The Azure Firewall in the secured hub centrally inspects all traffic—both VNet-to-VNet and branch-to-VNet—and routing intent can be configured to ensure that traffic is always forced through the firewall for inspection. This architecture scales naturally to many VNets and regions, integrates with ExpressRoute for hybrid connectivity, and centralizes security policy management, satisfying every stated requirement.

Why this answer

Azure Virtual WAN with a secured hub (Azure Firewall) provides a centralized, managed routing architecture that meets all requirements. It automatically routes internet-bound traffic from all VNets through the Azure Firewall in the hub for security inspection, while also ensuring optimal routing between VNets and on-premises via ExpressRoute without traversing the internet. This solution eliminates the need for manual UDRs and complex NVA management, as Virtual WAN handles routing and security centrally.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN with simple VNet peering or assume that Azure Route Server alone can provide centralized security inspection, but Virtual WAN is the only solution that combines centralized routing, security, and automatic propagation across multiple regions.

How to eliminate wrong answers

Option A is wrong because VNet peering with UDRs to force traffic through an NVA requires complex manual route management and does not scale well across multiple regions; it also does not inherently optimize on-premises routing without additional configuration. Option B is wrong because deploying Azure Firewall in each VNet inspects traffic locally, not centrally, which violates the requirement for a single, centralized inspection point and increases operational overhead. Option D is wrong because Azure Route Server propagates routes between NVAs and VNets but does not provide centralized internet-bound traffic inspection or force traffic through a single NVA; it is designed for dynamic route exchange, not security inspection.

167
MCQeasy

A company deploys a web application on Azure VMs across availability zones. They need to distribute HTTPS traffic, offload SSL termination, and maintain session persistence. They do not require traffic inspection. Which Azure load balancing solution should they use?

A.Azure Application Gateway v2.
B.Azure Load Balancer (Standard).
C.Azure Traffic Manager.
D.Azure Front Door.
AnswerA

Azure Application Gateway v2 is the correct choice because it operates as a regional Layer 7 load balancer, directly supporting HTTPS termination, cookie-based session persistence (affinity), and HTTP health probes for backend VMs. Its v2 SKU is designed to span availability zones, enabling zone-redundant deployment across VM sets within a single region. Unlike global services, it stays in the region, minimizing latency while providing all required web-layer capabilities.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that supports HTTPS traffic distribution, SSL termination (offloading the decryption burden from backend VMs), and session persistence via cookie-based affinity. It meets all requirements without needing traffic inspection, which is optional and can be disabled.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming any load balancer can handle SSL termination, but only Layer 7 solutions like Application Gateway or Front Door can offload SSL and maintain session persistence at the application layer.

How to eliminate wrong answers

Option B (Azure Load Balancer Standard) is wrong because it operates at Layer 4 (TCP/UDP) and cannot perform SSL termination or application-layer session persistence; it only distributes traffic based on IP and port. Option C (Azure Traffic Manager) is wrong because it is a DNS-based global traffic router that does not handle HTTPS traffic directly, SSL termination, or session persistence at the application layer. Option D (Azure Front Door) is wrong because it is a global Layer 7 service with built-in WAF and traffic inspection capabilities, which is unnecessary here and adds complexity; it also requires a custom domain for SSL termination, whereas Application Gateway v2 is a regional solution better suited for this scenario.

168
MCQmedium

You are designing a disaster recovery solution for an Azure IaaS workload. The application runs on Azure VMs in a single region and requires a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 4 hours. Which of the following is the most cost-effective approach to meet these requirements?

A.Configure geo-redundant storage (GRS) for the VM disks and manually attach them to new VMs in the secondary region.
B.Use Azure Front Door with a back-end pool containing VMs in both regions, and configure health probes to route traffic on failure.
C.Deploy Azure Site Recovery to replicate VMs to the secondary region with a replication policy that meets the RPO and RTO.
D.Use Azure Backup to back up VMs to a Recovery Services vault in the secondary region and perform restore during failover.
AnswerC

Azure Site Recovery provides asynchronous, continuous block-level replication with recovery points as frequent as every 30 seconds, comfortably satisfying the 15-minute RPO, while orchestrated failover to the paired region meets the 4-hour RTO. Unlike active-active or hot-standby designs, it keeps secondary-region compute costs near zero until failover, making it the most cost-effective fit.

Why this answer

Azure Site Recovery (ASR) provides orchestrated replication of Azure VMs to a secondary region with configurable RPO (as low as 30 seconds) and supports automated failover, meeting the 15-minute RPO and 4-hour RTO requirements. It is the most cost-effective because it replicates only changed blocks and does not require running standby VMs, unlike multi-region active deployments.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for archival and long-term recovery) with Azure Site Recovery (which is for replication and rapid failover), leading them to choose Option D despite its inadequate RPO and RTO for disaster recovery scenarios.

How to eliminate wrong answers

Option A is wrong because manually attaching GRS-based disks to new VMs in the secondary region cannot guarantee a 15-minute RPO (GRS replication is asynchronous with a typical lag of hours) and the manual process would exceed the 4-hour RTO. Option B is wrong because Azure Front Door is a global load balancer for web traffic, not a disaster recovery replication tool; it does not replicate VM state or data, so it cannot meet RPO/RTO for IaaS workloads. Option D is wrong because Azure Backup is designed for long-term retention and point-in-time restores, with typical RPO of 24 hours for daily backups and restore times that can exceed 4 hours, making it unsuitable for the required 15-minute RPO and 4-hour RTO.

169
MCQeasy

A company deploys a web application on multiple Azure virtual machines (VMs) in a single region. The application receives HTTP and HTTPS traffic. They need to distribute the traffic across the VMs, offload SSL/TLS termination, and ensure that client requests from the same user session are always sent to the same backend VM (session persistence). Additionally, they need to route requests based on URL paths (e.g., /api/* to one pool, /images/* to another). Which Azure load balancing solution should they use?

A.Azure Load Balancer
B.Azure Application Gateway
C.Azure Front Door
D.Azure Traffic Manager
AnswerB

Azure Application Gateway is a layer-7 load balancer specifically designed for HTTP(S) traffic. It supports SSL termination (and end-to-end SSL), cookie-based session affinity, URL path-based routing to different backend pools, and integrates with the Web Application Firewall (WAF). This makes it the correct choice for the company's stated requirements, as it directly handles application-level routing and persistence without the complexity of a global service.

Why this answer

Azure Application Gateway is the correct choice because it is a layer-7 load balancer that supports SSL/TLS termination, URL path-based routing, and session persistence (sticky sessions) via cookies. These features directly match the requirements for distributing HTTP/HTTPS traffic, offloading SSL, routing requests based on URL paths, and maintaining user session affinity to the same backend VM.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (layer 4) with Application Gateway (layer 7), assuming any load balancer can handle SSL termination and URL routing, but only layer-7 solutions like Application Gateway provide these application-level features.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at layer 4 (TCP/UDP) and cannot perform SSL/TLS termination, URL path-based routing, or session persistence based on HTTP cookies. Option C is wrong because Azure Front Door is a global layer-7 load balancer and CDN designed for multi-region traffic distribution, not for routing within a single region, and it does not support URL path-based routing to separate backend pools in the same region. Option D is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that operates at layer 3/4 and cannot offload SSL/TLS, route based on URL paths, or provide session persistence.

170
MCQeasy

A company runs a web application on Azure VMs in a single region. The application must scale out automatically based on CPU utilization. The VMs are behind an Azure Load Balancer. Which Azure service should they use to automatically add or remove VMs based on demand?

A.Azure Virtual Machine Scale Sets
B.Azure App Service
C.Azure Functions
D.Azure Batch
AnswerA

Azure Virtual Machine Scale Sets (VMSS) is the correct choice because it directly manages a group of identical VMs as a single pool, providing automatic horizontal scaling based on performance metrics like CPU or memory utilization, custom metrics, or scheduled times. It integrates natively with Azure Load Balancer and Application Gateway to distribute incoming web traffic across the VM instances, making it ideal for a web application hosted on Azure VMs. VMSS also supports manual scaling, automatic scale rules, and health monitoring to replace unhealthy instances, ensuring high availability and elastic capacity for fluctuating web workloads.

Why this answer

Azure Virtual Machine Scale Sets (VMSS) is the correct service because it provides automatic scaling of identical VM instances based on metrics like CPU utilization. When you configure an autoscale rule on a VMSS, it automatically adds or removes VM instances behind the Azure Load Balancer, ensuring the application scales out or in based on demand without manual intervention.

Exam trap

The trap here is that candidates often confuse Azure App Service's autoscale feature (which scales the number of App Service instances, not VMs) with the requirement to scale VMs behind a load balancer, leading them to select App Service instead of VMSS.

How to eliminate wrong answers

Option B (Azure App Service) is wrong because it is a platform-as-a-service (PaaS) offering for web apps, not a service that manages VMs behind a load balancer; it does not allow you to run custom VMs with full control over the OS. Option C (Azure Functions) is wrong because it is a serverless compute service for event-driven code, not designed for long-running web applications on VMs, and it does not integrate with Azure Load Balancer for VM-level scaling. Option D (Azure Batch) is wrong because it is a job-scheduling and compute-management service for large-scale parallel and HPC workloads, not for automatically scaling VMs behind a load balancer based on CPU utilization.

171
MCQeasy

A company plans to migrate on-premises SQL Server databases to Azure. They need to minimize changes to existing applications and want to use the latest features of SQL Server. Which Azure data service should they use?

A.SQL Server on Azure Virtual Machines
B.Azure SQL Managed Instance
C.Azure SQL Database
D.Azure Cosmos DB
AnswerB

As a PaaS offering, Azure SQL Managed Instance delivers near-virtual-machine-level compatibility with instance-scoped features such as SQL Server Agent, linked servers, and CLR, allowing most databases to be migrated with minimal or no application changes. It also offloads administrative tasks—like patching, backups, and availability—to Azure while keeping the database in a VNet for isolated networking.

Why this answer

Azure SQL Managed Instance is the correct choice because it provides near 100% compatibility with on-premises SQL Server, enabling a lift-and-shift migration with minimal application changes. It also supports the latest SQL Server features, such as native JSON support, temporal tables, and intelligent query processing, while offloading infrastructure management to Azure.

Exam trap

The trap here is that candidates often choose Azure SQL Database thinking it is the most modern PaaS option, but they overlook the requirement to minimize application changes, which SQL Managed Instance satisfies by offering the highest compatibility with on-premises SQL Server.

How to eliminate wrong answers

Option A is wrong because SQL Server on Azure Virtual Machines requires you to manage the VM, OS, and SQL Server patches, which does not minimize changes but adds operational overhead, and it does not provide the latest SQL Server features automatically (you must manually upgrade). Option C is wrong because Azure SQL Database is a PaaS offering that may require application changes due to differences in T-SQL syntax, database scoped configurations, and lack of instance-level features like SQL Agent jobs, cross-database queries, and CLR integration. Option D is wrong because Azure Cosmos DB is a NoSQL database service that does not support SQL Server features, T-SQL, or relational schemas, requiring significant application rewrites.

172
MCQmedium

You are designing a solution to securely store and manage secrets for multiple applications deployed in Azure. The solution must support automated rotation of secrets and provide audit logging. Which Azure service should you use?

A.Microsoft Entra ID application registration
B.Azure App Service Key Vault references
C.Azure Key Vault with managed identity and rotation policy
D.Azure Automation with PowerShell runbooks
AnswerC

Azure Key Vault with a managed identity and an enabled rotation policy is the correct choice because it natively supports secret lifecycle management: the rotation policy automatically creates new versions of the secret on a schedule or by proximity to expiry, the managed identity provides secure, passwordless authentication for workloads to access those secrets without embedding credentials, and Key Vault's diagnostic settings enable audit logging of all secret operations for compliance and monitoring.

Why this answer

Azure Key Vault with a managed identity and a rotation policy is the correct choice because it provides a centralized, secure store for secrets, supports automated rotation via built-in policies or custom logic, and integrates with Azure Monitor for audit logging. Managed identities eliminate the need for hard-coded credentials, and the rotation policy ensures secrets are automatically updated without manual intervention.

Exam trap

The trap here is that candidates often confuse 'Key Vault references' (which only retrieve secrets at runtime) with the full secret management lifecycle (which includes automated rotation and audit logging), leading them to select Option B instead of the comprehensive solution in Option C.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID application registration is used for identity and access management, not for storing secrets or automating their rotation; it lacks a built-in secret rotation mechanism and audit logging for secret lifecycle events. Option B is wrong because Azure App Service Key Vault references are a feature that allows an app to reference secrets from Key Vault at runtime, but they do not provide automated rotation or audit logging themselves—they rely on Key Vault for those capabilities. Option D is wrong because Azure Automation with PowerShell runbooks can be used to rotate secrets, but it is not a dedicated secret management service; it requires custom scripting, lacks native audit logging integration, and does not provide the same level of secure storage and access policies as Key Vault.

173
MCQmedium

A company plans to deploy a multi-tier application on Azure. The web tier requires SSL termination and health probes. The application tier must be isolated from the internet. The database tier requires high availability. They want to minimize administrative overhead and use Azure native services. Which architecture should they recommend?

A.Azure Application Gateway for web tier, Azure Load Balancer (internal) for application tier, and Azure SQL Database with active geo-replication
B.Azure Front Door for web tier, Azure Load Balancer for database tier, and SQL Server on Azure VMs with Always On
C.Azure Traffic Manager for web tier, Azure Application Gateway for database tier, and Azure SQL Database with failover groups
D.Azure Application Gateway for web tier, Azure Load Balancer (internal) for application tier, and Azure SQL Database with geo-restore
AnswerA

Azure Application Gateway is the correct ingress for the web tier because it performs L7 functions such as SSL termination, cookie affinity, and WAF rules while routing HTTP traffic to backend web apps. An internal Standard Load Balancer then distributes L4 network traffic among application-tier VMs, keeping that tier private from the internet. Azure SQL Database with active geo-replication maintains a readable secondary in a different Azure region, which supports a low-RPO manual or managed failover for business continuity. Together these services align with a typical multi-tier architecture and provide both high availability and regional resiliency.

Why this answer

Azure Application Gateway provides SSL termination and health probes for the web tier, an internal Azure Load Balancer isolates the application tier from the internet, and Azure SQL Database with active geo-replication offers high availability with automatic failover, minimizing administrative overhead by using PaaS services.

Exam trap

The trap here is that candidates often confuse Azure Front Door or Traffic Manager with Application Gateway for SSL termination and health probes, or assume that geo-restore provides the same automatic high availability as active geo-replication, leading them to choose options that either lack required features or increase administrative overhead.

How to eliminate wrong answers

Option B is wrong because Azure Front Door is a global load balancer for web traffic, but it does not natively provide SSL termination for a single-region web tier, and using Azure Load Balancer for the database tier is inappropriate as it does not offer database-level high availability; SQL Server on Azure VMs with Always On requires significant administrative overhead. Option C is wrong because Azure Traffic Manager is a DNS-based traffic router that does not perform SSL termination or health probes for the web tier, and Azure Application Gateway is not designed for the database tier; Azure SQL Database with failover groups is a valid HA option but the web tier architecture is incorrect. Option D is wrong because Azure SQL Database with geo-restore does not provide automatic high availability; it requires manual restore from a geo-redundant backup, which does not meet the requirement for minimal administrative overhead and active failover.

174
MCQeasy

You need to design a storage solution for an application that stores large amounts of unstructured data that is accessed frequently for the first 30 days, then rarely after that. Compliance requirements mandate that data be retained for 7 years. Which of the following is the most cost-effective storage solution?

A.Use Azure Files with snapshots and keep files in the Premium tier for 30 days, then move to Standard tier.
B.Use Azure Managed Disks with read-only snapshots and delete snapshots after 7 years.
C.Use Azure Blob Storage with lifecycle management to transition blobs from Hot to Cool to Archive tiers.
D.Store all data in Blob Storage Hot tier and delete after 7 years.
AnswerC

Azure Blob Storage is purpose-built for massive amounts of unstructured object data, offering essentially limitless scale and REST-based access. Lifecycle management lets you define rules to automatically move blobs from Hot to Cool after a set number of days based on last modification, and then from Cool to Archive after a longer period, which optimizes cost while preserving all data. Archive tier provides the lowest storage price for rarely accessed data, and with rehydration you can still retrieve it when needed, making this the most scalable and cost-effective design for long-term retention.

Why this answer

Azure Blob Storage lifecycle management allows you to automatically transition blobs from Hot to Cool after 30 days (once the initial frequent access period ends), and then to Archive after an additional period of low access (e.g., another 30 days) to meet the 7-year retention requirement at the lowest cost. The Archive tier provides the cheapest storage for rarely accessed data, while Hot and Cool tiers optimize for the initial high-access period.

Exam trap

The trap here is that candidates often choose Azure Files or Managed Disks because they associate 'storage' with file shares or disks, but Blob Storage's tiered lifecycle management is the only option that provides automated, cost-optimized transitions for unstructured data with long-term retention.

How to eliminate wrong answers

Option A is wrong because Azure Files Premium tier is designed for low-latency, high-performance workloads (e.g., SQL Server, file shares) and is not cost-effective for large-scale unstructured data; moving to Standard tier still incurs higher costs than Blob Storage tiers, and snapshots do not provide automated tiering. Option B is wrong because Azure Managed Disks are block-level storage for VMs, not optimized for unstructured data; read-only snapshots are incremental and billed per stored data, and deleting them after 7 years does not address the need for cost-effective tiering during the retention period. Option D is wrong because storing all data in the Hot tier for 7 years is significantly more expensive than using Cool and Archive tiers for rarely accessed data, violating the cost-effectiveness requirement.

175
MCQeasy

A company has an on-premises data center and wants to connect it to Azure with a dedicated, private network connection that is not routed over the public internet. They also need a higher service-level agreement (SLA) compared to VPN-based connections. Which Azure service should they use?

A.Azure VPN Gateway
B.Azure ExpressRoute
C.Azure Bastion
D.Azure Virtual WAN
AnswerB

Azure ExpressRoute establishes a logical private connection to Azure through a connectivity provider or direct peering, with traffic that never traverses the public internet. It uses BGP sessions over dedicated or co-located circuits, offering enterprise-grade reliability, high bandwidth (up to 100 Gbps), and native geographic redundancy across peering locations. The 99.95% SLA for dedicated circuits plus predictable latency make it the correct choice for a dedicated, private hybrid connection.

Why this answer

Azure ExpressRoute provides a dedicated, private connection from on-premises to Azure that bypasses the public internet, ensuring lower latency, higher reliability, and a 99.95% SLA (for dedicated circuits) compared to VPN-based connections. This meets the requirement for a private network connection with a higher SLA than VPN Gateway, which relies on internet-based IPSec tunnels with a 99.9% SLA.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN as a direct replacement for ExpressRoute, but Virtual WAN is a management overlay that still requires ExpressRoute or VPN as the underlying transport, not a dedicated private connection itself.

How to eliminate wrong answers

Option A (Azure VPN Gateway) is wrong because it uses IPSec tunnels over the public internet, which does not provide a dedicated private connection and has a lower SLA (99.9%) than ExpressRoute. Option C (Azure Bastion) is wrong because it is a PaaS service for secure RDP/SSH access to Azure VMs via the browser, not a hybrid connectivity solution between on-premises and Azure. Option D (Azure Virtual WAN) is wrong because it is a networking service that aggregates branch connectivity, but it still requires an underlying connectivity method (VPN or ExpressRoute) to provide the dedicated private link; by itself, it does not offer a dedicated private connection or the higher SLA specified.

176
Multi-Selecteasy

Which TWO Azure services can be used to implement a serverless event-driven architecture that processes messages from a queue and stores results in a database? (Choose two.)

Select 2 answers
A.Azure Logic Apps
B.Azure Event Grid
C.Azure Service Bus
D.Azure Functions
E.Azure Batch
AnswersA, D

Azure Logic Apps is a serverless workflow integration service that can be triggered directly by queue messages from Service Bus or Storage queues. It provides a visual designer with hundreds of connectors, enabling you to orchestrate multi-step workflows across different systems without writing code. Because it runs on demand and scales automatically per execution, it is a valid serverless processing solution for queue-based workloads.

Why this answer

Azure Logic Apps is correct because it provides a serverless workflow engine that can be triggered by a queue (e.g., Azure Service Bus queue or Storage queue) and then process messages using built-in connectors to write results into a database like Azure SQL Database or Cosmos DB. It supports event-driven execution without managing infrastructure, making it ideal for orchestrating message processing and persistence.

Exam trap

The trap here is that candidates often confuse Azure Event Grid or Service Bus as compute services that can process messages and store results, when in reality they are only messaging/event routing layers that require a separate compute service (like Functions or Logic Apps) to perform the actual processing and database writes.

177
MCQhard

A large enterprise is designing a data analytics platform in Azure that will ingest terabytes of data daily from multiple sources, including IoT devices, social media feeds, and internal databases. The data must be stored in a raw format for future processing, and then transformed and aggregated for reporting. The company requires low-latency querying for real-time dashboards and the ability to run complex batch analytics using Spark. The solution must also provide a unified data governance layer for cataloging and lineage tracking. Which combination of Azure services should the company choose to meet all these requirements with minimal operational overhead?

A.Azure Cosmos DB, Azure Stream Analytics, and Azure Analysis Services
B.Azure Blob Storage, Azure HDInsight, and Azure Data Factory
C.Azure SQL Database, Azure Databricks, and Azure Data Catalog
D.Azure Data Lake Storage, Azure Synapse Analytics, and Microsoft Purview
AnswerD

Azure Data Lake Storage Gen2 supplies the required raw landing zone: it combines Blob scalability with a hierarchical namespace and granular POSIX ACLs, enabling governed storage from bytes to petabytes. Azure Synapse Analytics is the analytical core, offering serverless SQL to query raw ADLS files in place, dedicated pools for high-performance warehouse workloads, and built-in Spark for batch transformations--all without separate infrastructure to manage. Microsoft Purview completes the platform by automatically scanning these assets, classifying sensitive data, and capturing end-to-end lineage so downstream analytics can be audited and trusted. Together these services deliver storage, real-time and historical query, batch processing, and governance in one integrated solution.

Why this answer

Azure Data Lake Storage provides scalable, cost-effective raw storage for terabytes of daily data, Azure Synapse Analytics offers both low-latency querying for real-time dashboards and Spark-based batch analytics, and Microsoft Purview delivers a unified data governance layer with cataloging and lineage tracking. This combination minimizes operational overhead by integrating storage, compute, and governance into a single, managed platform.

Exam trap

The trap here is that candidates may choose Azure HDInsight or Azure Databricks for Spark processing, overlooking that Azure Synapse Analytics natively integrates Spark with SQL and governance via Purview, reducing operational overhead compared to managing separate clusters.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL database optimized for transactional workloads, not for storing terabytes of raw data or running complex batch analytics with Spark, and Azure Analysis Services is a semantic model layer that does not provide data governance or lineage tracking. Option B is wrong because Azure HDInsight requires manual cluster management and lacks native low-latency querying for real-time dashboards, and Azure Data Factory is an orchestration tool that does not offer unified governance or cataloging. Option C is wrong because Azure SQL Database is a relational database not designed for raw data storage at terabyte scale or Spark-based batch analytics, and Azure Data Catalog is a legacy service that has been superseded by Microsoft Purview, lacking advanced lineage tracking.

178
MCQmedium

A company is deploying a web application on Azure App Service. The application must authenticate users with their Microsoft Entra ID credentials. The development team wants to use the Microsoft Authentication Library (MSAL) for authentication. Which App Service authentication feature should they use to simplify integration?

A.Use Application Insights to capture authentication logs
B.Use Azure API Management to handle authentication
C.Use Azure AD B2C for identity management
D.Configure the App Service authentication / authorization feature to use Microsoft Entra ID
AnswerD

Configuring the App Service authentication/authorization feature, also known as Easy Auth, is the correct approach because it natively integrates with Microsoft Entra ID and handles sign-in, token validation, and session management without custom code. It runs as a middleware layer in the platform, redirects unauthenticated users to Entra ID, and injects user claims into the application. This is the simplest, most secure method for an internal enterprise app.

Why this answer

The App Service authentication / authorization feature (also known as Easy Auth) provides a built-in, code-free integration with Microsoft Entra ID. By enabling this feature and configuring it to use Microsoft Entra ID, the App Service automatically handles token validation, session management, and redirects, allowing the development team to use MSAL on the client side for sign-in without writing server-side authentication logic.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing Azure API Management or Azure AD B2C, not realizing that App Service's built-in authentication feature is specifically designed to simplify integration with Microsoft Entra ID and MSAL without additional infrastructure.

How to eliminate wrong answers

Option A is wrong because Application Insights is a monitoring and diagnostics service that captures telemetry data (including authentication logs), but it does not handle authentication or simplify integration with MSAL. Option B is wrong because Azure API Management is an API gateway that can enforce authentication policies, but it is an additional layer that adds complexity and is not the simplest way to integrate MSAL with App Service. Option C is wrong because Azure AD B2C is designed for customer-facing identity management with social and local accounts, not for authenticating users with their existing Microsoft Entra ID credentials in a corporate scenario.

179
MCQeasy

You need to design a monitoring solution for a set of Azure virtual machines running a business-critical application. The solution must provide centralized log management, enable real-time analysis of security events, and support custom alerts for anomalous behavior. Which Azure service should you use?

A.Azure Log Analytics
B.Microsoft Defender for Cloud
C.Azure Monitor
D.Microsoft Sentinel
AnswerD

Microsoft Sentinel is a cloud-native, scalable SIEM (Security Information and Event Management) solution that builds on Azure Log Analytics to provide centralized log management, analysis, and custom alerting across your entire digital estate. It ingests data from hundreds of sources—Microsoft services, third-party firewalls, cloud workloads, and on-premises systems—then uses KQL queries, analytics rules, and machine learning to detect threats, and its SOAR capabilities automate incident response. Sentinel also offers entity behavior analytics and integrated threat intelligence, making it the only option listed that meets the stated requirement for a monitoring solution that includes log management, security analysis, and custom alerts.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that provides centralized log management, real-time security event analysis, and built-in support for custom analytics rules to detect anomalous behavior. Unlike Azure Monitor or Log Analytics, Sentinel is specifically designed for security-focused monitoring and can ingest logs from multiple sources, including Azure VMs, and use machine learning to identify threats.

Exam trap

The trap here is that candidates often confuse Azure Monitor (a general monitoring tool) with Microsoft Sentinel (a dedicated SIEM), failing to recognize that the question's emphasis on 'security events' and 'anomalous behavior' points to a security-specific solution, not just log aggregation.

How to eliminate wrong answers

Option A is wrong because Azure Log Analytics is a log storage and query service that lacks native SIEM capabilities such as real-time security event correlation and automated response; it requires additional services like Sentinel to provide security monitoring. Option B is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection tool that focuses on vulnerability assessment and security recommendations, not centralized log management or custom alerting for anomalous behavior across all logs. Option C is wrong because Azure Monitor is a platform monitoring service for performance and availability metrics, not a SIEM; it does not provide real-time security event analysis or built-in threat detection rules.

180
MCQeasy

A company plans to deploy a stateless web application on Azure virtual machines. They want to ensure that the application remains available in the event of a hardware failure within a single Azure datacenter. The VMs must be placed in a way that ensures they are on different physical servers and racks, but are still within the same datacenter. Which deployment strategy should they use?

A.Deploy the VMs in an Availability Set.
B.Deploy the VMs in different Availability Zones.
C.Deploy the VMs in a single Virtual Machine Scale Set with a large instance count.
D.Deploy each VM in a separate resource group.
AnswerA

An Availability Set logically groups VMs so Azure distributes them across multiple fault domains (racks with independent power and network) and update domains (groups that are rebooted sequentially during planned maintenance). This contains hardware failures and maintenance events to a subset of the VMs, keeping your stateless web app reachable. It is the correct choice because the requirement is to protect against hardware failure within a single Azure datacenter.

Why this answer

An Availability Set ensures that VMs are distributed across multiple fault domains (different physical servers, racks, and network switches) and update domains within a single Azure datacenter. This protects against hardware failures in that datacenter by guaranteeing that not all VMs are affected by the same local failure, while keeping them in the same datacenter for low-latency communication.

Exam trap

The trap here is that candidates often confuse Availability Zones (which span multiple datacenters) with Availability Sets (which operate within a single datacenter), leading them to select the zone-based option when the question explicitly requires staying within the same datacenter.

How to eliminate wrong answers

Option B is wrong because Availability Zones place VMs in physically separate datacenters within a region, not within the same datacenter, which adds cross-datacenter latency and is not required for the stated goal of surviving a single datacenter hardware failure. Option C is wrong because a single Virtual Machine Scale Set with a large instance count does not by itself enforce distribution across different physical servers and racks unless it is configured with an Availability Set or Availability Zones; a scale set without such placement constraints can place many VMs on the same physical host. Option D is wrong because deploying each VM in a separate resource group has no impact on physical placement or fault domain isolation; resource groups are logical containers for management and RBAC, not for infrastructure redundancy.

181
MCQmedium

Refer to the exhibit. A custom role is created. A user assigned this role reports being unable to view the VM's boot diagnostics in the Azure portal. What is the most likely reason?

A.The user does not have permission to start or restart the VM
B.The VM is stopped and deallocated
C.The role lacks permissions to the diagnostics storage account
D.The role does not include Microsoft.Compute/virtualMachines/read
AnswerC

Boot diagnostics requires the user to have read access to the storage account that stores the diagnostic data, such as Microsoft.Storage/storageAccounts/listKeys/action or a data-plane reader role on that account. The custom role only grants Compute actions on the VM and omits Storage actions, so the portal cannot retrieve the screenshot from the diagnostics container. This missing storage-scope authorization is the exact reason the boot diagnostics image cannot be viewed.

Why this answer

Boot diagnostics in Azure require access to a storage account where the serial console output and screenshots are stored. Even if the user has Microsoft.Compute/virtualMachines/read permission on the VM, they must also have the appropriate role (e.g., Storage Blob Data Reader) on the diagnostics storage account to read the boot diagnostics data. Without this, the portal will show an error or blank boot diagnostics pane.

Exam trap

The trap here is that candidates assume boot diagnostics are a property of the VM itself, when in reality they are stored in a separate storage account that requires explicit permissions beyond the VM scope.

How to eliminate wrong answers

Option A is wrong because starting or restarting a VM is not a prerequisite for viewing boot diagnostics; boot diagnostics are historical logs and screenshots that can be accessed regardless of the VM's power state. Option B is wrong because a stopped and deallocated VM still retains its boot diagnostics data in the storage account; the user should still be able to view the last boot logs. Option D is wrong because Microsoft.Compute/virtualMachines/read is likely included in the custom role (otherwise the user would not be able to see the VM at all), and the issue is specifically about accessing the storage account, not the VM resource itself.

182
MCQmedium

A company is designing a hybrid network solution connecting an on-premises data center to Azure. They require high availability with active-active routing and need to support up to 10 Gbps throughput. Which Azure service should they include in the design?

A.Site-to-Site VPN Gateway
B.Azure Virtual WAN
C.ExpressRoute FastPath
D.ExpressRoute Direct
AnswerD

ExpressRoute Direct provides a dedicated, private Layer-2 connection between your on-premises network and Microsoft's edge at a peering location, with port pairs available at 10 Gbps, 40 Gbps, or 100 Gbps. Since it delivers physical port-level bandwidth rather than a VPN gateway's aggregate limit, it easily satisfies the 10 Gbps throughput requirement. It also supports active-active routing by default through dual routers and BGP sessions, giving the required high availability with an SLA-backed redundant path.

Why this answer

ExpressRoute Direct provides dedicated, private connections from on-premises to Azure, supporting bandwidths up to 100 Gbps (10 Gbps easily). It enables active-active routing by using two circuits with BGP, meeting high availability and throughput requirements. ExpressRoute FastPath is a performance feature that reduces latency but is not a standalone service and does not itself provide active-active routing or guaranteed throughput; it requires an ExpressRoute circuit and does not replace the need for Direct when dedicated throughput is required.

Exam trap

A common mistake is assuming that ExpressRoute FastPath is a standalone service that can provide active-active routing and 10 Gbps throughput. In reality, FastPath is a feature that enhances performance but must be used with an existing ExpressRoute circuit. For dedicated bandwidth and native active-active routing, ExpressRoute Direct is the appropriate service.

How to eliminate wrong answers

Option A is wrong because Site-to-Site VPN Gateway is limited to a maximum throughput of approximately 1.25 Gbps per tunnel (aggregate up to 10 Gbps only with multiple tunnels and specific SKUs), and it relies on the public internet, which does not guarantee the consistent 10 Gbps throughput or the same SLA as a private connection. Option B is wrong because Azure Virtual WAN is a networking orchestration service that can aggregate multiple connection types, but it does not itself provide the high-throughput, dedicated private connectivity required; it would typically use ExpressRoute circuits underneath for such throughput, making it an architectural overlay rather than the direct service needed. Option D is wrong because ExpressRoute FastPath is a feature that improves network performance by bypassing the gateway for certain traffic flows, but it is not a standalone service; it must be enabled on an existing ExpressRoute circuit and does not itself provide the 10 Gbps throughput or active-active routing—it enhances performance after the circuit is in place.

183
MCQeasy

A company deploys a web application in two Azure regions for high availability. They need to automatically direct users to the nearest healthy region based on geographic location and endpoint health. Which Azure service should they use?

A.Azure Traffic Manager
B.Azure Load Balancer
C.Azure Application Gateway
D.Azure Front Door
AnswerA

Azure Traffic Manager is a DNS-based global load balancer that routes user requests to the most appropriate region based on routing methods like performance, priority, or geographic, and continuous health probes. Because it operates at the DNS layer, it simply returns the endpoint's IP address and does not proxy or terminate traffic, making it suitable for any application protocol. This enables simple, multi-region failover and geographic distribution as required by the company's two-region web application deployment.

Why this answer

Azure Traffic Manager is a DNS-based traffic load balancer that directs users to the nearest healthy region based on geographic location and endpoint health. It uses DNS resolution to route traffic to the closest available endpoint, making it ideal for global high-availability scenarios where users need automatic failover across regions.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Traffic Manager because both can route traffic globally, but Front Door is an application delivery controller with integrated WAF and SSL offload, whereas Traffic Manager is a simpler DNS-based load balancer focused solely on geographic and health-based routing.

How to eliminate wrong answers

Option B (Azure Load Balancer) is wrong because it operates at Layer 4 (TCP/UDP) and distributes traffic within a single region, not across multiple regions or based on geographic location. Option C (Azure Application Gateway) is wrong because it is a regional Layer 7 load balancer with features like SSL termination and URL-based routing, but it does not provide global geographic routing or multi-region failover. Option D (Azure Front Door) is wrong because, while it offers global load balancing and geographic routing, it is primarily an HTTP/HTTPS application delivery platform with advanced web application firewall (WAF) capabilities; for simple DNS-based geographic routing and health monitoring, Traffic Manager is the correct and more lightweight choice.

184
MCQeasy

A company has an on-premises data center and wants to connect it to Azure to extend their network. They require a dedicated, private, high-bandwidth connection that is not routed over the public internet. They also want a lower-cost backup connection for redundancy in case the primary connection fails. Which combination of connectivity options should they implement?

A.ExpressRoute as the primary connection and a Site-to-Site VPN as the backup connection.
B.Two ExpressRoute circuits from different service providers, both active.
C.Site-to-Site VPN as the primary connection and Point-to-Site VPN as the backup.
D.Azure VPN Gateway with active-passive mode and a second VPN Gateway for failover.
AnswerA

ExpressRoute is a private, dedicated connection that bypasses the public internet, providing consistent low latency, high bandwidth, and a 99.9% SLA. A Site-to-Site VPN over the public internet is significantly cheaper to maintain as a standby, and because it uses encrypted IPsec tunnels, it can serve as an adequate failover path if the ExpressRoute circuit goes down. This combination meets the requirement for a private primary path while keeping the backup cost-effective.

Why this answer

ExpressRoute provides a dedicated, private, high-bandwidth connection that bypasses the public internet, meeting the primary requirement. A Site-to-Site VPN over the internet serves as a cost-effective backup path for redundancy, as it uses encrypted tunnels over the public internet without the recurring costs of a second ExpressRoute circuit.

Exam trap

The trap here is that candidates often assume two ExpressRoute circuits are required for redundancy, overlooking the cost-effective alternative of using a Site-to-Site VPN as a backup, which still meets the redundancy requirement without the high cost of a second private connection.

How to eliminate wrong answers

Option B is wrong because two active ExpressRoute circuits from different providers provide high availability but at a higher cost, not a lower-cost backup. Option C is wrong because a Site-to-Site VPN as the primary connection does not meet the requirement for a dedicated, private, high-bandwidth connection not routed over the public internet; Point-to-Site VPN is for individual client connections, not site-to-site redundancy. Option D is wrong because Azure VPN Gateway with active-passive mode and a second VPN Gateway for failover still uses the public internet, failing the private connection requirement, and is more complex and costly than a single VPN Gateway with active-passive mode.

185
MCQeasy

A company has multiple virtual networks in different Azure regions. They need to connect all VNets together securely over the Microsoft backbone. They also need to connect to an on-premises data center via ExpressRoute. The solution should support transitive routing between all connected networks. Which Azure service should they use?

A.Azure Virtual Network Peering
B.Azure VPN Gateway
C.Azure Virtual WAN
D.Azure ExpressRoute Gateway
AnswerC

Azure Virtual WAN is the correct choice because it acts as a managed hub-and-spoke platform with automatic transitive routing between any connected VNets, regardless of region. Spoke VNets in different Azure regions can attach to the same Virtual WAN hub or to regional hubs, and traffic is routed over the Microsoft backbone with no need for manual peering or BGP. It also natively interconnects with VPN, ExpressRoute, and point-to-site gateways, making it the ideal centralized connectivity solution for multiple VNets.

Why this answer

Azure Virtual WAN is the correct choice because it provides a hub-and-spoke architecture that supports transitive routing between all connected networks (multiple VNets across regions and on-premises via ExpressRoute) over the Microsoft backbone. It natively integrates ExpressRoute and VPN gateways into a single managed service, enabling seamless connectivity and routing between any spoke VNet, branch, or on-premises site without requiring manual peering or gateway transit configuration.

Exam trap

The trap here is that candidates often choose Azure Virtual Network Peering (Option A) because they assume peering supports transitive routing, but Azure explicitly does not allow transitive routing through peered VNets unless you use a hub VNet with a network virtual appliance or enable gateway transit, which is not the same as native transitive routing.

How to eliminate wrong answers

Option A is wrong because Azure Virtual Network Peering does not support transitive routing; if you peer VNet A to VNet B and VNet B to VNet C, traffic cannot flow from A to C through B without additional configuration (e.g., a network virtual appliance or hub VNet). Option B is wrong because Azure VPN Gateway provides site-to-site or point-to-site connectivity over the public internet, not over the Microsoft backbone, and it does not natively support transitive routing between multiple VNets across regions without complex manual routing and additional gateways. Option D is wrong because Azure ExpressRoute Gateway is a component that connects a single VNet to an ExpressRoute circuit; it does not provide transitive routing between multiple VNets or across regions, and it requires additional services (like Virtual WAN or a hub VNet) to achieve full mesh connectivity.

186
MCQhard

A financial services company is designing a data platform on Azure that must comply with strict regulatory requirements. The platform will store sensitive customer data in Azure SQL Database. The company needs to prevent data exfiltration and ensure that only authorized Microsoft Entra ID users can access the data. The solution must also encrypt data at rest and in transit. Which combination of Azure services should the company implement?

A.Azure SQL Database firewall rules, Transparent Data Encryption (TDE), and Always Encrypted
B.Azure SQL Database with IP firewall rules, TLS 1.2, and Azure Information Protection
C.Azure SQL Database with Managed Identity, Azure Private Link, and Transparent Data Encryption (TDE)
D.Azure SQL Database with Microsoft Entra ID authentication, Azure Key Vault, and Azure Storage Service Encryption
AnswerC

Azure Private Link exposes the SQL Database through a private IP address within the customer's virtual network, completely removing the public internet from the data path and sharply reducing the attack surface for exfiltration. Managed Identity allows an Azure resource, such as a function app or virtual machine, to authenticate to SQL Database via Microsoft Entra ID without embedding credentials in code or configuration, ensuring that only the intended service identity can connect. TDE adds defense-in-depth by encrypting data files, backups, and transaction logs at rest. This combination of private network routing plus a non-interactive, least-privilege workload identity directly addresses the requirement to prevent unauthorized data copying.

Why this answer

It combines Managed Identity for secure, password-free authentication to Azure SQL Database, Azure Private Link to eliminate public internet exposure and prevent data exfiltration, and Transparent Data Encryption (TDE) to encrypt data at rest. This trio directly addresses the regulatory requirements for access control, network isolation, and encryption without relying on less secure firewall rules or client-side encryption.

Exam trap

The trap here is that candidates often confuse network-level isolation (Private Link) with access control (firewall rules) or encryption methods (TDE vs. Always Encrypted), and mistakenly believe that IP firewall rules or client-side encryption alone satisfy exfiltration prevention requirements.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database firewall rules alone do not prevent data exfiltration (they only restrict source IPs, not destination) and Always Encrypted is a client-side encryption feature that does not protect data in transit between the client and the database. Option B is wrong because IP firewall rules are insufficient for preventing data exfiltration (they do not isolate the network path), TLS 1.2 only covers data in transit, and Azure Information Protection is a classification/labeling service, not a data-at-rest encryption mechanism for SQL Database. Option D is wrong because Azure Storage Service Encryption applies only to Azure Storage (Blob, Files, etc.), not to Azure SQL Database, and while Entra ID authentication and Key Vault are useful, they do not provide network-level exfiltration prevention.

187
MCQmedium

You are an Azure administrator. The above Azure Policy definition is assigned to a subscription. A developer tries to deploy a Virtual Machine with SKU Standard_DS2_v2. What will happen?

A.The deployment is denied and an error message is returned.
B.The deployment succeeds with a warning logged.
C.The VM is created but the SKU is changed to a different series.
D.The deployment succeeds because the policy only audits.
AnswerA

The policy definition's effect is Deny, so Azure Resource Manager evaluates the VM SKU against the condition before the resource provider accepts the request. When the condition matches, the create or update call is blocked, the deployment status is Failed, and the response contains the policy violation, including the policy name and assignment ID. Because evaluation happens during the PUT request, no VM is ever created or partially provisioned.

Why this answer

The Azure Policy definition assigned to the subscription includes a 'deny' effect for VM SKUs that are not in the allowed list. Since Standard_DS2_v2 is not an allowed SKU, the deployment is denied and an error message is returned to the developer, preventing the VM from being created.

Exam trap

The trap here is that candidates often confuse the 'deny' effect with 'audit' or 'modify' effects, assuming a policy only logs non-compliance or automatically corrects the resource, rather than understanding that 'deny' actively blocks the deployment.

How to eliminate wrong answers

Option B is wrong because a policy with a 'deny' effect does not allow the deployment to succeed with a warning; it actively blocks the deployment. Option C is wrong because Azure Policy does not automatically change the SKU to a different series; it either allows or denies the deployment based on the defined effect. Option D is wrong because the policy uses a 'deny' effect, not an 'audit' effect; an audit effect would log compliance but still allow the deployment to succeed.

188
Matchingmedium

Match each Azure monitoring service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Collect, analyze, and act on telemetry

Query and analyze log data

Application performance monitoring (APM)

Personalized recommendations for best practices

Personalized alerts for service issues

Why these pairings

The correct matches are: Azure Monitor for telemetry collection, Log Analytics for log analysis, Application Insights for APM, and Azure Sentinel for security. Common confusions include swapping Azure Monitor with Application Insights or Log Analytics.

189
MCQeasy

You are designing a backup strategy for Azure virtual machines that must support application-consistent backups and be capable of restoring to a different Azure region. Which solution should you use?

A.Azure Site Recovery
B.Azure Files
C.Azure Disk Backup
D.Azure Backup
AnswerD

Azure Backup is the native backup service for Azure VMs; it installs an extension that initiates VSS on Windows (and file-consistent snapshots on Linux) to produce application-consistent recovery points. The snapshots are stored in a Recovery Services vault, which can be configured for locally redundant or geo-redundant storage, enabling cross-region restores in the paired region. Azure Backup also provides customizable retention policies, multiple scheduled backups per day, and the ability to restore the full VM, individual files, or disks. This combination of VSS-based consistency, vault storage, and policy-based retention makes it the correct choice for this VM backup strategy.

Why this answer

Azure Backup is the correct solution because it provides native support for application-consistent backups of Azure VMs using the Volume Shadow Copy Service (VSS) on Windows or file-system-consistent snapshots on Linux, and it supports Cross-Region Restore (CRR) to recover backups to a different Azure region. This meets both requirements directly without additional configuration.

Exam trap

The trap here is that candidates confuse Azure Site Recovery (disaster recovery) with Azure Backup (backup), mistakenly thinking replication for failover also provides application-consistent point-in-time backups and cross-region restore capabilities.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery is a disaster recovery solution that replicates VMs for failover, not a backup service; it does not inherently provide application-consistent backups for long-term retention or point-in-time restore. Option B is wrong because Azure Files is a managed file share service, not a backup solution for VMs; it cannot back up entire VMs or provide application-consistent snapshots of VM disks. Option C is wrong because Azure Disk Backup only protects managed disks at the disk level, not the VM level, and it does not guarantee application-consistent backups (it uses crash-consistent snapshots) nor does it support Cross-Region Restore.

190
MCQmedium

You are designing a network topology for a multi-tier application in Azure. The application has a web tier, an API tier, and a database tier. You need to ensure that the web tier can communicate with the API tier, and the API tier can communicate with the database tier, but the web tier cannot directly access the database tier. Which Azure networking solution should you implement?

A.Azure Firewall
B.Network Security Groups (NSGs) with service tags
C.Azure Application Security Groups (ASGs)
D.VNet peering
AnswerC

ASGs allow you to group VMs and define security rules based on application tiers, simplifying policy management.

Why this answer

Azure Application Security Groups (ASGs) let you group VMs by workload role (web, API, database) and then write NSG rules that reference those groups as source and destination, so you can allow web-to-API and API-to-database while implicitly denying web-to-database. This provides the tiered, role-based segmentation the scenario requires without managing individual IP addresses. ASGs are the purpose-built Azure construct for application-centric micro-segmentation within a VNet.

Exam trap

AZ-305 often tests whether candidates confuse ASGs (application-tier grouping for NSG rules) with service tags (Azure platform service IP ranges), leading them to pick NSGs with service tags when role-based micro-segmentation is required.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a centralized, stateful network security appliance for perimeter and east-west traffic inspection at scale; it can enforce rules but is overkill and not the simplest way to achieve intra-VNet tier isolation between specific VM groups. Option B is wrong because NSGs with service tags alone cannot express 'web tier can talk to API tier but not database tier' cleanly, since service tags represent Azure platform services, not your own workload tiers. Option D is wrong because VNet peering only connects virtual networks and does not provide any traffic filtering or tier isolation between subnets within a VNet.

191
MCQeasy

You are designing a cloud-native application that will run on Azure Kubernetes Service (AKS). The application needs to authenticate users and manage access to resources. Which identity service should you use?

A.Microsoft Entra External ID
B.Microsoft Entra ID
C.Microsoft Account
D.Azure Active Directory Domain Services
AnswerB

Microsoft Entra ID (formerly Azure Active Directory) is the identity provider (IdP) for the entire Azure platform, authenticating users, service principals, and managed identities via OAuth 2.0, OpenID Connect, and SAML. In a cloud-native application, services such as AKS use Entra ID for RBAC and workload identity federation, allowing pods to fetch tokens without hard-coded secrets. It is the correct choice because the same tenant that defines organizational users also authorizes access to the Azure control plane and integrates with application authentication.

Why this answer

Microsoft Entra ID (formerly Azure AD) is the correct identity service for a cloud-native application on AKS because it provides OAuth 2.0 and OpenID Connect authentication, enabling secure user sign-in and role-based access control (RBAC) for Kubernetes resources. It integrates natively with AKS to manage identities for users and service principals, supporting managed identities for Azure resources without credential management.

Exam trap

The trap here is confusing Microsoft Entra ID (the modern cloud identity provider for enterprise users) with Azure Active Directory Domain Services (a legacy domain service for on-premises-style authentication), leading candidates to pick D for AKS when only Entra ID supports the required OAuth 2.0/OIDC protocols.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra External ID is designed for external-facing scenarios like customer or partner identities, not for authenticating internal users or managing access to AKS resources. Option C is wrong because Microsoft Account is a consumer identity provider for personal accounts (e.g., Outlook, Xbox) and lacks enterprise features like RBAC, group management, and integration with AKS. Option D is wrong because Azure Active Directory Domain Services provides legacy LDAP, Kerberos, and NTLM authentication for domain-joined VMs or lift-and-shift apps, not modern OAuth/OpenID Connect flows required by cloud-native AKS applications.

192
Multi-Selecteasy

Which TWO of the following are benefits of using Azure Policy? (Choose two.)

Select 2 answers
A.Assess compliance of resources against defined policies
B.Enforce tagging conventions on resources
C.Manage access control for resources
D.Create new Azure resources based on a template
E.Automatically remediate non-compliant resources without manual intervention
AnswersA, B

Azure Policy continuously evaluates existing and newly deployed resources against policy definitions and initiatives, aggregating the results into a compliance dashboard that shows per-policy and per-resource compliance states. This assessment process covers properties like resource types, locations, and configuration settings, enabling organizations to identify drift from corporate standards even after enrollment.

Why this answer

Azure Policy is a service that enables you to create, assign, and manage policies that enforce rules and effects over your Azure resources. Option A is correct because one of its primary benefits is the ability to assess the compliance state of existing and newly deployed resources against defined policy definitions, providing a clear compliance dashboard and reports. This assessment is continuous and can be viewed at the subscription, management group, or resource group level.

Exam trap

The trap here is that candidates often confuse Azure Policy's ability to enforce rules (like tagging) with automatic remediation, but automatic remediation requires explicit configuration of the 'deployIfNotExists' or 'modify' effect and a remediation task, making it not a direct benefit of simply using Azure Policy.

193
MCQmedium

A company deploys a web application on Azure virtual machines (VMs) across multiple availability zones in the East US region. The application receives HTTPS traffic. They need to distribute incoming traffic across the VMs, offload SSL/TLS termination, and ensure that client requests from the same user session are always sent to the same backend VM (session persistence). Which Azure load balancing solution should they choose?

A.Azure Load Balancer
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a regional Layer-7 load balancer that terminates SSL and decrypts incoming HTTPS requests, enabling it to inspect HTTP headers and route based on URL paths. It natively provides cookie-based session affinity using the Application Gateway Affinity cookie, which reliably pins a client session to the same backend VM across availability zones. With additional features like URL path-based routing, WebSocket support, and optional WAF integration, it is the appropriate choice for distributing HTTPS traffic to VMs within a single region.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that supports SSL/TLS termination, cookie-based session persistence (affinity), and can distribute HTTPS traffic across VMs in multiple availability zones. These features directly match all three requirements: SSL offloading, session persistence, and cross-zone traffic distribution.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming any load balancer can handle SSL termination and session persistence, but only Layer 7 solutions like Application Gateway or Front Door provide cookie-based affinity and SSL offload.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and does not support SSL/TLS termination or application-layer session persistence; it can only maintain session affinity using source IP hashing, which is not cookie-based and less reliable for HTTPS. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not perform SSL termination or session persistence; it directs clients to regional endpoints based on DNS resolution, not per-request load balancing. Option D is wrong because Azure Front Door is a global Layer 7 service that supports SSL termination and session affinity, but it is designed for global distribution across regions, not for distributing traffic within a single region across availability zones; it adds unnecessary latency and complexity for a regional-only workload.

194
MCQhard

A multinational organization is designing a Microsoft 365 deployment for 10,000 users. The organization requires that all users have a consistent experience and that desktop settings follow users across devices. The solution must also support offline access to files and automatic sync. Which Microsoft 365 service should the organization use?

A.Microsoft Entra ID
B.Microsoft Intune
C.Enterprise State Roaming
D.OneDrive for Business
AnswerD

OneDrive for Business provides a full client-side sync engine that replicates files from SharePoint Online to the local disk, enabling true offline access and background re-synchronization when connectivity returns. Its Known Folder Move feature redirects Windows known folders—Documents, Desktop, and Pictures—into OneDrive, allowing user files to roam seamlessly across multiple devices. Together with Files On-Demand, OneDrive meets both offline access and user data sync, making it the only listed option that satisfies the stated requirements.

Why this answer

OneDrive for Business is the correct choice because it provides per-user cloud storage with offline file access via Files On-Demand and automatic sync through the OneDrive sync client. It also enables desktop settings (such as desktop, documents, and pictures folders) to follow users across devices via Known Folder Move, ensuring a consistent experience. This directly meets the requirements for offline access, automatic sync, and cross-device settings roaming.

Exam trap

The trap here is confusing Enterprise State Roaming (which roams Windows settings) with OneDrive for Business (which roams files and provides offline sync), leading candidates to pick Option C when the question explicitly requires offline file access and automatic sync.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (formerly Azure AD) is an identity and access management service that handles authentication and authorization, not file sync, offline access, or desktop settings roaming. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not for syncing files or roaming desktop settings. Option C is wrong because Enterprise State Roaming syncs Windows settings and application data across devices using Azure AD, but it does not provide offline file access or automatic file sync; that is a capability of OneDrive for Business.

195
MCQhard

Your organization has a hybrid identity solution using Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You need to design a solution that allows users to use their on-premises credentials to authenticate to cloud applications, but you want to avoid synchronizing password hashes to the cloud. Which authentication method should you choose?

A.Seamless Single Sign-On
B.Pass-through Authentication
C.Active Directory Federation Services (AD FS)
D.Password Hash Synchronization
AnswerB

Pass-through Authentication is correct because it validates the user's password directly against the on-premises Active Directory without ever storing a password hash in Azure AD. An agent on the on-premises server listens via an outbound connection to the Azure AD Service Bus; when a sign-in occurs, the cloud sends the credentials to the agent, which checks them against AD and returns a success or failure result. This design meets the explicit requirement to avoid synchronizing password hashes, while still allowing Azure AD and Microsoft 365 to authenticate users with their existing on-premises credentials.

Why this answer

Pass-through Authentication (PTA) is the correct choice because it validates users' passwords directly against on-premises Active Directory without ever storing password hashes in the cloud. This meets the requirement to avoid synchronizing password hashes while still enabling authentication to cloud applications via Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse Seamless SSO as an independent authentication method, when it is actually a convenience feature that must be paired with either PTA or PHS, and they may overlook the explicit requirement to avoid password hash synchronization.

How to eliminate wrong answers

Option A is wrong because Seamless Single Sign-On is not an authentication method; it is a feature that provides automatic sign-in when users are on domain-joined devices, but it requires either Password Hash Synchronization or Pass-through Authentication as the underlying method. Option C is wrong because Active Directory Federation Services (AD FS) can avoid password hash synchronization, but it introduces additional infrastructure complexity and is not the simplest solution that meets the requirement; the question asks for an authentication method, and PTA is more straightforward for this specific need. Option D is wrong because Password Hash Synchronization explicitly synchronizes password hashes to the cloud, which directly violates the requirement to avoid that.

196
MCQhard

A company has multiple Azure subscriptions and wants to enforce consistent network policies across all VNets. They need to ensure that all traffic going out to the internet is inspected by a central firewall. The solution must be scalable and support multiple regions. What should they implement?

A.Use Azure Virtual WAN with a secured hub and Azure Firewall Manager
B.Deploy Azure Firewall in each subscription and route traffic through it
C.Use Azure Policy to enforce route tables on each VNet
D.Create VNet peering and use a network virtual appliance in one subscription
AnswerA

Azure Virtual WAN with a secured hub consolidates all networking into a single managed backbone, and Azure Firewall Manager provides a consistent, central security policy applied across every hub in all subscriptions. This approach eliminates the need to configure per-subscription inspection, because routing and security are integrated. Firewall Manager also offers cross-subscription governance and centralized logging, making it the only option that delivers both scalable connectivity and mandatory traffic inspection at the enterprise level.

Why this answer

Azure Virtual WAN with a secured hub and Azure Firewall Manager provides a centralized, scalable solution for enforcing consistent network policies across multiple subscriptions and regions. It enables a hub-and-spoke architecture where all internet-bound traffic from VNets is routed through a central Azure Firewall for inspection, with Azure Firewall Manager offering global policy management and automated routing.

Exam trap

The trap here is that candidates often choose Option C (Azure Policy) because they confuse policy enforcement with actual traffic routing, not realizing that Azure Policy only audits or enforces configuration compliance, not dynamic traffic inspection paths.

How to eliminate wrong answers

Option B is wrong because deploying Azure Firewall in each subscription creates a decentralized, inconsistent policy enforcement model that increases management overhead and fails to provide a single point of inspection for cross-subscription traffic. Option C is wrong because Azure Policy can enforce route tables, but it cannot dynamically route all internet traffic through a central firewall across multiple regions; it only ensures compliance with static routing configurations, not the actual traffic inspection path. Option D is wrong because VNet peering and a single network virtual appliance (NVA) in one subscription is not scalable across multiple regions and does not provide centralized policy management; it also introduces a single point of failure and complex routing updates.

197
MCQhard

A company is designing a hub-spoke network topology in Azure. The hub contains a third-party network virtual appliance (NVA) for inspection. Spokes need to communicate with each other, and all inter-spoke traffic must be routed through the NVA in the hub. Which configuration should they use?

A.Set route tables on spoke subnets with a 0.0.0.0/0 route to the Internet
B.Configure Azure Firewall in the hub with forced tunneling to on-premises
C.Create user-defined routes (UDRs) in each spoke subnet that force traffic to go through the hub NVA
D.Use VNet peering with gateway transit enabled
AnswerC

The correct approach is to create user-defined routes on each spoke subnet with a route for the other spoke's address space and the next hop set to the private IP address of the hub NVA. Because VNet peering is non-transitive, spoke-to-spoke traffic will not automatically flow through the hub; the UDR overrides the system route to force that path. You must also enable IP forwarding on the NVA network interface and ensure the NVA is in a hub subnet so return traffic takes a symmetric path. This gives precise, deterministic control of inter-spoke inspection and is the standard hub-spoke design pattern.

Why this answer

User-defined routes (UDRs) allow you to explicitly override Azure's default system routes. By adding a route in each spoke subnet with the hub NVA's private IP as the next hop for inter-spoke traffic (e.g., 10.1.0.0/16 -> 10.0.0.4), all traffic between spokes is forced through the NVA for inspection. This ensures the hub-spoke topology meets the requirement without relying on Azure Firewall or Internet routing.

Exam trap

The trap here is that candidates often confuse VNet peering's built-in transitive routing (which is disabled by default) with the ability to force traffic through an NVA, mistakenly thinking peering alone or gateway transit can achieve the required inspection without explicit UDRs.

How to eliminate wrong answers

Option A is wrong because a 0.0.0.0/0 route to the Internet would send all outbound traffic to the Internet, not through the hub NVA, and would not route inter-spoke traffic correctly. Option B is wrong because Azure Firewall with forced tunneling to on-premises would route traffic to on-premises, not through the hub NVA, and does not satisfy the requirement for inter-spoke inspection within Azure. Option D is wrong because VNet peering with gateway transit enables spokes to use a VPN gateway in the hub, but it does not force inter-spoke traffic through an NVA; it only provides transitive routing via the gateway, not custom inspection.

198
Multi-Selecteasy

You are designing a network architecture for a three-tier application in Azure. The web tier must be accessible from the internet. The application tier must only accept traffic from the web tier. The database tier must only accept traffic from the application tier. Which TWO Azure services should you use to enforce these network rules? (Choose two.)

Select 2 answers
A.Azure Bastion
B.Network Security Groups (NSGs)
C.Azure Application Gateway
D.Azure Front Door
E.Azure Firewall
AnswersB, C

Network Security Groups are stateful, distributed packet filters applied at a subnet or network interface (NIC) level, with rules that allow or deny traffic based on source/destination IP, port, endpoint, and protocol. For a three-tier application, you can associate a distinct NSG with each subnet—for example, the web subnet allows HTTPS from the internet or Application Gateway, the application subnet allows only a specific port from the web subnet, and the data subnet allows only the database port from the application subnet. This implements least-privilege segmentation directly within the VNet at no additional cost and without introducing a centralized appliance or extra network hop.

Why this answer

Network Security Groups (NSGs) are the correct choice because they act as a distributed, stateful firewall that can filter traffic at the subnet or NIC level using source and destination IP addresses, ports, and protocols. By applying NSGs to the subnets hosting the application and database tiers, you can create inbound rules that restrict traffic to only the preceding tier's subnet or IP range, enforcing the required east-west segmentation without introducing additional latency or cost.

Exam trap

The trap here is that candidates often choose Azure Firewall (Option E) for all network security needs, overlooking that NSGs are the native, lightweight solution for east-west traffic filtering within a virtual network, and Azure Firewall is typically reserved for centralized inspection, logging, and outbound traffic control.

199
MCQeasy

A company deploys a web application on Azure VMs within a single region. They need to distribute incoming HTTP traffic across multiple VMs, offload SSL encryption, and maintain session persistence (sticky sessions) for user sessions. Which Azure load balancing solution should they use?

A.Azure Load Balancer
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a Layer 7 reverse proxy that understands HTTP/S, enabling SSL termination at the gateway so VMs receive decrypted traffic and offload cryptographic overhead. It provides cookie-based session affinity (sticky sessions) using Application Gateway Affinity cookies, ensuring requests from the same user session reach the same VM. These capabilities map directly to the deployment's requirement for inbound web traffic distribution within a single region, making it the correct choice.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that can route HTTP/HTTPS traffic, offload SSL/TLS encryption, and support session affinity (sticky sessions) using cookies. Unlike a Layer 4 load balancer, it can inspect application-layer data, making it ideal for web applications requiring SSL termination and persistent user sessions.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support SSL offloading and sticky sessions, but only Layer 7 solutions like Application Gateway or Front Door provide these application-layer features.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot offload SSL encryption or maintain HTTP-based sticky sessions; it only distributes traffic based on IP and port. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not handle SSL offloading or session persistence at the application layer; it directs clients to endpoints based on DNS resolution. Option D is wrong because Azure Front Door is a global Layer 7 service designed for multi-region distribution and acceleration, not for intra-region load balancing with SSL offloading and sticky sessions within a single region; it adds unnecessary complexity and cost for a single-region scenario.

200
MCQeasy

A company is designing a virtual network architecture for a three-tier application (web, application, database). They want network isolation between tiers and secure access from the internet to the web tier only. Which Azure networking solution should they use?

A.Azure Virtual Network with subnets for each tier and Network Security Groups.
B.Azure Virtual Network with a single subnet and application security groups.
C.Azure Virtual Network with subnets and Azure Firewall.
D.Azure Virtual Network with subnets and a network virtual appliance (NVA).
AnswerA

This approach uses separate subnets for the web, application, and data tiers, establishing Layer-3 network boundaries within the virtual network. Network Security Groups (NSGs) are stateful, built-in filters that you associate with each subnet to enforce inbound and outbound rules, such as allowing internet traffic only to the web tier on ports 80/443 and permitting the web subnet to talk to the app subnet on a specific application port. Because NSGs are natively supported and incur no extra cost, this is the most efficient and standard method for isolating tiers and controlling east-west traffic without introducing additional appliances or routing complexity.

Why this answer

Deploying each tier in its own subnet within an Azure Virtual Network and applying Network Security Groups (NSGs) allows granular inbound/outbound rule enforcement. NSGs can restrict traffic so that only the web tier is reachable from the internet (via a public IP or Azure Load Balancer), while the application and database tiers are isolated from direct internet access and can only communicate with the adjacent tier as defined by NSG rules.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing Azure Firewall or an NVA for basic isolation, not realizing that NSGs with subnets are the native, cost-effective, and fully supported method for network segmentation within a single Azure VNet.

How to eliminate wrong answers

Option B is wrong because a single subnet with Application Security Groups (ASGs) still places all VMs in the same broadcast domain and does not provide network-level isolation between tiers; ASGs only group VMs logically for NSG rule application, but they do not prevent lateral traffic within the subnet without explicit NSG rules, and a single subnet cannot enforce separate routing or address spaces. Option C is wrong because Azure Firewall is a managed, stateful firewall service used for centralized inspection and logging across VNets or hybrid networks, but it is overkill and not the simplest solution for basic tier isolation within a single VNet; NSGs alone provide sufficient subnet-level filtering without the cost and complexity of a firewall. Option D is wrong because a Network Virtual Appliance (NVA) is typically used for advanced traffic inspection, routing, or security functions (e.g., third-party firewalls, WAN optimization) and is unnecessary for simple tier isolation; it adds operational overhead and cost when NSGs can achieve the same isolation with less complexity.

201
MCQhard

A global company is deploying a microservices application on AKS clusters in multiple Azure regions. They need to provide a single endpoint for users worldwide with SSL offloading, web application firewall, and URL path-based routing to the nearest healthy AKS cluster. They also need global load balancing with automatic failover. Which Azure service should they use?

A.Azure Front Door
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Load Balancer
AnswerA

Azure Front Door is a global application delivery controller that operates at Layer 7, using Anycast to terminate connections at the nearest point of presence. It directly satisfies the multi-region AKS requirement by performing SSL offloading, applying a web application firewall, and routing requests to different AKS clusters based on URL paths. Its global health probes and failover are distinct from DNS-based or regional approaches, making it the only listed service that can steer user traffic across the globe while preserving HTTP semantics.

Why this answer

Azure Front Door is the correct choice because it provides global HTTP/HTTPS load balancing with SSL offloading, web application firewall (WAF) integration, and URL path-based routing. It uses Anycast-based routing to direct users to the nearest healthy AKS cluster, ensuring low latency and automatic failover across regions.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Azure Traffic Manager, but Traffic Manager only provides DNS-level routing without application-layer features like SSL offloading, WAF, or path-based routing.

How to eliminate wrong answers

Option B is wrong because Azure Application Gateway is a regional load balancer that operates within a single Azure region and cannot provide global load balancing or cross-region failover. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not support SSL offloading, WAF, or URL path-based routing at the application layer. Option D is wrong because Azure Load Balancer is a Layer 4 (TCP/UDP) load balancer that operates regionally and lacks application-layer features like SSL termination, WAF, and path-based routing.

202
MCQhard

A multinational corporation needs to design a global DNS solution for Azure resources. They require automatic failover across Azure regions and low-latency responses based on the client's geographic location. The solution must also support custom domains without exposing the underlying Azure public IP addresses. Which combination of Azure services should they use?

A.Azure Traffic Manager with geographic routing and Azure Front Door
B.Azure Application Gateway with Azure Front Door
C.Azure DNS with Azure Traffic Manager
D.Azure Traffic Manager with priority routing and Azure Application Gateway
AnswerA

Azure Traffic Manager with geographic routing is the correct DNS-level mechanism for a multinational workload because it uses the client’s source DNS resolver location to select the optimal regional endpoint, enabling true global load balancing. Azure Front Door complements it by terminating HTTPS at the edge, providing the custom domain and managed TLS certificates, and allowing the origin to be exposed privately via private link, which is essential when user-facing traffic can’t hit the endpoint directly. Together they deliver global DNS failover plus application-layer routing and security, which is why this is the required combination.

Why this answer

Azure Front Door provides global load balancing with automatic failover across regions and low-latency routing based on the client's geographic location via its anycast protocol. Azure Traffic Manager with geographic routing complements this by directing traffic to specific regional endpoints based on the client's origin, and together they support custom domains while hiding the underlying Azure public IP addresses through Front Door's frontend endpoint.

Exam trap

The trap here is confusing regional services like Application Gateway with global services like Front Door, and assuming that DNS-based routing alone (Traffic Manager) can achieve low-latency geographic routing without the anycast edge network of Front Door.

How to eliminate wrong answers

Option B is wrong because Azure Application Gateway is a regional layer-7 load balancer that does not provide global failover or geographic routing across Azure regions. Option C is wrong because Azure DNS only provides name resolution and does not perform traffic routing, failover, or hide public IP addresses. Option D is wrong because Azure Traffic Manager with priority routing does not support geographic-based low-latency responses, and Azure Application Gateway is regional, not global.

203
MCQeasy

A company needs to implement a hybrid identity solution that allows users to access both on-premises applications and Microsoft 365 using a single identity. The company has on-premises Active Directory Domain Services (AD DS). They want to synchronize identities to the cloud while also enabling password writeback for self-service password reset. Which Azure service should they use?

A.Microsoft Entra ID
B.Microsoft Entra Connect Health
C.Microsoft Entra Connect
D.Microsoft Entra Domain Services
AnswerC

Microsoft Entra Connect is the correct on-premises synchronization tool that bridges on-premises Active Directory and Microsoft Entra ID, performing password hash sync, pass-through authentication, and, when properly configured with the required Microsoft Entra ID Premium license, password writeback. When a user resets a password in the cloud, Entra Connect receives that reset securely, encrypts it, and updates the on-premises AD password, ensuring the new credential works immediately for both on-premises and cloud authentication.

Why this answer

Microsoft Entra Connect (formerly Azure AD Connect) is the correct tool for synchronizing on-premises AD DS identities to Microsoft Entra ID while enabling password writeback for self-service password reset (SSPR). It supports the required hybrid identity scenarios, including password hash synchronization or pass-through authentication, and can be configured to write passwords back to on-premises AD DS via the SSPR writeback feature.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect (the sync tool) with Microsoft Entra ID (the cloud directory) or Microsoft Entra Domain Services (a managed domain service), leading them to select the wrong service for hybrid identity synchronization and password writeback.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is the cloud-based identity and access management service itself, not the synchronization tool; it does not directly perform identity sync or password writeback. Option B is wrong because Microsoft Entra Connect Health provides monitoring and diagnostics for the sync infrastructure but does not perform identity synchronization or password writeback. Option D is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., LDAP, Kerberos) for cloud VMs, not identity synchronization or password writeback to on-premises AD DS.

204
MCQmedium

A company wants to deploy a web application on Azure virtual machines (VMs). The application experiences variable traffic patterns, so the company needs to automatically add or remove VM instances based on CPU utilization. They also want the application to remain highly available even if an Azure datacenter fails. Which combination of Azure services should they use?

A.Virtual Machine Scale Sets configured with autoscale rules based on CPU and distributed across availability zones
B.Azure App Service with autoscale rules and deployment slots
C.Azure Load Balancer with a backend pool of VMs and autoscale rules applied to individual VMSS
D.Azure Traffic Manager with endpoints in separate regions and Manual scaling of VMs
AnswerA

Virtual Machine Scale Sets are the only compute option listed that runs your workload on IaaS VMs while natively supporting horizontal autoscale: you define a scale condition (e.g., scale out by one instance when CPU percentage exceeds 75%, scale in when below 25%) and Azure applies it to the entire set. Deploying the VMSS across multiple availability zones places instance replicas in physically separate datacenters within the region, so a zone outage does not take down the entire web tier. This combination directly satisfies both the CPU-based automatic scaling and the zone-failure protection requirement.

Why this answer

Virtual Machine Scale Sets (VMSS) with autoscale rules based on CPU utilization automatically add or remove VM instances to match variable traffic patterns. Distributing the VMSS across availability zones ensures the application remains highly available even if an entire Azure datacenter fails, because availability zones are physically separate datacenters within a region.

Exam trap

The trap here is that candidates often confuse Azure App Service (PaaS) with IaaS VM solutions, or assume that a load balancer alone can handle autoscaling, when in fact autoscale rules must be configured directly on the VMSS resource.

How to eliminate wrong answers

Option B is wrong because Azure App Service is a Platform-as-a-Service (PaaS) offering, not a VM-based solution, and the question explicitly requires deployment on Azure virtual machines. Option C is wrong because Azure Load Balancer distributes traffic but does not itself perform autoscaling; autoscale rules must be applied directly to the VMSS, not to individual VMs, and the phrase 'applied to individual VMSS' is redundant and misstates the architecture. Option D is wrong because Traffic Manager provides global DNS-based traffic routing across regions, but manual scaling of VMs does not meet the requirement for automatic scaling based on CPU utilization.

205
MCQeasy

A company has multiple branch offices and needs to connect them to Azure and to each other using a scalable, managed solution that simplifies network architecture. The solution should support automatic routing and integration with ExpressRoute and VPN. Which Azure service should they use?

A.Azure Virtual Network
B.Azure Virtual WAN
C.Azure ExpressRoute
D.Azure VPN Gateway
AnswerB

Azure Virtual WAN is a managed networking service that creates a hub-and-spoke architecture with integrated routing, automatically interconnecting branches, Azure VNets, and on-premises locations. It natively supports Site-to-Site VPN, Point-to-Site VPN, and ExpressRoute, and it performs automatic route table generation and propagation across all spokes. Virtual WAN also enables branch-to-branch connectivity without manual peering, making it the only option here that delivers a scalable, zero-touch global transit network.

Why this answer

Azure Virtual WAN is a managed networking service that aggregates branch, VPN, and ExpressRoute connectivity into a single hub-and-spoke architecture. It automatically handles routing between branches and Azure, supports any-to-any connectivity, and integrates natively with ExpressRoute and VPN gateways, making it the correct choice for a scalable, managed solution that simplifies network architecture.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN with Azure Virtual Network, thinking that a simple VNet with VPN gateways can scale to interconnect multiple branches, but they overlook the managed, automatic routing and aggregation capabilities that Virtual WAN provides for multi-site topologies.

How to eliminate wrong answers

Option A is wrong because Azure Virtual Network is a fundamental building block for creating isolated networks in Azure, but it does not provide managed, automatic routing between multiple branch offices or native integration with ExpressRoute and VPN at scale; it requires manual configuration of peering, gateways, and routing. Option C is wrong because Azure ExpressRoute is a dedicated private connection from on-premises to Azure, but it does not connect multiple branch offices to each other or provide automatic routing between them; it is a connectivity option, not a managed WAN service. Option D is wrong because Azure VPN Gateway provides site-to-site VPN connectivity from a single branch to Azure, but it does not offer a managed, scalable hub for interconnecting multiple branches or automatic routing between them; it requires additional configuration and does not aggregate multiple connections into a single managed topology.

206
MCQhard

Refer to the exhibit. The ARM template provisions a VM. The deployment succeeds but the VM fails to start. What is the most likely cause?

A.The admin password is in plaintext and does not meet complexity requirements
B.The data disk size 1023 GB exceeds the maximum for StandardSSD_LRS
C.The network interface resource ID is incorrectly formatted
D.The VM size Standard_D2s_v3 is not available in the region
AnswerD

Correct. As explained, the VM size not being available in the region can lead to a successful deployment but the VM failing to start.

Why this answer

The VM size Standard_D2s_v3 may not be available in the specified region or subscription. ARM template deployments can succeed in provisioning the resource definition, but the VM fails to start if the scheduler cannot allocate a host that supports this VM size. This is a common issue when the size is restricted or not available in the region, causing a delayed failure after deployment.

Exam trap

The trap here is that candidates assume any deployment success means all configuration is valid, but Azure separates infrastructure provisioning from guest OS configuration, so password or other guest-level failures can occur after deployment succeeds.

How to eliminate wrong answers

Option B is wrong because StandardSSD_LRS supports data disks up to 4095 GB, so 1023 GB is well within the limit. Option C is wrong because the network interface resource ID format in the exhibit (e.g., /subscriptions/.../networkInterfaces/...) is correctly formatted; an incorrect format would cause a deployment failure, not a VM start failure. Option D is wrong because if the VM size were unavailable in the region, the deployment itself would fail with a capacity error, not succeed and then fail to start.

207
MCQeasy

You need to design a storage solution for a data lake that will store petabytes of structured and unstructured data. The data must be accessible from Azure Databricks and Azure Machine Learning. The solution must optimize costs by automatically moving data to cooler tiers when access frequency decreases. Which Azure storage solution should you use?

A.Azure Data Lake Storage Gen2
B.Azure Blob Storage (flat namespace)
C.Azure NetApp Files
D.Azure Files
AnswerA

Azure Data Lake Storage Gen2 is the correct choice because it combines blob-based, petabyte-scale object storage with a hierarchical namespace that mirrors a file system. This enables POSIX-style access controls, atomic directory rename, and efficient path-based operations, which are critical for Databricks and machine learning workloads that enumerate directory trees. It also supports lifecycle management policies to tier data across hot, cool, and archive tiers, reducing cost while preserving analytical performance.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) is the correct choice because it combines a hierarchical namespace with Blob Storage's tiered lifecycle management, enabling petabyte-scale storage for both structured and unstructured data. It integrates natively with Azure Databricks and Azure Machine Learning via the ABFS driver, and its lifecycle policies automatically move data to cooler tiers (cool, archive) based on access frequency, optimizing costs.

Exam trap

The trap here is that candidates confuse Azure Blob Storage (flat namespace) with ADLS Gen2, assuming both support data lake workloads equally, but the hierarchical namespace is a critical differentiator for performance and security in petabyte-scale analytics.

How to eliminate wrong answers

Option B (Azure Blob Storage with flat namespace) is wrong because it lacks a hierarchical namespace, which is essential for efficient directory-level operations and ACL-based security in data lake scenarios; while it supports lifecycle management, the flat namespace makes it suboptimal for large-scale analytics workloads. Option C (Azure NetApp Files) is wrong because it is designed for high-performance, low-latency NFS/SMB workloads (e.g., enterprise applications, VDI) and does not support automatic tiering to cooler storage tiers; it also incurs higher costs for petabyte-scale data lakes. Option D (Azure Files) is wrong because it provides SMB file shares for lift-and-shift scenarios, not the object storage or hierarchical namespace needed for data lake analytics, and it lacks lifecycle management for cost optimization across tiers.

208
MCQmedium

A company has an Azure virtual network (VNet) in the East US region hosting a web application. They need to securely connect to an on-premises data center in the same region using a dedicated, private network connection with high throughput and low latency. They also need a backup connection for redundancy in case the primary connection fails. Which connectivity solution should they implement?

A.Site-to-Site VPN only
B.ExpressRoute only
C.ExpressRoute as primary with Site-to-Site VPN as backup
D.Azure Virtual WAN with VPN
AnswerC

The optimal design is an ExpressRoute circuit as the primary path for production traffic, leveraging its dedicated private bandwidth, low latency, and Microsoft SLA. In parallel, a Site-to-Site VPN over the internet serves as a cost-effective backup that automatically takes over if the ExpressRoute circuit fails, especially when implemented with Azure VPN Gateway in active-passive mode or with BGP routing. This hybrid approach satisfies both performance requirements and continuity of connectivity without doubling cost.

Why this answer

ExpressRoute provides a dedicated, private, high-throughput, low-latency connection to Azure, ideal for the primary link. A Site-to-Site VPN over the internet serves as a cost-effective, encrypted backup path that activates if the ExpressRoute circuit fails, meeting the redundancy requirement without relying on the same physical infrastructure.

Exam trap

The trap here is that candidates often choose ExpressRoute only, forgetting that it lacks built-in redundancy and that a Site-to-Site VPN is the standard, cost-effective backup for ExpressRoute circuits in the same region.

How to eliminate wrong answers

Option A is wrong because a Site-to-Site VPN alone uses the public internet, which cannot guarantee the dedicated, high-throughput, low-latency private connection required for the primary link. Option B is wrong because ExpressRoute alone provides no automatic backup; if the circuit fails, connectivity is lost, violating the redundancy requirement. Option D is wrong because Azure Virtual WAN with VPN is a managed networking service that can aggregate multiple connections, but it does not inherently provide a dedicated private primary link with a VPN backup unless ExpressRoute is also configured; the option as stated lacks the ExpressRoute component needed for the primary connection.

209
MCQeasy

A small business is moving its on-premises file server to Azure. The company has 50 users and stores approximately 500 GB of data, which includes documents and spreadsheets. The users need to access the files from their Windows laptops both at the office and remotely. The company wants to minimize costs while ensuring that files are always available and secure. You need to recommend a storage solution. What should you recommend?

A.Migrate the files to Azure Blob Storage and use Azure Storage Explorer for access.
B.Use Azure Stack Edge to sync the data to Azure Blob Storage.
C.Deploy Azure NetApp Files with a Standard capacity pool.
D.Deploy Azure Files with Azure File Sync and use a Windows File Server on-premises.
AnswerD

Azure Files provides fully managed SMB file shares in the cloud, and Azure File Sync replicates those shares to an on-premises Windows File Server, giving users low-latency local access while the cloud retains an authoritative copy. This hybrid setup preserves the existing server's drive-letter mappings, NTFS permissions, and AD integration, effectively 'lifting and shifting' the file server to Azure with minimal client disruption. Cloud tiering can even free local storage by keeping cool files only in Azure, while warm files stay cached on the server—ideal for a small business with modest capacity.

Why this answer

Azure Files with Azure File Sync provides a cloud-based file share that users can access via the SMB protocol from Windows laptops both on-premises and remotely, while Azure File Sync enables caching on an on-premises Windows File Server for low-latency access. This solution minimizes costs by using a standard file share tier and leverages Azure Backup for security and availability, meeting the 50-user, 500 GB requirement without over-provisioning.

Exam trap

The trap here is that candidates often choose Azure Blob Storage (Option A) because it is cheap and familiar, but they overlook the lack of native SMB file sharing support required for Windows laptop users to map drives and collaborate on documents.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage is an object storage solution that does not natively support SMB access for file sharing; users would need to use Azure Storage Explorer, which is not designed for concurrent file sharing from Windows laptops and lacks the seamless drive-mapping experience required. Option B is wrong because Azure Stack Edge is a hardware appliance designed for edge computing and data transfer to Azure, which is overkill and costly for a simple 500 GB file server migration with 50 users. Option C is wrong because Azure NetApp Files is a high-performance, enterprise-grade file service with a Standard capacity pool that is significantly more expensive than Azure Files and is typically used for latency-sensitive workloads like SAP or HPC, not for basic document and spreadsheet sharing.

210
MCQhard

A company uses Azure Firewall to secure outbound traffic from a hub virtual network. The security team reports that some traffic is bypassing the firewall because of asymmetric routing. You need to design a solution to force all outbound traffic through the firewall. What should you implement?

A.VNet peering with gateway transit
B.User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall
C.Azure Route Server
D.Azure Firewall Manager to enforce routing policies
AnswerB

A UDR with an address prefix of 0.0.0.0/0 and a next hop type of VirtualAppliance, pointing to the Azure Firewall's private IP, overrides the system default route for all outbound traffic from associated subnets. This forces all internet-bound traffic through the firewall, ensuring stateful inspection and symmetric routing for return packets. UDRs are the core mechanism for forced tunneling and centralized egress control in a hub-and-spoke architecture, making this the correct solution.

Why this answer

User Defined Routes (UDRs) with a default route (0.0.0.0/0) pointing to Azure Firewall as the next hop are the correct solution because they override the system default route and force all outbound traffic from subnets to be forwarded to the firewall, preventing asymmetric routing. Asymmetric routing occurs when traffic takes different paths to and from a destination; by ensuring the firewall is the next hop for all outbound traffic, UDRs guarantee symmetric flow through the firewall.

Exam trap

The trap here is that candidates often confuse Azure Firewall Manager's policy enforcement with actual traffic routing, but Firewall Manager does not create UDRs; it only manages firewall policies, and UDRs are still required to direct traffic to the firewall.

How to eliminate wrong answers

Option A is wrong because VNet peering with gateway transit allows traffic to flow through a VPN or ExpressRoute gateway in a peered VNet, but it does not enforce a specific next hop for outbound traffic and does not prevent asymmetric routing through Azure Firewall. Option C is wrong because Azure Route Server is used to dynamically exchange routes between network virtual appliances (NVAs) and Azure virtual networks, but it does not directly force all outbound traffic through a firewall; it facilitates BGP route propagation, which can be overridden by UDRs. Option D is wrong because Azure Firewall Manager can centralize routing policies and manage firewall policies across multiple firewalls, but it does not enforce the next hop for outbound traffic at the subnet level; UDRs are still required to direct traffic to the firewall.

211
MCQmedium

A media company is building a video streaming platform on Azure. The platform will store original high-definition videos and convert them to multiple resolutions for distribution. The company needs a cost-effective storage solution for the original videos, which are accessed infrequently but must be instantly available when needed. The converted videos will be served to end users globally and must be cached at edge locations for low latency. You need to design a storage and content delivery solution. What should you recommend?

A.Store original videos in Azure Blob Storage Cool tier and use Azure CDN for distribution.
B.Store original videos in Azure Blob Storage Premium tier and use Azure CDN for distribution.
C.Store original videos in Azure Blob Storage Archive tier and use Azure CDN for distribution.
D.Store original videos in Azure Files and use Azure Front Door for caching.
AnswerA

Cool tier is cost-effective for original videos that are stored but rarely accessed directly by consumers, because most playback traffic is served from Azure CDN edge caches. With CDN absorbing the majority of end-user requests, the origin store in Cool incurs negligible transaction costs while still offering immediate low-latency retrieval, unlike Archive or the premium cost of Hot. This architecture optimizes both storage spend and streaming performance.

Why this answer

Azure Blob Storage Cool tier provides low-cost storage for infrequently accessed data with instant retrieval, meeting the requirement for original videos that are rarely accessed but must be available immediately. Azure CDN caches the converted videos at edge locations globally, ensuring low-latency delivery to end users.

Exam trap

The trap here is confusing the Archive tier's low cost with instant availability, overlooking the mandatory rehydration delay, and mistaking Azure Front Door's global load balancing for a CDN caching solution.

How to eliminate wrong answers

Option B is wrong because Azure Blob Storage Premium tier is designed for high-performance, low-latency access with SSDs, which is unnecessary and cost-prohibitive for infrequently accessed original videos. Option C is wrong because Azure Blob Storage Archive tier has a retrieval latency of up to 15 hours (rehydration time), violating the requirement for instant availability. Option D is wrong because Azure Files is a managed file share for SMB/NFS protocols, not optimized for large-scale video storage or global content distribution, and Azure Front Door is a global load balancer and application accelerator, not a caching CDN for static content like video files.

212
MCQmedium

You are designing a containerized microservices application on Azure Kubernetes Service (AKS). The application must scale automatically based on HTTP traffic. You need to minimize cost by scaling down to zero pods when there is no traffic. Which scaling solution should you use?

A.Horizontal Pod Autoscaler (HPA)
B.Cluster Autoscaler
C.Kubernetes Event-driven Autoscaler (KEDA)
D.Vertical Pod Autoscaler (VPA)
AnswerC

Kubernetes Event-driven Autoscaler (KEDA) is the correct choice because it extends the Horizontal Pod Autoscaler (HPA) with event-driven triggers from HTTP requests, message queues, databases, or other external sources, allowing a microservice to scale from zero to N replicas and back down to zero when idle. KEDA installs a custom metrics API server that reports the current event stream length or request rate to the HPA, enabling fine-grained scaling that reacts to actual demand rather than only steady-state server metrics. This makes it ideal for containerized microservices that experience intermittent traffic and require cost-efficient running with no idle pods.

Why this answer

KEDA (Kubernetes Event-driven Autoscaler) is the correct choice because it can scale the number of pods in an AKS deployment down to zero when there is no HTTP traffic, and then scale up from zero when traffic resumes. Unlike the Horizontal Pod Autoscaler (HPA), which cannot scale below 1 replica by default, KEDA works with external event sources (like HTTP requests via an add-on) to achieve true zero-to-N scaling, minimizing cost during idle periods.

Exam trap

The trap here is that candidates often assume the Horizontal Pod Autoscaler (HPA) can scale to zero pods because it is the default autoscaler for Kubernetes, but HPA has a hard-coded minimum of 1 replica and cannot scale down to zero, making KEDA the only correct option for cost minimization through zero-pod scaling.

How to eliminate wrong answers

Option A is wrong because the Horizontal Pod Autoscaler (HPA) cannot scale a deployment to zero pods; it has a minimum replica count of 1 by design, as it relies on continuous metrics like CPU/memory or custom metrics that are not available when no pods exist. Option B is wrong because the Cluster Autoscaler adjusts the number of worker nodes in the AKS cluster, not the number of pods; it cannot scale pods to zero and does not respond to HTTP traffic directly. Option D is wrong because the Vertical Pod Autoscaler (VPA) adjusts CPU and memory requests/limits of existing pods, not the number of replicas, and cannot scale down to zero pods.

213
MCQeasy

A company deploys a web application on multiple Azure VMs within an availability set. They need to distribute incoming HTTP traffic evenly across the VMs and provide health probe monitoring. The solution must support SSL termination and source IP affinity (session persistence). Which Azure load balancing solution should they choose?

A.Azure Load Balancer (Basic)
B.Azure Load Balancer (Standard)
C.Azure Application Gateway v2
D.Azure Traffic Manager
AnswerC

Azure Application Gateway v2 is a regional layer-7 reverse proxy that terminates SSL/TLS at the gateway, offloading decryption from the backend VMs, and can optionally re-encrypt traffic to the origin pool. It provides cookie-based session affinity (ARRAffinity), configurable health probes, and URL/path-based routing, directly matching the need for SSL termination and persistent user sessions across multiple VMs. Its static VIPs and WebSocket support further solidify it as the correct L7 load-balancing choice in Azure.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that supports SSL termination, source IP affinity (session persistence), and health probe monitoring. It can distribute HTTP traffic evenly across VMs in an availability set while offloading SSL processing from the backend VMs.

Exam trap

The trap here is that candidates often confuse Layer 4 load balancers (Azure Load Balancer) with Layer 7 application delivery controllers (Application Gateway), assuming that SSL termination and session persistence are available in all load balancing tiers, but these features require application-layer processing only provided by Application Gateway.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer (Basic) operates at Layer 4 and does not support SSL termination or application-layer features like session persistence based on source IP. Option B is wrong because Azure Load Balancer (Standard) also operates at Layer 4 and cannot terminate SSL or provide Layer 7 routing capabilities. Option D is wrong because Azure Traffic Manager is a DNS-based global traffic routing solution that does not handle SSL termination or health probes at the application layer; it distributes traffic across endpoints based on DNS resolution, not direct HTTP traffic distribution.

214
MCQmedium

Your company has a global application deployed across multiple Azure regions. You need to design a disaster recovery solution that meets a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The solution should use Azure-native services and minimize costs. Which option should you choose?

A.Azure Traffic Manager with priority routing
B.Azure Site Recovery with 15-minute replication
C.Active geo-replication for Azure SQL Database
D.Azure Backup with cross-region restore
AnswerB

Azure Site Recovery continuously replicates your Azure VMs (or Hyper-V/VMware workloads) to a secondary region and can create application-consistent recovery points at a frequency as low as 15 minutes, giving a tightly bounded RPO. It also provides orchestrated failover, failback, and non-disruptive disaster-recovery drills, so the whole multi-tier application can be recovered in the paired region within minutes.

Why this answer

Azure Site Recovery (ASR) with 15-minute replication is the correct choice because it provides application-consistent replication for Azure VMs with a configurable RPO as low as 15 minutes and supports failover within the 1-hour RTO. ASR is an Azure-native disaster recovery service that orchestrates replication, failover, and failback across regions, making it the most cost-effective option for meeting the stated RPO and RTO requirements for a multi-region application.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery with Azure Backup, assuming both are suitable for DR, but Azure Backup is optimized for archival and long-term retention with higher RPO/RTO, while ASR is purpose-built for low-RPO/RTO disaster recovery scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager with priority routing is a DNS-level traffic load balancer that does not provide replication or failover of application data; it only redirects traffic based on endpoint health, so it cannot meet the RPO/RTO for data recovery. Option C is wrong because active geo-replication for Azure SQL Database offers an RPO of 5 seconds and RTO of 1 hour, but it is specific to Azure SQL Database and does not cover the entire application stack (e.g., VMs, app tiers), and it is more expensive than ASR for a full application DR solution. Option D is wrong because Azure Backup with cross-region restore is designed for long-term backup retention and has an RPO of typically 24 hours (or more) and an RTO that can exceed several hours, making it unsuitable for the 15-minute RPO and 1-hour RTO requirements.

215
MCQmedium

Your company is migrating a legacy on-premises application to Azure. The application requires low-latency access to a shared file system that supports SMB protocol. The solution must be highly available within a single Azure region and must not require the application to be modified. Which Azure service should you recommend?

A.Azure Managed Disks (SSD)
B.Azure NetApp Files
C.Azure Files (premium tier)
D.Azure Blob Storage
AnswerC

Azure Files is the correct choice because it provides fully managed SMB 3.0 file shares that expose a familiar UNC path (\\storageaccount.file.core.windows.net\share) without requiring application code changes. The premium tier uses SSD hardware to guarantee sub-millisecond latency for IOPS-intensive or latency-sensitive workloads, and it supports SMB Multichannel, AD integration, and Azure File Sync caching. Since it is a true file share service, multiple VMs can connect concurrently, allowing the legacy on-premises app to be re-pointed at the cloud share exactly as it would use any Windows file server.

Why this answer

Azure Files (premium tier) provides fully managed SMB file shares with low-latency access, high availability within a single Azure region, and supports the SMB protocol natively without requiring any application modifications. This makes it the ideal choice for migrating legacy on-premises applications that rely on SMB-based file sharing.

Exam trap

The trap here is that candidates often confuse Azure NetApp Files (a third-party service) with Azure Files, or assume that Azure Blob Storage can be used as a file share via SMB without modifications, overlooking the native SMB support and low-latency guarantees of Azure Files premium tier.

How to eliminate wrong answers

Option A is wrong because Azure Managed Disks (SSD) provide block-level storage for virtual machines, not a shared file system accessible via SMB protocol, and they require application modifications to use. Option B is wrong because Azure NetApp Files offers high-performance NFS and SMB volumes but is a third-party service (NetApp) that introduces additional complexity and cost, and while it supports SMB, it is not the simplest or most cost-effective fully managed Azure-native solution for this requirement. Option D is wrong because Azure Blob Storage is an object storage service that does not support the SMB protocol natively; it requires application modifications or additional components (like Azure File Sync) to present as a file share, and it is not designed for low-latency SMB access.

216
MCQeasy

Your company deploys a line-of-business application on Azure App Service. The application requires custom domain names and SSL/TLS certificates. You need to ensure that the application can be accessed via a custom domain with HTTPS. What should you configure in the App Service?

A.Add the custom domain and bind the SSL/TLS certificate.
B.Configure IP restrictions to allow only the custom domain.
C.Create a deployment slot for production traffic.
D.Scale out the App Service plan to increase instance count.
AnswerA

Azure App Service web apps require a custom domain to be mapped to the app's default hostname (e.g., appname.azurewebsites.net) before users can reach it via a domain they own. Binding an SSL/TLS certificate (whether App Service Managed Certificate, Key Vault, or a custom PFX) then enables HTTPS for that domain, fulfilling the need for secure access over the company's domain. Without both steps, the app stays on the azurewebsites.net hostname with only the default wildcard certificate, so the custom domain remains inaccessible over HTTPS.

Why this answer

To access an App Service via a custom domain with HTTPS, you must first add the custom domain to the App Service and then bind an SSL/TLS certificate (either App Service Managed Certificate, a Key Vault certificate, or a third-party certificate) to that domain. This binding enables the App Service to present the certificate during the TLS handshake, allowing secure HTTPS connections. Without both steps, the custom domain will not resolve securely.

Exam trap

The trap here is that candidates may confuse IP restrictions (which filter traffic) or deployment slots (which manage releases) with the necessary steps for custom domain and certificate binding, leading them to overlook the direct requirement of adding the domain and binding the certificate.

How to eliminate wrong answers

Option B is wrong because IP restrictions control which source IP addresses can access the app, not which domain names are allowed; they do not enable custom domain HTTPS access. Option C is wrong because deployment slots are used for staging and swapping traffic between environments, not for configuring custom domains or SSL/TLS bindings. Option D is wrong because scaling out increases the number of instances for performance and availability, but has no effect on custom domain or certificate configuration.

217
MCQhard

You need to design a network topology for a global e-commerce platform on Azure. The solution must provide low-latency access to static content and protect the backend APIs from DDoS attacks. The backend APIs are deployed in multiple regions behind an internal load balancer. Which services should you use?

A.Azure Traffic Manager and Azure Firewall.
B.Azure Content Delivery Network (CDN) and Azure Load Balancer.
C.Azure Application Gateway with WAF and Azure API Management.
D.Azure Front Door with WAF and Azure API Management.
AnswerD

Azure Front Door with WAF provides a single global entry point via anycast and split TCP, performing Layer 7 routing, SSL termination, path-based matching, and edge WAF policies that can inspect every request before it reaches the API origin. Azure API Management then acts as the API gateway, publishing APIs, applying subscription keys, validating JWT/OAuth tokens, rate-limiting and quotaing consumers, and enabling versioning/transformation policies. Together they satisfy the e-commerce platform's need for global availability, DDoS and WAF protection, and secure API control, while keeping backend origins scalable and stable.

Why this answer

Azure Front Door with WAF provides global load balancing and low-latency access to static content via its anycast-based routing, while the integrated Web Application Firewall (WAF) protects backend APIs from DDoS and application-layer attacks. Azure API Management secures and manages the backend APIs, offering policies for throttling, authentication, and transformation. This combination meets the requirements for global low-latency content delivery and DDoS protection for multi-region backend APIs.

Exam trap

The trap here is that candidates often confuse Azure Application Gateway (regional, Layer 7) with Azure Front Door (global, anycast), and overlook that only Front Door provides global low-latency access and edge DDoS protection for multi-region deployments.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager is a DNS-based load balancer that does not provide low-latency static content delivery or integrated DDoS protection, and Azure Firewall is a stateful network firewall that lacks application-layer WAF capabilities for API protection. Option B is wrong because Azure CDN delivers static content but does not protect backend APIs from DDoS attacks, and Azure Load Balancer operates at Layer 4 (TCP/UDP) without WAF or application-layer security. Option C is wrong because Azure Application Gateway with WAF is a regional service that cannot provide global low-latency access or multi-region load balancing, and Azure API Management alone does not offer global DDoS protection or anycast-based routing.

218
MCQmedium

A company has headquarters and multiple branch offices worldwide, each with its own on-premises network. They want to connect all these sites to Azure and to each other over a single, centrally managed solution. They need high bandwidth connectivity for site-to-site traffic, support for both VPN and ExpressRoute connections, and automatic routing management without the complexity of configuring multiple VPN tunnels or BGP manually. Which Azure service should they use?

A.Azure Virtual WAN
B.Azure VPN Gateway (site-to-site) with BGP
C.Azure ExpressRoute with Microsoft peering
D.Azure Virtual Network peering
AnswerA

Azure Virtual WAN is a Microsoft-managed global transit architecture that uses a hub-and-spoke topology to connect branch offices to Azure and to each other. It automatically establishes routing tables, supports multiple connection types (S2S VPN, ExpressRoute, point-to-site, VNet), and propagates routes across the hubs so traffic between any pair of on-premises sites flows over the Microsoft backbone. This built-in transitive connectivity and centralized management is exactly what a worldwide branch network requires, making it the ideal choice.

Why this answer

Azure Virtual WAN is the correct choice because it provides a single, centrally managed hub-and-spoke architecture that connects branch offices, headquarters, and Azure over a unified network. It supports both VPN and ExpressRoute connections, automatically manages routing (including BGP) without manual configuration of multiple tunnels, and offers high bandwidth for site-to-site traffic.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN with a simple VPN gateway or ExpressRoute, not realizing that Virtual WAN is a managed overlay that combines both connectivity types with automatic routing, while the other options require manual configuration for multi-site scenarios.

How to eliminate wrong answers

Option B is wrong because Azure VPN Gateway (site-to-site) with BGP requires manual configuration of multiple VPN tunnels and BGP peering for each branch, lacking the centralized management and automatic routing that Virtual WAN provides. Option C is wrong because Azure ExpressRoute with Microsoft peering only provides private connectivity to Azure, not site-to-site connectivity between branch offices, and does not include VPN support or automatic routing management across multiple sites. Option D is wrong because Azure Virtual Network peering connects only Azure virtual networks, not on-premises networks, and cannot provide site-to-site connectivity between branch offices or support VPN/ExpressRoute connections.

219
MCQhard

A company is planning to migrate a legacy application to Azure VMs. The application requires a static IP address for licensing purposes. The VM must be highly available within a single region. Which combination of Azure resources should they use?

A.Application Gateway with a static frontend IP and virtual machine scale set
B.Standard Load Balancer with a static frontend IP and availability set
C.Basic Load Balancer with a static frontend IP and availability zone
D.Azure Front Door with a static backend IP and VM in an availability zone
AnswerB

The Standard Load Balancer is a Layer-4 (TCP/UDP) service that supports a static frontend IP address and can route traffic to a backend pool of VMs deployed within an availability set. An availability set spreads virtual machines across multiple fault domains and update domains, ensuring that a hardware failure or planned maintenance does not take down all instances at once. This configuration directly matches common legacy migration requirements: a fixed IP for client whitelisting and resilient handling of raw TCP/UDP sessions.

Why this answer

A Standard Load Balancer with a static frontend IP provides a fixed IP address for licensing, and an availability set ensures high availability by distributing VMs across fault and update domains within a single region. This combination meets the requirement for a static IP and regional HA without needing scale-out or global routing.

Exam trap

The trap here is that candidates often confuse availability zones with availability sets, assuming zones provide better HA, but for a single-region legacy app with a static IP, an availability set is the correct choice because it offers fault domain redundancy without the complexity of multi-zone deployment.

How to eliminate wrong answers

Option A is wrong because an Application Gateway is a Layer 7 load balancer with SSL termination and URL routing, which is unnecessary for a simple static IP requirement; a VM scale set implies auto-scaling, which is not required for a single legacy application. Option C is wrong because a Basic Load Balancer does not support availability zones, and using an availability zone would place the VM in a single zone, not providing high availability across the region. Option D is wrong because Azure Front Door is a global load balancer with a static backend IP, but it requires a public backend IP and is designed for multi-region scenarios, not single-region HA; an availability zone alone does not provide fault domain redundancy like an availability set.

220
Drag & Dropmedium

Drag and drop the steps to set up Azure Key Vault for storing secrets and access them from an Azure function into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for setting up Azure Key Vault with an Azure function begins with creating the vault, then adding the secret. Next, grant the function app's managed identity access to the vault (using an access policy). After that, configure app settings or references in the function app to point to the secret.

Finally, test the function to ensure it can retrieve the secret successfully. Common mistakes include misordering the grant access and configure references steps, or attempting to add secrets or configure references before the vault exists.

221
MCQhard

A healthcare organization is deploying a new application on Azure that will handle Protected Health Information (PHI). The application must be compliant with HIPAA. The security team requires encryption at rest and in transit, and the ability to audit access to the data. The solution should minimize administrative overhead. Which storage solution should you recommend?

A.Azure SQL Database with Transparent Data Encryption and Always Encrypted
B.Azure Cosmos DB with encryption at rest
C.Azure SQL Managed Instance with customer-managed keys
D.SQL Server on Azure Virtual Machine with BitLocker
AnswerA

Azure SQL Database is a managed PaaS offering that automatically handles high availability, backups, and patching while providing built-in Transparent Data Encryption (TDE) for at-rest encryption and Always Encrypted to protect sensitive columns in transit and client-side. Always Encrypted ensures encryption keys are never exposed to the database engine, adding a strong separation-of-duties layer, and the service natively supports auditing for compliance.

Why this answer

Azure SQL Database provides encryption at rest via Transparent Data Encryption (TDE), which is enabled by default, and encryption in transit via TLS. It also supports Always Encrypted to protect sensitive data client-side, ensuring PHI is never exposed to database administrators. Built-in auditing tracks access, and as a PaaS service, it minimizes administrative overhead compared to SQL Managed Instance or IaaS.

Exam trap

Candidates may choose Azure SQL Managed Instance with customer-managed keys (Option C) thinking it is more HIPAA-compliant, but customer-managed keys increase administrative overhead. Azure SQL Database with service-managed keys is equally HIPAA-compliant and simpler to manage, while still supporting TDE and Always Encrypted.

How to eliminate wrong answers

Option B is wrong because Azure Cosmos DB with encryption at rest only provides encryption at rest, not encryption in transit with the granularity needed for PHI compliance, and lacks built-in auditing capabilities for access to specific data items. Option C is wrong because Azure SQL Managed Instance with customer-managed keys adds administrative overhead for key management (e.g., using Azure Key Vault) and does not inherently provide encryption in transit via Always Encrypted, which is required for HIPAA. Option D is wrong because SQL Server on Azure Virtual Machine with BitLocker requires manual configuration for encryption in transit (e.g., SSL/TLS), adds significant administrative overhead for patching and backups, and does not offer the same level of integrated auditing as Azure SQL Database.

222
MCQmedium

A company wants to deploy containerized microservices on Azure without managing virtual machines. The solution must support automatic scaling based on demand, built-in load balancing, rolling updates for zero-downtime deployments, and a fully managed platform. Which Azure compute service should they choose?

A.Azure Container Apps
B.Azure Container Instances
C.Azure Batch
D.Azure Functions
AnswerA

Azure Container Apps is a serverless platform for running containers. It provides automatic scaling based on HTTP traffic or events, built-in load balancing, and supports rolling updates via revisions. It abstracts away underlying infrastructure, so no VMs to manage.

Why this answer

Azure Container Apps is the correct choice because it provides a fully managed, serverless platform for running containerized microservices without managing virtual machines. It supports automatic scaling based on HTTP traffic or events, built-in load balancing via Envoy, and rolling updates with revision management to ensure zero-downtime deployments. This aligns perfectly with the requirement for a fully managed platform that abstracts away infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Container Instances (ACI) with a managed orchestration solution, but ACI lacks the automatic scaling, load balancing, and rolling update capabilities that Container Apps provides for microservices.

How to eliminate wrong answers

Option B (Azure Container Instances) is wrong because it is designed for running individual containers on demand without built-in orchestration, automatic scaling, or rolling update capabilities—it lacks the microservice management features required. Option C (Azure Batch) is wrong because it is a job-scheduling service for high-performance computing (HPC) and parallel workloads, not for deploying containerized microservices with load balancing and rolling updates. Option D (Azure Functions) is wrong because it is a serverless compute service for event-driven code (functions), not for running containerized microservices; it does not support container orchestration or rolling updates for containers.

223
MCQeasy

A company is deploying a web application that must be accessible from the internet. The application is hosted on Azure virtual machines in a virtual network. The solution must provide SSL termination, web application firewall (WAF) protection, and URL path-based routing (e.g., /api/* to one backend pool, /app/* to another). The web tier must not be directly exposed to the internet. Which Azure load balancing solution should they use?

A.Azure Application Gateway v2
B.Azure Front Door
C.Azure Load Balancer
D.Azure Traffic Manager
AnswerA

Azure Application Gateway v2 is a regional Layer 7 reverse proxy that performs SSL termination, web application firewall (WAF) inspection, and URL path-based or multi-site routing. It can be configured with a public front-end IP and a backend pool containing VMs with only private IPs, making it ideal for protecting an internet-facing web tier. The v2 SKU adds auto-scaling and zone redundancy, with the WAF policy enforcing OWASP rule sets at the HTTP edge.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that provides SSL termination, a web application firewall (WAF), and URL path-based routing. It can route traffic to different backend pools based on URL paths (e.g., /api/* and /app/*) while keeping the web tier isolated within the virtual network, as the gateway itself is exposed to the internet.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway, but Front Door is designed for global, multi-region scenarios and cannot provide direct VNet integration for a single-region app without exposing backend public IPs, whereas Application Gateway is the correct Layer 7 solution for a single-region VNet deployment.

How to eliminate wrong answers

Option B (Azure Front Door) is wrong because it is a global, multi-region load balancer and application delivery network that operates at the edge, not within a single virtual network; it cannot provide direct SSL termination and WAF for a single-region VNet-hosted app without exposing the backend to the internet via public endpoints. Option C (Azure Load Balancer) is wrong because it operates at Layer 4 (TCP/UDP) and cannot perform SSL termination, WAF inspection, or URL path-based routing. Option D (Azure Traffic Manager) is wrong because it is a DNS-based traffic router that only directs clients to endpoints based on DNS resolution, not a proxy that can terminate SSL, apply WAF rules, or route based on URL paths.

224
MCQhard

Your organization is migrating a legacy on-premises application to Azure. The application uses a monolithic architecture and requires high availability. The application tier runs on Windows Server and uses a SQL Server database. You need to design a migration strategy that minimizes changes to the application code while maximizing availability. The application can be stateless if session state is externalized. You have the following requirements: (1) The application must be resilient to Azure region failures. (2) The database must have an RPO of 5 minutes and RTO of 1 hour. (3) The migration must be completed within 6 months. (4) The solution should use platform-as-a-service (PaaS) services where possible to reduce operational overhead. Which approach should you recommend?

A.Rehost the application on Azure VMs in an availability set and use SQL Server Always On Availability Groups.
B.Migrate the web tier to Azure App Service with staging slots and use Azure SQL Database with active geo-replication.
C.Refactor the application into microservices and deploy to Azure Kubernetes Service.
D.Containerize the application using Docker and deploy to Azure Container Instances in paired regions.
AnswerB

Azure App Service with staging slots gives you zero-downtime deployments through slot swaps, and you can use external session state (e.g., Redis Cache) so the web tier can scale out. Azure SQL Database with active geo-replication creates a readable secondary in a paired region, supporting manual or automatic failover to meet RPO/RTO targets. This PaaS solution requires minimal or no code changes—much less than a microservices refactor—and offloads patching, high availability, and backup management to the platform.

Why this answer

It uses Azure App Service (PaaS) to host the stateless web tier with staging slots for zero-downtime deployments and Azure SQL Database with active geo-replication to meet the RPO of 5 minutes and RTO of 1 hour. This approach minimizes code changes by externalizing session state (e.g., using Azure Cache for Redis) and leverages PaaS to reduce operational overhead while providing regional failover resilience.

Exam trap

The trap here is that candidates often choose Option A (rehost on VMs with Always On Availability Groups) because it seems familiar for SQL Server high availability, but they overlook the requirement to minimize operational overhead and the need for regional resilience, which PaaS services like App Service and Azure SQL Database with active geo-replication address more effectively.

How to eliminate wrong answers

Option A is wrong because rehosting on Azure VMs with an availability set only protects against datacenter failures within a single region, not Azure region failures, and it increases operational overhead (IaaS management) rather than using PaaS. Option C is wrong because refactoring into microservices and deploying to AKS requires significant code changes and a longer migration timeline, contradicting the requirement to minimize code changes and complete migration within 6 months. Option D is wrong because Azure Container Instances in paired regions does not provide built-in high availability or automated failover for the database tier, and it lacks the session state externalization and PaaS database capabilities needed to meet the RPO/RTO targets.

225
MCQmedium

A company is designing an Azure Kubernetes Service (AKS) cluster for a microservices application. They need to ensure that pods can securely access Azure resources such as Azure Key Vault and Azure SQL Database without using service principals or connection strings. Which AKS feature should they enable?

A.Azure RBAC for Kubernetes authorization
B.Azure Policy for AKS
C.Microsoft Entra Workload ID
D.Azure CNI network plugin
AnswerC

Microsoft Entra Workload ID is the correct solution because it creates a federated identity credential that lets a Kubernetes pod authenticate to Azure services using an Azure AD workload identity. This identity is automatically projected into the pod as a token, enabling secure, passwordless access to Azure resources like Azure SQL or Blob Storage without storing secrets. It directly solves the required scenario by mapping the application's identity to Azure resource permissions.

Why this answer

Microsoft Entra Workload ID (formerly Azure AD Workload Identity) enables pods in AKS to authenticate to Azure resources like Key Vault and Azure SQL Database using federated identity credentials, eliminating the need for service principals or connection strings. It works by projecting an Entra ID-managed identity into the pod via a sidecar or mutating webhook, allowing the pod to obtain tokens directly from the Microsoft identity platform.

Exam trap

The trap here is that candidates often confuse Azure RBAC for Kubernetes authorization (which controls Kubernetes API permissions) with Azure RBAC for Azure resources, or assume that Azure CNI or Azure Policy can somehow provide identity-based access to Azure services.

How to eliminate wrong answers

Option A is wrong because Azure RBAC for Kubernetes authorization controls access to Kubernetes resources (e.g., pods, deployments) within the cluster, not access to external Azure services like Key Vault or SQL Database. Option B is wrong because Azure Policy for AKS enforces compliance and governance rules on the cluster (e.g., restricting container privileges), but does not provide identity-based authentication to Azure resources. Option D is wrong because Azure CNI (Container Networking Interface) provides IP-per-pod networking and VNet integration, but has no role in identity management or secure access to Azure services.

← PreviousPage 3 of 4 · 241 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design infrastructure solutions questions.