Courseiva

CCNA Design infrastructure solutions Questions

16 of 241 questions · Page 4/4 · Design infrastructure solutions · Answers revealed

226
MCQeasy

Refer to the exhibit. You deploy this ARM template to a resource group in the East US region. You specify the parameter storageAccountType as 'Standard_GRS'. Which of the following is true about the deployed storage account?

A.The storage account name will be 'storage' followed by a random string.
B.The storage account will be deployed in the same region as specified by the parameter.
C.The storage account is zone-redundant and replicates data across availability zones.
D.The storage account is geo-redundant and replicates data to a paired region.
AnswerD

The sku.name value Standard_GRS explicitly designates Geo-Redundant Storage. This tier writes data to three copies in the primary region and then asynchronously copies it to a Microsoft-chosen paired secondary region. Therefore, the storage account is indeed geo-redundant and replicates its contents across a regional pair, which matches the statement exactly.

Why this answer

The parameter 'storageAccountType' is set to 'Standard_GRS', which specifies geo-redundant storage (GRS). GRS replicates your data synchronously three times within a single region using LRS, then asynchronously replicates to a paired secondary region, ensuring durability even during a regional outage.

Exam trap

The trap here is that candidates confuse 'Standard_GRS' with zone-redundant storage (ZRS) or assume the parameter controls the region, when in fact the region is determined by the resource group's location and the replication type is explicitly defined by the storage account SKU.

How to eliminate wrong answers

Option A is wrong because the ARM template uses the 'uniqueString' function with the resource group ID to generate a deterministic name, not a random string; the name will be 'storage' concatenated with a unique hash. Option B is wrong because the 'location' property is set to '[resourceGroup().location]', which deploys the storage account in the same region as the resource group (East US), not as specified by the parameter. Option C is wrong because 'Standard_GRS' is geo-redundant, not zone-redundant; zone-redundant storage (ZRS) uses 'Standard_ZRS' or 'Premium_ZRS' and replicates across availability zones within a single region.

227
MCQmedium

Your company is designing a new application that will process large volumes of streaming data from IoT devices. The data will be ingested, processed in near real-time, and stored for long-term analytics. You need to design a solution that meets the following requirements: (1) Ingest up to 1 million events per second. (2) Process events with a latency of less than 10 seconds. (3) Store processed data for 7 years for compliance. (4) Enable ad-hoc querying of the stored data. Which combination of Azure services should you recommend?

A.Azure IoT Hub, Azure Stream Analytics, and Azure Cosmos DB.
B.Azure Service Bus, Azure Functions, and Azure SQL Database.
C.Azure Event Hubs, Azure Functions, and Azure Cosmos DB.
D.Azure Event Hubs, Azure Stream Analytics, and Azure Data Lake Storage Gen2.
AnswerD

This stack is correct because Azure Event Hubs is a fully managed, partition-based event ingestion service that can capture millions of events per second with low latency. Azure Stream Analytics provides a SQL-like processing engine with tumbling, hopping, and sliding windows to aggregate and filter the data in real time, and it can write output directly to Azure Data Lake Storage Gen2. ADLS Gen2 offers hierarchical namespace, fine-grained POSIX ACLs, and low per-terabyte cost, making it ideal for long-term archival that can be queried on demand by engines like Synapse, Databricks, or Power BI.

Why this answer

Azure Event Hubs can ingest up to 1 million events per second with low latency, Azure Stream Analytics processes the streaming data in near real-time (sub-10-second latency) using temporal windowing and SQL-like queries, and Azure Data Lake Storage Gen2 provides cost-effective, scalable storage for 7 years of compliance data while supporting ad-hoc querying via tools like Azure Synapse Analytics or PolyBase. This combination meets all requirements: high-throughput ingestion, low-latency processing, long-term retention, and queryability.

Exam trap

The trap here is that candidates often choose Azure Cosmos DB for storage because of its low-latency querying, but they overlook the cost and scalability requirements for 7-year compliance storage, where Azure Data Lake Storage Gen2 is the correct choice for cost-effective, queryable archival.

How to eliminate wrong answers

Option A is wrong because Azure Cosmos DB is a NoSQL database optimized for low-latency transactional workloads, not for long-term, cost-effective storage of large volumes of historical data for 7 years; it would be prohibitively expensive and lacks native ad-hoc querying over petabyte-scale data. Option B is wrong because Azure Service Bus is a message broker designed for enterprise messaging with lower throughput (typically up to 20,000 messages per second) and does not support 1 million events per second; Azure Functions has a maximum execution timeout of 10 minutes and is not designed for continuous, high-throughput stream processing with sub-10-second latency. Option C is wrong because while Azure Event Hubs handles ingestion, Azure Functions is not optimized for sustained, high-throughput stream processing (it scales per event and incurs cold-start latency), and Azure Cosmos DB is not suitable for 7-year compliance storage due to high cost and lack of native ad-hoc querying over historical data.

228
MCQhard

Your organization is migrating a legacy on-premises application to Azure. The application uses a proprietary authentication protocol that is not supported by Microsoft Entra ID. You need to integrate the application with Microsoft Entra ID without modifying the application code. What should you do?

A.Use Azure Active Directory B2C with custom policies to translate the authentication protocol.
B.Deploy Azure Active Directory Domain Services and domain-join the application servers.
C.Configure Microsoft Entra ID Application Proxy to provide secure remote access and pass through authentication.
D.Implement Azure Active Directory Connect with pass-through authentication.
AnswerC

Microsoft Entra ID Application Proxy is the correct service because it publishes on-premises legacy applications through an outbound connector on your network without requiring a VPN or DMZ. In pass-through mode, the proxy forwards requests directly to the app and lets the app perform its own authentication, which is ideal for protocols that Microsoft Entra ID cannot understand. In pre-authentication mode, it can also use Kerberos constrained delegation or header injection to enable single sign-on while keeping Microsoft Entra ID as the front-end identity provider.

Why this answer

Microsoft Entra ID Application Proxy can be configured to publish on-premises applications that use legacy authentication protocols. It acts as a reverse proxy, terminating the external connection and forwarding requests to the internal application. Because it can be set to pass through authentication without requiring any changes to the application code, it allows the proprietary authentication protocol to continue working while still integrating with Microsoft Entra ID for access control and conditional access policies.

Exam trap

The trap here is that candidates often confuse pass-through authentication (which validates passwords against on-premises AD) with Application Proxy's pass-through mode (which forwards authentication headers unchanged), leading them to incorrectly select Azure AD Connect with pass-through authentication (Option D) instead of the correct Application Proxy solution.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C with custom policies is designed for customer-facing identity scenarios and requires modifying the application to redirect authentication flows, not for pass-through of a proprietary protocol without code changes. Option B is wrong because deploying Azure AD DS and domain-joining the application servers would require the application to support Kerberos or NTLM authentication, which it does not (it uses a proprietary protocol), and it does not integrate with Microsoft Entra ID for modern authentication. Option D is wrong because Azure AD Connect with pass-through authentication is used to synchronize on-premises directory objects and validate passwords against on-premises Active Directory, but it does not proxy or translate proprietary authentication protocols for an application.

229
MCQeasy

You are designing a disaster recovery solution for a critical application running in Azure. The application uses Azure SQL Database. The recovery point objective (RPO) is 5 seconds, and the recovery time objective (RTO) is 30 minutes. Which Azure SQL Database configuration should you recommend?

A.Point-in-time restore to a different region
B.Active geo-replication
C.Auto-failover groups
D.Azure Backup for SQL Server in Azure VM
AnswerB

Active geo-replication maintains a readable secondary database in a different region using asynchronous replication with an RPO of up to 5 seconds. The application can initiate a manual failover to the secondary, which typically completes in under 30 seconds, satisfying the RTO of 30 minutes. This makes it the ideal choice for critical databases that require minimal data loss and fast recovery.

Why this answer

Active geo-replication is the correct choice because it provides a continuous, asynchronous replication of data to a secondary database in a different Azure region, enabling an RPO of 5 seconds (typically under 5 seconds) and an RTO of 30 minutes or less by manually initiating a failover. This meets the stringent RPO and RTO requirements for a critical application using Azure SQL Database.

Exam trap

The trap here is that candidates often choose auto-failover groups (Option C) because they assume automatic failover is faster, but the RTO can be longer due to the grace period and the fact that automatic failover may not trigger within 30 minutes if the primary region is degraded but not fully down.

How to eliminate wrong answers

Option A is wrong because point-in-time restore to a different region restores from backups, which have an RPO of at least 1 hour (based on backup frequency) and an RTO that can exceed several hours, failing the 5-second RPO and 30-minute RTO. Option C is wrong because auto-failover groups use the same underlying geo-replication technology but add automatic failover, which can introduce a longer RTO due to the grace period and potential data loss from the asynchronous replication, and the RPO is still typically 5 seconds but the automatic failover may not meet the 30-minute RTO if the primary region is completely unavailable. Option D is wrong because Azure Backup for SQL Server in Azure VM is designed for SQL Server on VMs, not Azure SQL Database, and its RPO is typically 1 hour or more with an RTO that can be hours, making it unsuitable for the stated requirements.

230
MCQhard

Refer to the exhibit. You are analyzing a deployment of Azure Storage account with customer-managed key encryption. The deployment fails with an error indicating that the key vault is not accessible. Which of the following is the most likely cause?

A.The key vault name is misspelled in the keyUri
B.The key vault has a firewall enabled and does not allow access from the storage account
C.The key vault is in a different Azure region than the storage account
D.The user-assigned managed identity does not have permissions to access the key
AnswerD

For a storage account using a customer-managed key with a user-assigned managed identity, that identity must be explicitly granted at least get, wrapKey, and unwrapKey permissions on the key vault through an access policy or Azure RBAC (for example, the 'Key Vault Crypto Service Encryption User' role). Without these key-level permissions, Azure Storage cannot retrieve the encryption key or perform wrap/unwrap operations, resulting in a 403 Forbidden error when the storage account attempts to access the keyUri. This matches the symptom and is the correct root cause when other configuration settings like network rules and key version are verified correct.

Why this answer

When using customer-managed keys (CMK) with Azure Storage encryption, the storage account must authenticate to the key vault to retrieve the key. If a user-assigned managed identity is specified in the encryption policy, that identity must have at least 'Get', 'Wrap Key', and 'Unwrap Key' permissions on the key vault. Without these permissions, the storage account cannot access the key, resulting in a deployment failure with a 'key vault not accessible' error.

Exam trap

The trap here is that candidates often assume the error is due to a network firewall or a naming mistake, but Azure explicitly requires the managed identity to have cryptographic permissions on the key vault, and the error message 'not accessible' is a generic wrapper for permission failures.

How to eliminate wrong answers

Option A is wrong because a misspelled keyUri would cause a different error (e.g., 'KeyVaultKeyNotFound' or 'InvalidKeyUri'), not a generic 'key vault not accessible' error; the error message specifically indicates the vault itself is unreachable, not that the key name is incorrect. Option B is wrong because while a key vault firewall can block access, the error message 'key vault is not accessible' in the context of CMK deployment typically points to a permissions issue rather than a network restriction; if the firewall were the cause, the error would more likely indicate a network connectivity failure or a 'Forbidden' response. Option C is wrong because Azure Key Vault and Azure Storage can be in different regions when using CMK; there is no regional dependency requirement for this integration.

231
MCQmedium

A multinational company plans to deploy a new application on Azure. The application must comply with GDPR and requires data residency in the EU. The solution should minimize latency for users in Europe and provide disaster recovery across regions. Which Azure architecture should the company implement?

A.Deploy the application in two EU regions with Azure Front Door and Azure SQL Database geo-replication.
B.Deploy the application in a single Azure region in Ireland with Azure Site Recovery for DR.
C.Deploy the application in two EU regions with Azure Traffic Manager and Azure Cosmos DB multi-region writes.
D.Deploy the application in a single EU region with Azure Site Recovery and Azure Redis Cache.
AnswerC

This option correctly satisfies both the low-latency and EU-data-residency requirements. Azure Traffic Manager performs DNS-based traffic routing to the nearest available regional endpoint, so users are directed to the closest of the two EU-deployed regions, reducing network round-trip time, while Azure Cosmos DB in multi-region write mode allows the application to write and read in either EU region with replication confined to the configured EU geography. Because Cosmos DB multi-region writes provide active-active replication with automatic failover and 99.999% availability, the solution achieves resilience across two EU regions without requiring cross-region data egress. Traffic Manager and Cosmos DB together give both geo-routing and globally distributed data plane behavior, but when all regions are within the EU, data stays inside EU boundaries.

Why this answer

It meets all requirements: deploying in two EU regions ensures data residency within the EU, Azure Traffic Manager provides low-latency routing for European users via DNS-based traffic distribution, and Azure Cosmos DB multi-region writes enable active-active disaster recovery with automatic failover and no data loss, minimizing latency for writes across regions.

Exam trap

The trap here is that candidates often confuse Azure Front Door (HTTP/HTTPS layer 7) with Azure Traffic Manager (DNS layer 4) and assume SQL Database geo-replication provides zero data loss, but Cosmos DB multi-region writes are the only option that guarantees RPO=0 for active-active DR across EU regions.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database geo-replication is asynchronous, which can lead to data loss during a disaster (RPO > 0), and Azure Front Door is primarily an HTTP/HTTPS load balancer with global anycast, not optimized for DNS-based regional failover as required for disaster recovery across two EU regions. Option B is wrong because deploying in a single region violates the disaster recovery requirement; Azure Site Recovery alone cannot provide cross-region DR without a secondary region, and a single region cannot ensure low latency for all European users. Option D is wrong because a single EU region fails to meet the disaster recovery requirement, and Azure Redis Cache is an in-memory cache that does not provide data persistence or geo-replication for DR, nor does it address multi-region latency.

232
MCQhard

You are designing a network topology for a global e-commerce company that operates multiple web applications. The company has three main offices (New York, London, Tokyo) connected via ExpressRoute to Azure. Users access the applications through a public endpoint. The company requires that traffic be routed to the nearest healthy application instance based on geographic location, and that the solution provide automatic failover if an entire region goes down. Additionally, the company wants to protect against DDoS attacks at the network layer. You need to recommend a solution that meets these requirements while minimizing cost. What should you include in the design?

A.Deploy Azure Front Door with geographic routing and enable DDoS protection.
B.Deploy Azure Firewall in each region and use Public IP prefix for egress.
C.Deploy Azure Application Gateway v2 with WAF in each region and Azure DDoS Standard protection.
D.Deploy Azure Traffic Manager with geographic routing and Azure DDoS Standard protection.
AnswerA

Azure Front Door is the correct choice for a global e-commerce topology because it operates as a single anycast global endpoint, automatically routing users to the nearest region via its distributed edge network. It natively supports geographic routing to enforce data residency or direct customer traffic based on country/region, and it integrates with Azure WAF and Azure DDoS Standard, providing both L7 and L3/L4 protection at the edge. This combination gives you global load balancing, low-latency access, and comprehensive security without needing to manage per-region ingress gateways.

Why this answer

Azure Front Door with geographic routing directs users to the nearest healthy application instance based on geographic location, and it provides automatic failover if an entire region goes down by routing traffic to the next closest healthy region. Front Door also includes built-in DDoS protection at the network layer (Azure DDoS Basic) at no additional cost, which meets the DDoS requirement while minimizing cost. This combination satisfies all requirements without the need for separate, more expensive services.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager with Azure Front Door, assuming Traffic Manager's geographic routing and DNS-level failover are sufficient, but they overlook that Traffic Manager lacks built-in DDoS protection and application-layer features, and that Front Door provides a more cost-effective all-in-one solution for global load balancing with DDoS protection.

How to eliminate wrong answers

Option B is wrong because Azure Firewall is a stateful firewall for controlling outbound and inbound traffic, not a global load balancer with geographic routing, and it does not provide automatic failover across regions or DDoS protection at the network layer. Option C is wrong because Azure Application Gateway v2 is a regional load balancer that cannot route traffic based on geographic location across global regions, and while it supports WAF, it requires Azure DDoS Standard (which incurs additional cost) to protect against network-layer DDoS attacks. Option D is wrong because Azure Traffic Manager with geographic routing can route based on location and provide failover, but it does not include built-in DDoS protection; you would need to add Azure DDoS Standard separately, increasing cost, and Traffic Manager operates at the DNS level, not at the application layer, which can introduce latency and lacks features like SSL offloading and caching that Front Door provides.

233
MCQeasy

A company plans to migrate a legacy web application to Azure. The application runs on multiple Windows virtual machines (VMs) in an availability set. The VMs must be exposed to the internet via a single endpoint that performs SSL termination and health checks. The load-balancing solution must preserve the original client IP address for logging purposes. Which Azure service should the company use?

A.Azure Load Balancer (Standard)
B.Azure Application Gateway v2
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway v2 is the appropriate choice because it is a regional layer-7 reverse proxy that terminates SSL/TLS at the gateway, offloading certificate management from the web servers. It supports cookie-based session affinity, URL-based routing, and a built-in web application firewall (WAF), while preserving the original client IP via the X-Forwarded-For request header. The v2 SKU also provides autoscaling, high availability, and a resilient static VIP, aligning well with a single-region legacy web application migration.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that supports SSL termination, health probes, and provides a single public endpoint. It preserves the original client IP address by inserting the X-Forwarded-For header in the HTTP request, which the backend VMs can read for logging. This meets all requirements: single internet-facing endpoint, SSL offload, health checks, and client IP preservation.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming that any load balancer can terminate SSL and preserve client IP, but only Layer 7 services can inspect HTTP headers and perform SSL offload natively.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer (Standard) operates at Layer 4 (TCP/UDP) and does not support SSL termination or HTTP-level health checks; it also preserves client IP only via Direct Server Return (DSR) mode, which is not suitable for SSL termination and adds complexity. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not perform SSL termination or health checks at the application layer; it only directs traffic based on DNS resolution and cannot preserve the original client IP in the HTTP headers. Option D is wrong because Azure Front Door is a global Layer 7 service that does support SSL termination and health checks, but it is designed for global distribution and CDN scenarios, not for a single regional endpoint; it also modifies the client IP by default (inserting X-Forwarded-For but also adding its own IP), which can complicate logging if only a single regional endpoint is needed.

234
MCQmedium

A company deploys a containerized microservices application on Azure Kubernetes Service (AKS). They need to expose the application to the internet with TLS termination and provide a single endpoint for multiple services. The solution must also include a Web Application Firewall (WAF). Which Azure service should they use as the ingress controller?

A.Azure Application Gateway with WAF
B.Azure Front Door with WAF
C.Azure Load Balancer with TLS termination
D.Azure Traffic Manager with health probes
AnswerA

Azure Application Gateway with WAF is correct because the Application Gateway Ingress Controller (AGIC) runs inside AKS and watches Kubernetes Ingress resources, translating them into routing rules on the gateway. This allows TLS termination and WAF inspection at a single public endpoint, with L7 HTTP/S routing directly to the appropriate microservices. Unlike L4 or DNS-level services, it understands application paths, hostnames, and headers, making it a true ingress controller for AKS.

Why this answer

Azure Application Gateway with WAF is the correct choice because it is a regional, layer-7 load balancer that can act as an ingress controller for AKS. It provides TLS termination at the gateway and integrates a Web Application Firewall (WAF) to protect against common web exploits. This allows a single public endpoint to route traffic to multiple microservices within the AKS cluster based on URL paths or host headers.

Exam trap

The trap here is that candidates often confuse Azure Front Door (global, edge-based) with Application Gateway (regional, cluster-facing), assuming both can serve as an AKS ingress controller, but only Application Gateway integrates natively with AKS via AGIC for internal cluster routing.

How to eliminate wrong answers

Option B is wrong because Azure Front Door is a global, multi-region load balancer and application delivery controller, not a regional ingress controller for AKS; it is designed for global HTTP(S) load balancing and WAF at the edge, not for terminating TLS and routing directly into a single AKS cluster's internal services. Option C is wrong because Azure Load Balancer operates at layer 4 (TCP/UDP) and does not support TLS termination or WAF; it cannot inspect HTTP headers or perform path-based routing. Option D is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that operates at layer 3/4 and does not provide TLS termination, WAF, or HTTP-level routing; it only directs traffic to endpoints based on DNS resolution.

235
MCQhard

You are designing a storage solution for a healthcare application that stores patient records. The solution must meet the following requirements: - Support for both structured and unstructured data. - Provide low-latency access to frequently accessed data. - Automatically move cold data to a lower-cost tier. - Encrypt data at rest using customer-managed keys. Which combination of Azure services should you recommend?

A.Azure Table Storage for structured data and Azure Blob Storage for unstructured data
B.Azure Files for unstructured data and Azure SQL Database for structured data
C.Azure Blob Storage for unstructured data and Azure Cosmos DB for structured data
D.Azure Blob Storage for unstructured data and Azure SQL Database for structured data
AnswerC

Azure Blob Storage provides multiple access tiers and lifecycle management policies, enabling automated movement of unstructured data (e.g., medical images, text reports) to cool or archive storage based on age, significantly reducing costs. Azure Cosmos DB offers single-digit millisecond read/write latency for structured healthcare data, with guaranteed throughput and global distribution, which is essential for electronic health records and real-time patient monitoring. Both services support customer-managed keys (CMK) for encryption at rest, meeting the healthcare industry's strict compliance and security requirements.

Why this answer

Azure Cosmos DB provides low-latency access to structured data with multi-region writes and automatic indexing, while Azure Blob Storage handles unstructured data like medical images. Both services support encryption at rest with customer-managed keys via Azure Key Vault, and Blob Storage offers lifecycle management policies to automatically move cold data to lower-cost tiers like Cool or Archive.

Exam trap

The trap here is that candidates often assume Azure SQL Database is the only option for structured data, overlooking Cosmos DB's superior low-latency and global distribution capabilities, and they forget that Blob Storage's lifecycle management is the key to automated cold data tiering.

How to eliminate wrong answers

Option A is wrong because Azure Table Storage is a NoSQL key-value store that lacks the low-latency guarantees and global distribution of Cosmos DB, and it does not natively support customer-managed keys for encryption at rest. Option B is wrong because Azure Files is a fully managed file share for SMB protocol, not optimized for unstructured data like images or documents, and Azure SQL Database does not automatically tier cold data to lower-cost storage. Option D is wrong because Azure SQL Database, while supporting customer-managed keys, does not automatically move cold data to a lower-cost tier; it requires manual scaling or use of elastic pools, and it is not designed for unstructured data.

236
MCQhard

A company has a hub-spoke network topology in Azure. They have multiple spoke VNets connected to a hub VNet via peering. They need to ensure that all east-west traffic between spoke VNets goes through a network virtual appliance (NVA) in the hub for inspection. Additionally, all outbound internet traffic from spoke VMs must use a single public IP address. What should they configure?

A.Configure spoke VNets with a default route to the NVA IP, and deploy a NAT gateway in the hub for outbound traffic.
B.Configure a route table in each spoke with a route to the hub NVA for inter-spoke traffic, and use Azure Firewall in the hub for outbound internet traffic.
C.Enable 'Allow gateway transit' on the hub VNet and 'Use remote gateways' on the spoke VNets for the NVA.
D.Configure VNet peering with 'Allow forwarded traffic' enabled, add user-defined routes in each spoke pointing to the NVA IP for inter-spoke traffic, and use Azure Firewall in the hub for outbound internet with a default route in spokes.
AnswerD

This is the correct design because the hub NVA is placed as a next-hop for inter-spoke traffic via user-defined routes (UDRs) in each spoke route table, and enabling 'Allow forwarded traffic' on the peering lets the NVA accept and route packets between the connected VNets. For outbound internet access, Azure Firewall in the hub provides centralized egress, and a default route (0.0.0.0/0) in the spoke UDRs sends internet-bound traffic to the firewall's private IP. This combination cleanly separates east-west (NVA) and north-south (firewall) traffic while meeting the requirement for a single public IP and controlled routing.

Why this answer

It combines two critical configurations: user-defined routes (UDRs) in each spoke VNet force inter-spoke traffic through the NVA in the hub by specifying the NVA's IP as the next hop, and 'Allow forwarded traffic' on the VNet peering enables the hub NVA to forward packets between spokes. For outbound internet traffic, Azure Firewall in the hub provides a single public IP, and a default route (0.0.0.0/0) in the spoke UDRs directs all internet-bound traffic to the Azure Firewall's private IP, ensuring centralized inspection and egress.

Exam trap

The trap here is that candidates often forget to enable 'Allow forwarded traffic' on the VNet peering, assuming UDRs alone are sufficient for transitive routing through an NVA, or they confuse 'Allow gateway transit' with NVA forwarding, which is a common misstep in hub-spoke design questions.

How to eliminate wrong answers

Option A is wrong because a NAT gateway in the hub does not inspect traffic; it only provides source network address translation (SNAT) for outbound connections, failing the inspection requirement. Option B is wrong because while it correctly uses Azure Firewall for outbound traffic, it omits the critical 'Allow forwarded traffic' setting on the VNet peering, without which the hub NVA cannot forward packets between spoke VNets even with UDRs in place. Option C is wrong because 'Allow gateway transit' and 'Use remote gateways' are used for VPN/ExpressRoute gateway sharing, not for routing traffic through an NVA; these settings do not force inter-spoke traffic through the NVA.

237
MCQeasy

You are designing a solution to securely store secrets, keys, and certificates for a cloud application. Which Azure service should you use?

A.Azure App Configuration
B.Azure Key Vault
C.Azure Managed HSM
D.Azure Storage
AnswerB

Azure Key Vault is the purpose-built service for securely storing secrets, encryption keys, and certificates, with granular access via Azure RBAC or vault access policies. It supports versioning, soft-delete, purge protection, and near-real-time audit logs through Azure Monitor, enabling tracking of every read, modify, and deletion operation. It is the correct choice because it is designed specifically for secret management and natively integrates with services like App Service, AKS, Azure Functions, and Logic Apps.

Why this answer

Azure Key Vault is the correct service because it is specifically designed to securely store and manage secrets, encryption keys, and certificates. It provides centralized control with hardware security module (HSM) backed keys, access policies, and audit logging, meeting the core requirement for a cloud application's secure storage.

Exam trap

The trap here is that candidates often confuse Azure App Configuration (which can store secrets with encryption but lacks HSM and key management features) with Azure Key Vault, or they over-engineer by choosing Azure Managed HSM when the simpler Key Vault meets the requirement for standard secret, key, and certificate storage.

How to eliminate wrong answers

Option A is wrong because Azure App Configuration is optimized for managing application configuration settings and feature flags, not for storing secrets, keys, or certificates; it lacks native HSM support and key rotation capabilities. Option C is wrong because Azure Managed HSM is a dedicated, single-tenant HSM solution for customers who require FIPS 140-2 Level 3 validated key management, but it is overkill and more expensive for general secret storage, and it does not natively store secrets or certificates as Azure Key Vault does. Option D is wrong because Azure Storage is a general-purpose object storage service for blobs, files, queues, and tables; it does not provide built-in access policies, key rotation, or HSM-backed encryption for secrets, and storing secrets there would require manual encryption and expose them to broader access risks.

238
MCQmedium

A logistics company runs a customer-facing web application on 20 Azure VMs behind an Azure Standard Load Balancer. The company requires a 99.99% availability SLA for the VMs. The VMs are currently all deployed in a single availability set within one Azure region. What should you recommend to meet the SLA requirement with minimal architectural changes?

A.Deploy the VMs across multiple regions and use Azure Traffic Manager for load balancing.
B.Deploy the VMs across three availability zones in the same region.
C.Keep the VMs in the availability set but add a second availability set in the same region.
D.Move the VMs to Azure Virtual Machine Scale Sets with a single placement group.
AnswerB

Availability zones provide a higher SLA (99.99%) for VMs because they are physically separate datacenters within a region, protecting against datacenter-level failures. Deploying the existing VMs across three zones in the same region meets the SLA with minimal changes to the overall architecture, as the load balancer can be zone-redundant.

Why this answer

Availability zones are physically separate datacenters within an Azure region, each with independent power, cooling, and networking. Deploying VMs across three zones provides a 99.99% SLA, higher than the 99.95% offered by availability sets. This approach requires minimal changes because the existing load balancer can be made zone-redundant, and no cross-region data replication is needed.

Exam trap

The trap here is assuming that adding more availability sets or using a single placement group scale set automatically improves the SLA, when only availability zones provide the higher 99.99% SLA.

239
MCQeasy

A company has Azure virtual networks (VNets) in three different Azure regions (West US, East US, and West Europe). They also have an on-premises data center connected to the East US region via ExpressRoute. They need to connect all VNets to each other and to the on-premises network. The solution must support transitive routing between all sites and provide centralized management of connectivity and routing policies. Which Azure service should they use?

A.VNet peering
B.Azure Virtual WAN
C.VPN Gateway
D.ExpressRoute Direct
AnswerB

Azure Virtual WAN is the correct architectural solution because it creates regional hubs connected in an any-to-any mesh, and each hub contains a fully managed virtual router with built-in VPN/ExpressRoute gateways. It provides transitive routing between VNets attached to different hubs as well as between VNets and on-premises sites, using a single, centrally managed route table and route propagation via BGP. This eliminates the need to build a full mesh of VNet peerings and gives centralized monitoring, routing, and security policy management across all regions.

Why this answer

Azure Virtual WAN is correct because it provides a hub-and-spoke architecture with built-in transitive routing between all VNets and on-premises sites. It supports automatic connectivity through Virtual Hub routers, which use BGP to propagate routes across all spokes and branches, meeting the requirement for centralized management of connectivity and routing policies.

Exam trap

The trap here is that candidates often assume VNet peering can be chained to achieve transitive routing, but Azure explicitly blocks transitive routing through peered VNets unless a network virtual appliance or Azure Virtual WAN is used.

How to eliminate wrong answers

Option A is wrong because VNet peering does not support transitive routing; peered VNets cannot route traffic through each other to reach a third VNet or on-premises network without additional user-defined routes and network virtual appliances. Option C is wrong because a VPN Gateway only provides site-to-site or point-to-site connectivity to a single VNet and does not inherently enable transitive routing between multiple VNets or centralized policy management across regions. Option D is wrong because ExpressRoute Direct is a physical port offering for dedicated private connections to Azure, not a service that provides transitive routing or centralized connectivity management between multiple VNets and on-premises networks.

240
MCQeasy

You need to design a solution to store configuration data for a cloud-native application. The configuration must be centrally managed, versioned, and accessible to multiple services without hard-coding values. Which Azure service should you use?

A.Azure App Configuration
B.Azure Cosmos DB
C.Azure Blob Storage
D.Azure Key Vault
AnswerA

Azure App Configuration is the correct choice because it is a purpose-built managed service for centrally storing and managing application configuration settings such as key-value pairs, hierarchical labels, feature flags, and dynamic refresh. It supports versioning, rollback, and composition with services like Azure Kubernetes Service, so workload configuration can be updated without redeploying. Unlike a general NoSQL store, it provides a simple configuration model and SDK integration to watch for changes and apply them at runtime.

Why this answer

Azure App Configuration is the correct choice because it is a fully managed service specifically designed for central management of application configuration and feature flags. It supports versioning of configuration key-values, provides instant access to multiple services via SDKs or REST API, and eliminates the need to hard-code values by allowing dynamic updates without redeployment.

Exam trap

The trap here is that candidates often confuse Azure Key Vault (for secrets) with Azure App Configuration (for non-secret configuration), or assume a general-purpose database like Cosmos DB can serve as a configuration store, overlooking the specialized versioning and dynamic refresh capabilities of App Configuration.

How to eliminate wrong answers

Option B (Azure Cosmos DB) is wrong because it is a NoSQL database for storing transactional or operational data, not a configuration store; it lacks built-in versioning for configuration and adds unnecessary complexity and cost. Option C (Azure Blob Storage) is wrong because it is an object storage service for unstructured data like files and backups, not designed for fine-grained, versioned configuration key-values with low-latency access from multiple services. Option D (Azure Key Vault) is wrong because it is a secrets management service for storing sensitive items like passwords and certificates, not for general configuration data; it does not support versioning of configuration values in a way that is easily consumable by application code.

241
Multi-Selectmedium

A company is designing a highly available architecture for a web application on Azure VMs. The solution must protect against both planned and unplanned downtime and provide automatic failover. Which TWO Azure services should the company use together? (Choose two.)

Select 2 answers
A.Azure Availability Zones
B.Azure Site Recovery
C.Azure Traffic Manager
D.Azure Load Balancer
E.Azure Application Gateway
AnswersA, D

Azure Availability Zones are physically separate datacenters within the same Azure region, each with independent power, cooling, and networking. By placing VM replicas across multiple zones, you ensure that a failure of one entire datacenter does not affect all instances, achieving intra-region high availability. This is the foundational building block for many HA architectures and carries a 99.99% VM SLA when two or more instances are deployed across zones.

Why this answer

Azure Availability Zones (A) protect against datacenter-level failures by distributing VMs across physically separate zones within a region, each with independent power, cooling, and networking. Azure Load Balancer (D) provides automatic failover by distributing incoming traffic across healthy VMs in a backend pool, using health probes to detect and route away from failed instances. Together, they ensure the application remains available during both planned maintenance and unplanned outages, with the Load Balancer handling traffic redirection and Availability Zones providing infrastructure redundancy.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (a disaster recovery service with RTOs of minutes to hours) with high-availability solutions that provide automatic failover within seconds, leading them to select Site Recovery instead of Availability Zones.

← PreviousPage 4 of 4 · 241 questions total

Ready to test yourself?

Try a timed practice session using only Design infrastructure solutions questions.

CCNA Design infrastructure solutions Questions — Page 4 of 4 | Courseiva