Courseiva

AZ-305 · topic practice

Design identity, governance, and monitoring solutions practice questions

This domain covers identity, governance, and monitoring design on Azure: Entra ID authentication and Conditional Access, RBAC and Azure Policy for compliance, management group and subscription hierarchy for cost and policy scoping, plus Azure Monitor, Log Analytics, and Application Insights for observability. Questions present business or security requirements and ask you to select the service, scope, or configuration that satisfies them.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design identity, governance, and monitoring solutions

What the exam tests

What to know about Design identity, governance, and monitoring solutions

Be able to map a stated requirement to the correct Entra ID, Azure Policy, RBAC, or Azure Monitor construct and choose the right scope. The single most important thing: distinguish governance controls that restrict configuration (Azure Policy) from those that restrict identities and access (RBAC, Conditional Access).

Microsoft Entra Conditional Access policies triggered by sign-in risk and user risk

Azure Policy definitions, initiatives, and remediation tasks enforcing resource compliance

Management groups, subscriptions, and resource groups for scoping RBAC and cost tracking

Azure Monitor, Log Analytics workspaces, and Application Insights for metrics, logs, and alerts

Watch out for

Common Design identity, governance, and monitoring solutions exam traps

  • ▸Confusing Azure Policy (resource compliance, deny/audit) with RBAC (who can perform actions), and applying policy at the wrong scope.
  • ▸Assuming MFA is enforced globally instead of using Conditional Access with risk-based conditions and named locations.
  • ▸Placing Log Analytics workspaces or diagnostic settings at the wrong scope, so logs from multiple subscriptions are not centralized.

Practice set

Design identity, governance, and monitoring solutions questions

20 questions · select your answer, then reveal the explanation

A company needs to monitor sign-in logs from multiple Microsoft Entra ID tenants and analyze user sign-in patterns across those tenants. Which Azure solution should they use?

A company has multiple Azure subscriptions and wants to enforce that all administrators must use multi-factor authentication (MFA) when accessing the Azure portal. They also want to monitor and report on any policy changes that affect this enforcement. Which combination of Azure services should they use?

A large enterprise has multiple Azure subscriptions and on-premises servers. They need to collect performance metrics (CPU, memory) from all servers, create custom dashboards to visualize health across workloads, and set up alerts for critical thresholds. They also need to retain log data for one year. Which combination of Azure services should they use?

Question 4hardmultiple choice
Study the full multicast explanation →

A company uses Microsoft Entra ID Privileged Identity Management (PIM) to control access to administrator roles. They want to implement a monitoring solution that sends an email to the security team whenever a user activates the Global Administrator role outside of standard business hours (9 AM–5 PM). They also need to track all activation history for quarterly audits. Which solution should they implement?

A company uses Microsoft Entra ID and wants to automate the process of granting access to internal applications and Microsoft 365 groups. Employees request access through a portal, and managers must approve the requests. The access should be automatically removed after a defined period, and managers must perform quarterly access reviews to confirm continued need. Which Microsoft Entra ID feature should they use?

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect identity-related risks such as leaked credentials, impossible travel, and sign-ins from anonymous IP addresses. They want to generate reports summarizing risk events and integrate the risk data with their existing Security Information and Event Management (SIEM) system via an API. Which Microsoft Entra ID feature should they configure?

A company uses Microsoft Entra ID. They want to allow users to sign in to partner applications using their Microsoft Entra ID credentials. The partner applications support SAML 2.0 and OpenID Connect. They also need to customize the appearance of the sign-in pages. Which Microsoft Entra ID feature should they configure?

An enterprise wants just-in-time elevation for Azure administrators and periodic validation that privileged users still require access. Which two Microsoft Entra features should you recommend? (Choose 2.)

Drag and drop the steps to configure Azure Load Balancer for high availability of web servers into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

You are designing a monitoring solution for a global e-commerce application hosted on Azure. The application experiences intermittent performance degradation that is difficult to reproduce. You need to ensure that you can capture detailed diagnostic data when the degradation occurs, without permanently storing large amounts of data. Which Azure feature should you use?

You are designing an identity governance solution for a multinational company. The company uses Microsoft Entra ID and has a requirement to automatically remove user access to critical SaaS applications when the user leaves the organization or changes roles. You need to ensure that the access removal is audited and can be reversed within 30 days if needed. What should you implement?

Refer to the exhibit. You create this Azure Policy definition in a management group that contains all subscriptions. After assigning the policy, you notice that no audit events are generated when a new custom RBAC role is created. What is the most likely reason?

Exhibit

Refer to the exhibit.
{
  "type": "Microsoft.Authorization/policyDefinitions",
  "properties": {
    "displayName": "Audit usage of custom RBAC roles",
    "policyType": "Custom",
    "mode": "All",
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Authorization/roleDefinitions"
      },
      "then": {
        "effect": "Audit",
        "details": {
          "roleDefinitionIds": ["/providers/Microsoft.Authorization/roleDefinitions/*"]
        }
      }
    }
  }
}

Your organization has a hybrid identity infrastructure with Microsoft Entra ID and on-premises Active Directory. You plan to implement Microsoft Entra ID Protection to detect and respond to identity risks. You need to ensure that risky sign-ins from anonymous IP addresses are automatically blocked, while still allowing legitimate users to self-remediate. What should you configure?

Which TWO are valid methods to authenticate to Azure from a PowerShell script that runs unattended? (Choose two.)

Your company uses Azure Policy to enforce tagging standards. You need to ensure that any new resource group automatically inherits the 'CostCenter' tag from its subscription. Which Azure Policy effect should you use?

Your company has multiple Azure subscriptions managed by a management group. You need to enforce that all resources are deployed in the West US region only. Additionally, you must allow a specific resource group in the production subscription to be deployed in East US. What should you configure?

Refer to the exhibit. You have an Azure Policy definition as shown. The policy is assigned at the subscription scope. What is the result when a user tries to create a VM with SKU Standard_D8s_v3?

Exhibit

Refer to the exhibit.

```json
{
  "policyRule": {
    "if": {
      "field": "type",
      "equals": "Microsoft.Compute/virtualMachines"
    },
    "then": {
      "effect": "deny",
      "details": {
        "field": "Microsoft.Compute/virtualMachines/sku.name",
        "notIn": ["Standard_D2s_v3", "Standard_D4s_v3"]
      }
    }
  }
}
```

Refer to the exhibit. You run the KQL query in Azure Monitor Log Analytics. Which user accounts should you investigate first?

Exhibit

Refer to the exhibit.

```kql
SigninLogs
| where TimeGenerated > ago(1d)
| where RiskLevelDuringSignIn == "medium"
| where RiskEventTypes has_any ("unfamiliarFeatures", "anonymousIPAddress")
| summarize Count = count() by UserPrincipalName
| where Count > 5
```

Refer to the exhibit. You are analyzing a deployment of a Custom Script Extension on an Azure VM. The extension fails to run. What is the most likely cause?

Exhibit

{
  "properties": {
    "targetResourceId": "/subscriptions/12345678-1234-1234-1234-123456789012/resourceGroups/prod-rg/providers/Microsoft.Compute/virtualMachines/vm-prod-01",
    "configuration": {
      "protectedSettings": {
        "commandToExecute": "powershell -ExecutionPolicy Unrestricted -File configure.ps1"
      }
    },
    "extensionType": "CustomScriptExtension",
    "publisher": "Microsoft.Compute",
    "typeHandlerVersion": "1.10"
  }
}

You have an Azure subscription that contains a virtual network named VNet1. You need to monitor all network security group (NSG) flow logs. Which three components must you enable? (Select THREE.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design identity, governance, and monitoring solutions sessions

Start a Design identity, governance, and monitoring solutions only practice session

Every question in these sessions is drawn from the Design identity, governance, and monitoring solutions domain — nothing else.

Related practice questions

Related AZ-305 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-305 exam test about Design identity, governance, and monitoring solutions?
Be able to map a stated requirement to the correct Entra ID, Azure Policy, RBAC, or Azure Monitor construct and choose the right scope. The single most important thing: distinguish governance controls that restrict configuration (Azure Policy) from those that restrict identities and access (RBAC, Conditional Access).
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design identity, governance, and monitoring solutions questions in a focused session?
Yes — the session launcher on this page draws every question from the Design identity, governance, and monitoring solutions domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-305 topics?
Use the topic links above to move to related areas, or go back to the AZ-305 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-305 exam covers. They are not copied from any real exam or dump site.