Courseiva

CCNA Infrastructure Solutions Questions

75 of 241 questions · Page 1/4 · Infrastructure Solutions topic · Answers revealed

1
MCQhard

You are designing a disaster recovery solution for a multi-tier application. The application consists of a web tier, an application tier, and a database tier running SQL Server on Azure VMs. The RPO must be 5 seconds, and the RTO must be 15 minutes. You need to recommend a SQL Server availability solution that meets these requirements. What should you use?

A.Azure SQL Database Managed Instance automatic backups
B.Azure Site Recovery with replication of SQL Server VMs
C.SQL Server log shipping
D.SQL Server Always On Availability Groups with synchronous commit and automatic failover
AnswerD

SQL Server Always On Availability Groups with synchronous commit mode writes the transaction to the primary and at least one secondary replica before acknowledging the commit, guaranteeing zero data loss and an RPO of 0 seconds. Automatic failover, when configured with two synchronous replicas and a quorum of validators, can complete in seconds to a few minutes, comfortably meeting the RTO of under 15 minutes. This is the only option that satisfies both the 5-second RPO and 15-minute RTO requirements.

Why this answer

SQL Server Always On Availability Groups with synchronous commit and automatic failover provides near-zero data loss (RPO of 5 seconds) and rapid automatic failover (RTO of 15 minutes) by replicating data synchronously across replicas. This solution meets the stringent RPO/RTO requirements for a multi-tier application running SQL Server on Azure VMs, as it ensures transactions are committed on both primary and secondary replicas before acknowledging success, and automatic failover occurs within seconds if the primary fails.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery's VM-level replication with database-level replication, overlooking that ASR's RPO/RTO are typically higher and not suitable for sub-minute RPO requirements, while log shipping is dismissed due to its manual failover and higher RPO.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database Managed Instance automatic backups have an RPO of up to 5 minutes (not 5 seconds) and an RTO measured in hours, not 15 minutes. Option B is wrong because Azure Site Recovery with replication of SQL Server VMs typically has an RPO of 30 seconds to several minutes and an RTO of 30 minutes or more, and it does not guarantee synchronous replication or automatic failover at the database level. Option C is wrong because SQL Server log shipping has an RPO of minutes (depending on backup/restore intervals) and an RTO of minutes to hours, as it requires manual failover and does not support automatic failover or synchronous replication.

2
MCQeasy

You need to design a solution to store log data from multiple Azure services. The data must be retained for 7 years for compliance purposes and should be queryable for analysis. Which Azure service should you use as the primary storage for these logs?

A.Azure Data Lake Storage
B.Azure SQL Database
C.Azure Blob Storage
D.Azure Log Analytics workspace
AnswerD

An Azure Log Analytics workspace is the correct destination because it is a purpose-built, managed log data store within Azure Monitor, where agents and other sources natively send data as structured tables. It provides Kusto Query Language (KQL) for powerful time-series filtering and joins, built-in alerting, dashboards, and configurable retention/archive policies (up to 730 days online) with long-term storage to cheaper tiers. This makes it the central repository for multi-source logs that require continuous querying and monitoring.

Why this answer

Azure Log Analytics workspace is the correct choice because it is purpose-built for ingesting, storing, and querying log data from Azure services. It supports long-term retention up to 7 years (via the Basic Logs tier or data archiving with Azure Data Explorer) and provides Kusto Query Language (KQL) for interactive analysis, meeting both compliance and queryability requirements.

Exam trap

The trap here is that candidates often choose Azure Blob Storage because it is cheap and can store logs for 7 years, but they overlook the requirement that the data must be 'queryable for analysis'—Blob Storage alone does not provide native querying, whereas Log Analytics does.

How to eliminate wrong answers

Option A is wrong because Azure Data Lake Storage is optimized for big data analytics and unstructured data at scale, not for structured log querying with built-in search capabilities; it lacks native log analytics query features. Option B is wrong because Azure SQL Database is a relational database for transactional workloads, not designed for high-volume, append-only log ingestion; it would be cost-prohibitive and inefficient for long-term log retention and querying. Option C is wrong because Azure Blob Storage is an object store for unstructured data; while it can store logs, it does not provide native querying capabilities—you would need additional services like Azure Data Lake or Log Analytics to analyze the data.

3
MCQeasy

A company plans to deploy a web application on Azure App Service that will be accessed by users worldwide. The application must have a single endpoint and use Azure Web Application Firewall (WAF) policies. Which Azure service should be placed in front of the App Service to meet these requirements?

A.Azure Application Gateway
C.Azure Front Door
D.Azure Traffic Manager
AnswerC

Azure Front Door is a global, HTTP(S)-aware application delivery and security service that offers a single anycast endpoint, global routing, TLS termination, and an integrated Web Application Firewall (WAF) that applies policies at edge locations. It can route traffic across multiple Azure regions or on-premises origins with health probes and instant failover, making it the most complete answer for a globally deployed web app. It supports path-based routing, SSL offload, and can even be layered in front of Application Gateways for deeper regional WAF/DDoS protection.

Why this answer

Azure Front Door is the correct choice because it provides a single, global endpoint with built-in Web Application Firewall (WAF) policies at the edge. It operates at Layer 7 (HTTP/HTTPS) and uses anycast routing to route user traffic to the nearest App Service instance, ensuring low latency and high availability worldwide.

Exam trap

The trap here is that candidates often confuse Azure Application Gateway with Azure Front Door, not realizing that Application Gateway is regional and cannot serve a single global endpoint, while Front Door is the only global Layer 7 service with integrated WAF.

How to eliminate wrong answers

Option A is wrong because Azure Application Gateway is a regional Layer 7 load balancer, not a global service, so it cannot provide a single endpoint for worldwide users. Option B is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and does not support WAF policies or HTTP-level routing. Option D is wrong because Azure Traffic Manager is a DNS-based traffic router that does not terminate HTTP traffic or support WAF policies; it only directs DNS queries to endpoints.

4
MCQhard

A healthcare organization is migrating a regulatory-compliant application to Azure. The application must be isolated from the internet and accessible only from on-premises networks via a private IP address. The solution must minimize latency and maximize throughput for large data transfers. Which Azure networking solution should the organization implement?

A.Azure Private Link
B.Azure VPN Gateway
C.Azure Virtual WAN
D.Azure ExpressRoute
AnswerD

Azure ExpressRoute establishes a dedicated private connection between an on-premises network and Azure through a telecommunications provider, completely bypassing the public internet and providing consistent lower latency, higher throughput, and a guaranteed SLA. This makes it the preferred choice for healthcare organizations that need to transfer large volumes of sensitive regulatory data reliably and securely. ExpressRoute also supports private peering for services such as virtual machines, and optional Microsoft peering for Azure PaaS, making it the right solution.

Why this answer

Azure ExpressRoute provides a dedicated private connection from on-premises networks to Azure, bypassing the public internet. This ensures the application is isolated from the internet, uses private IP addresses, and offers the lowest latency and highest throughput for large data transfers due to dedicated bandwidth and no internet congestion.

Exam trap

The trap here is that candidates often confuse Azure Private Link (which provides private access to PaaS services) with a private network connection from on-premises, overlooking that Private Link still requires an underlying connectivity method like ExpressRoute or VPN for on-premises access, and does not itself guarantee low latency or high throughput for large transfers.

How to eliminate wrong answers

Option A is wrong because Azure Private Link exposes Azure services over a private endpoint within a virtual network, but it does not provide a dedicated connection from on-premises; it still requires a VPN or ExpressRoute for on-premises access and does not inherently minimize latency or maximize throughput for large data transfers. Option B is wrong because Azure VPN Gateway uses encrypted tunnels over the public internet, which introduces higher latency, variable throughput, and potential internet congestion, failing to meet the requirements for minimized latency and maximized throughput. Option C is wrong because Azure Virtual WAN is a networking service that aggregates connectivity (including VPN and ExpressRoute), but by itself it does not provide a dedicated private connection; it is a management and orchestration layer, not the direct connectivity solution for isolated, low-latency, high-throughput data transfers.

5
MCQeasy

A company needs to provide secure remote administration access to Azure virtual machines for their IT team. The VMs are in a virtual network with no public IP addresses. The IT team uses browsers to connect. The solution should not require any custom software on the client machines. Which Azure service should they use?

A.Azure Bastion
B.Just-in-Time VM access
C.Azure VPN Gateway
D.Microsoft Entra ID Domain Services
AnswerA

Azure Bastion is a fully managed PaaS service that provides browser-based RDP and SSH connectivity to virtual machines directly through the Azure portal over TLS. It is deployed inside a virtual network and brokers the connection from the portal to the VM, so the VMs do not need public IP addresses and no client software is required on the user's machine. The management ports (RDP 3389 and SSH 22) are never exposed to the public internet, and the session is rendered securely over SSL, fully satisfying the requirements for secure remote administration.

Why this answer

Azure Bastion provides secure, seamless RDP/SSH connectivity to Azure virtual machines directly in the Azure portal over TLS. Because the VMs have no public IP addresses, Bastion acts as a jump server that is deployed inside the virtual network, eliminating the need for any public exposure. Since the IT team uses browsers and cannot install custom software, Bastion's native browser-based HTML5 client meets the requirement perfectly.

Exam trap

The trap here is that candidates often confuse Just-in-Time VM access (which still requires a public IP and a client) with Bastion's fully browser-based, no-public-IP solution, or they mistakenly think a VPN gateway provides browser-based RDP/SSH without client software.

How to eliminate wrong answers

Option B (Just-in-Time VM access) is wrong because it only reduces the attack surface by temporarily opening ports on existing public IPs or NSGs; it does not eliminate the need for public IPs and still requires a client-side RDP/SSH client, not a browser. Option C (Azure VPN Gateway) is wrong because it requires installing a VPN client on each IT team member's machine and does not provide browser-based access; it also requires a public endpoint for the VPN gateway itself. Option D (Microsoft Entra ID Domain Services) is wrong because it provides managed domain services (LDAP, Kerberos, NTLM) for authentication and group policy, not remote desktop or SSH connectivity to VMs.

6
MCQeasy

Your company has a hybrid identity environment with Microsoft Entra ID and an on-premises Active Directory. You need to enable single sign-on (SSO) for users accessing Microsoft 365 applications from domain-joined devices. Which authentication method should you configure?

A.Microsoft Entra Pass-through Authentication
B.Microsoft Entra password hash synchronization
C.Microsoft Entra Seamless SSO
D.Active Directory Federation Services (AD FS)
AnswerC

Microsoft Entra Seamless SSO is the correct feature because it automatically signs in domain-joined devices when users access Azure AD resources while they are connected to the corporate network. It uses the on-premises Active Directory computer account of the user's device to obtain a Kerberos ticket, which is then presented to Azure AD through a non-interactive flow, eliminating the need for password prompts. Seamless SSO can be combined with either PHS or PTA and specifically addresses the hybrid identity need for frictionless access without deploying additional federation infrastructure.

Why this answer

Microsoft Entra Seamless SSO (C) is the correct choice because it automatically signs users in when they are on domain-joined devices connected to the corporate network, without requiring any additional prompts. It integrates with password hash synchronization or pass-through authentication to provide a true single sign-on experience for Microsoft 365 applications, leveraging Kerberos delegation to validate the user's identity against on-premises Active Directory.

Exam trap

The trap here is that candidates often confuse authentication methods that validate credentials (like Pass-through Authentication or password hash sync) with methods that provide single sign-on, forgetting that SSO requires a separate mechanism like Seamless SSO or federation to eliminate credential prompts.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Pass-through Authentication validates passwords directly against on-premises Active Directory but does not provide SSO; it still requires user interaction for credential entry. Option B is wrong because Microsoft Entra password hash synchronization synchronizes password hashes to the cloud for authentication but does not enable SSO; users must still enter their credentials unless combined with Seamless SSO. Option D is wrong because Active Directory Federation Services (AD FS) is a federated identity solution that can provide SSO, but it is more complex and heavyweight than needed for domain-joined devices accessing Microsoft 365; Seamless SSO is the simpler, recommended approach for this specific scenario.

7
MCQmedium

A company is deploying a multi-tier application on Azure. The web tier runs on Azure App Service, and the database tier runs on Azure SQL Database. The company wants to secure the connection between the web tier and the database by using a private endpoint for Azure SQL Database. They also want to ensure that the web tier can resolve the private endpoint's DNS name. What should you recommend?

A.Configure a private endpoint for Azure SQL Database and use Azure Firewall to redirect DNS queries.
B.Configure a private endpoint for Azure SQL Database and integrate an Azure Private DNS zone with the virtual network used by the web tier.
C.Configure a service endpoint for Azure SQL Database and enable Azure Private Link.
D.Configure a private endpoint for Azure SQL Database and add a custom DNS record in the Azure DNS zone for the web tier's domain.
AnswerB

A private endpoint for Azure SQL Database creates a private IP address within a virtual network. To resolve the private endpoint's DNS name, you must integrate an Azure Private DNS zone with the virtual network. This ensures that the web tier can resolve the database's FQDN to the private IP, enabling secure connectivity.

Why this answer

To securely connect to Azure SQL Database using a private endpoint, you must create the private endpoint and integrate an Azure Private DNS zone with the virtual network. The Private DNS zone automatically creates the necessary A record for the SQL server's FQDN, resolving to the private IP. This allows the web tier to connect securely without exposing traffic to the public internet.

Exam trap

The trap here is assuming that service endpoints or custom DNS records are sufficient for private endpoint resolution, but only an Azure Private DNS zone linked to the virtual network provides the correct DNS resolution.

8
MCQmedium

A company is designing a disaster recovery solution for Azure VMs running a critical application. They need a Recovery Time Objective (RTO) of less than 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The solution should be cost-effective and allow testing without affecting production. Which Azure service should they use?

A.Azure Migrate
B.Azure Backup
C.Azure Front Door
D.Azure Site Recovery
AnswerD

Azure Site Recovery orchestrates continuous, block-level replication of Azure VMs, VMware, Hyper-V, or physical servers to Azure or to a secondary site, with application-consistent snapshots that support RPOs in the single-digit minutes range. It provides automated failover and failback, alongside non-disruptive recovery drills (test failovers) that validate the recovery plan without impacting production workloads. This combination of continuous replication, orchestrated failover, and testability is why Azure Site Recovery meets the DR requirements where the other options do not.

Why this answer

Azure Site Recovery (ASR) is the correct choice because it provides orchestrated replication and failover for Azure VMs, supporting RPOs as low as 15 minutes (with continuous replication) and RTOs under 1 hour. It also enables non-disruptive test failovers in isolated networks, meeting the requirement for testing without affecting production. ASR is cost-effective for critical workloads as it only charges for replication storage and compute during failover, unlike always-on redundancy solutions.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for long-term data retention with higher RPO/RTO) with Azure Site Recovery (which is for rapid failover and replication), often overlooking the specific RPO/RTO thresholds stated in the question.

How to eliminate wrong answers

Option A is wrong because Azure Migrate is a discovery and migration tool, not a disaster recovery solution; it cannot provide ongoing replication or meet RTO/RPO targets. Option B is wrong because Azure Backup is designed for data backup with typical RPOs of 12-24 hours (or 4 hours for enhanced policy) and RTOs measured in hours to days, failing the 15-minute RPO and sub-1-hour RTO requirements. Option C is wrong because Azure Front Door is a global load balancer and application delivery controller for HTTP/S traffic, not a VM-level disaster recovery service; it does not replicate VM state or provide failover for compute resources.

9
MCQeasy

A company deploys a web application on Azure VMs in a single region. They need to distribute incoming HTTPS traffic across multiple VMs, offload SSL termination, and provide session persistence. Which Azure load balancing solution should they choose?

A.Azure Load Balancer (Standard SKU)
B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a Layer 7 load balancer that natively performs SSL termination, offloading the decryption workload from the VMs and enabling efficient certificate management. It also offers URL-based routing, cookie-based session persistence, and HTTP health probes, allowing application-aware traffic distribution across VMs within a single Azure region. These Layer 7 capabilities directly align with the web application's need for secure, sticky sessions and advanced routing.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that supports SSL termination, session persistence (via cookie-based affinity), and HTTP/HTTPS traffic distribution. Unlike Azure Load Balancer (Layer 4), it can inspect application-layer headers and offload SSL decryption, meeting all three requirements.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers handle SSL termination, but only Layer 7 solutions like Application Gateway or Front Door can offload HTTPS traffic and provide cookie-based session persistence.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL termination or application-layer session persistence; it only distributes traffic based on IP and port. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not handle SSL termination or session persistence; it directs clients to endpoints based on DNS resolution, not proxying traffic. Option D is wrong because Azure Front Door is a global Layer 7 service with SSL termination and session affinity, but it is designed for multi-region distribution and CDN scenarios, not for a single-region VM deployment where Application Gateway is the more appropriate and cost-effective choice.

10
MCQhard

Your company is deploying a critical application on Azure VMs. The application requires a static private IP address that does not change even if the VM is stopped and deallocated. The VM must be placed in an availability zone for high availability. Which networking approach should you use?

A.Use Azure Firewall to provide static private IP and load balancing.
B.Assign a static private IP address to the VM's NIC and use a standard public load balancer.
C.Use Azure Traffic Manager to assign static private IP.
D.Use Application Gateway with a static private IP.
AnswerB

Assigning a static private IP to the VM's NIC guarantees the address is retained even when the VM is deallocated, preserving internal DNS mappings and dependent integrations. A standard public load balancer provides a public frontend IP, uses health probes to verify backend availability, and forwards traffic according to load-balancing rules. Together, these two mechanisms give the application a stable private identity and robust external accessibility, which is the correct approach for a critical workload.

Why this answer

A static private IP address assigned to the VM's NIC persists even when the VM is stopped and deallocated, ensuring the application always uses the same private IP. Placing the VM in an availability zone provides high availability by protecting against zonal failures, and a standard public load balancer can distribute traffic across VMs in different zones while preserving the static private IP for each VM.

Exam trap

The trap here is that candidates often confuse the static IP assignment at the VM NIC level with the static IP of a load balancer or gateway, mistakenly thinking that a load balancer or firewall can provide a static private IP to the VM itself, when in fact the VM's NIC must be explicitly configured with a static private IP address.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a managed network security service that provides outbound/inbound filtering and SNAT, not a mechanism to assign a static private IP to a VM; it cannot guarantee a static private IP for the VM itself. Option C is wrong because Azure Traffic Manager is a DNS-based traffic routing service that operates at the DNS level and does not assign IP addresses to VMs; it directs traffic based on DNS resolution, not static private IP assignment. Option D is wrong because Application Gateway is a layer-7 load balancer that can have a static private IP, but it does not assign static private IPs to the backend VMs; the VM's NIC must be configured separately for a static private IP, and the question specifically requires the VM to have a static private IP that does not change.

11
MCQmedium

A company is designing a solution for storing sensitive documents in Azure Blob Storage. They require that all data be encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, they want to prevent any accidental deletion of the key vault and its keys. Which combination of actions should they take?

A.Assign the Key Vault Contributor role to only the security team
B.Configure firewall rules to restrict network access
C.Enable soft-delete and purge protection on the key vault
D.Enable diagnostic settings and send logs to a Log Analytics workspace
AnswerC

Soft-delete retains deleted vaults and keys for a recovery window, while purge protection blocks permanent deletion during that period. Together they satisfy the requirement to prevent accidental deletion of the key vault and its keys.

Why this answer

Enabling soft-delete and purge protection on the Azure Key Vault prevents accidental or malicious deletion of the key vault and its keys, which is essential when using customer-managed keys for encryption at rest. Soft-delete allows recovery of deleted vaults and keys within a retention period, while purge protection prevents permanent deletion until the retention period expires. Option A is incorrect because Key Vault Contributor role allows management of the vault but does not prevent deletion; in fact, it could allow authorized users to delete the vault.

Option B is incorrect because firewall rules restrict network access but do not prevent deletion of the vault itself. Option D is incorrect because diagnostic settings and logging only provide monitoring and auditing, not protection against deletion.

Exam trap

Candidates might mistakenly choose RBAC roles (Option A) believing that restricting role assignments prevents deletion, but RBAC does not block deletion by users who are assigned the Contributor role. The actual protection against deletion comes from soft-delete and purge protection.

12
Multi-Selectmedium

Which TWO of the following are valid design considerations for implementing Azure SQL Database geo-replication? (Choose two.)

Select 2 answers
A.Geo-replication ensures zero data loss during failover
B.Geo-replication supports up to four readable secondary replicas
C.Geo-replication provides automatic failover without manual intervention
D.Geo-replication requires a listener for client connections
E.Geo-replication can be used to offload read-only workloads
AnswersB, E

Azure SQL Database active geo-replication is a valid design consideration because it supports establishing up to four readable secondary replicas. This technical mechanism allows organisations to distribute read workloads across multiple Azure regions, significantly enhancing disaster recovery capabilities and regional resilience. Designing with multiple secondaries facilitates robust business continuity planning and global read-scale scenarios, directly addressing the need for resilient database architectures.

Why this answer

Azure SQL Database geo-replication supports up to four readable secondary replicas, which can be used for read-only query offloading and disaster recovery. Option E is correct because these secondary replicas are fully readable, allowing you to distribute read-only workloads to reduce load on the primary database.

Exam trap

The trap here is that candidates confuse geo-replication with Auto-Failover Groups, assuming geo-replication alone provides automatic failover and zero data loss, when in fact it only supports manual failover with asynchronous replication.

13
MCQhard

A healthcare company is designing a new Azure solution that must comply with HIPAA. The solution will store patient records in Azure Blob Storage and must ensure that data is encrypted at rest using customer-managed keys. The company also requires that the encryption keys be stored in a hardware security module (HSM) and that they have full control over key rotation. Which Azure service should the solutions architect use to meet these requirements?

A.Azure Disk Encryption
B.Azure Dedicated HSM
C.Azure Key Vault Managed HSM
D.Azure Key Vault (standard tier)
AnswerC

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant HSM service that enables you to store cryptographic keys in FIPS 140-2 Level 3 validated HSMs. It supports customer-managed keys for Azure Storage encryption and provides full control over key rotation, directly satisfying the HIPAA compliance and HSM requirements.

Why this answer

Azure Key Vault Managed HSM provides HSM-backed keys with full customer control, meeting the HIPAA and key rotation requirements. It integrates with Azure Storage for customer-managed keys, allowing the healthcare company to encrypt Blob Storage using keys stored in a hardware security module. Other options either lack HSM backing, are not integrated with Blob Storage, or are intended for different purposes.

Exam trap

The trap here is confusing Azure Key Vault standard tier with Managed HSM; standard tier uses software-protected keys and does not satisfy the HSM requirement.

14
Multi-Selecthard

You are designing a disaster recovery (DR) solution for a critical application hosted on Azure VMs. The solution must meet the following requirements: - Recovery Point Objective (RPO) of 15 minutes. - Recovery Time Objective (RTO) of 1 hour. - Automatically fail over to a secondary region in the event of a regional outage. - Support for non-disruptive DR testing. Which THREE components should you include in the solution? (Choose three.)

Select 3 answers
A.Azure Backup
B.Azure Site Recovery test failover capability
C.Azure Site Recovery
D.Azure Traffic Manager
E.Azure Front Door
AnswersB, C, D

Azure Site Recovery's test failover capability lets you perform a real failover of replicated VMs into an isolated Network Security Group-backed test network, without affecting the production environment or the ongoing replication stream. This exercise validates the orchestration of your recovery plan, as well as the boot order, IP addressing, DNS resolution, and connectivity of your recovered workloads — essentially a no-cost dress rehearsal of DR. It directly satisfies the need to prove that a DR solution actually works before a real outage occurs.

Why this answer

Azure Site Recovery's test failover capability allows you to perform non-disruptive DR testing by isolating the test failover in a separate virtual network, ensuring no impact on the production environment. This meets the explicit requirement for non-disruptive DR testing while validating replication and failover processes.

Exam trap

The trap here is that candidates often confuse Azure Backup (data protection) with Azure Site Recovery (disaster recovery), or mistakenly think Azure Front Door can handle VM-level failover when it only operates at the application layer with HTTP/HTTPS traffic.

15
Multi-Selecthard

Which THREE considerations are important when designing a highly available Azure SQL Database solution?

Select 3 answers
A.Auto-failover groups
B.Transparent Data Encryption
C.Active geo-replication
D.Zone redundancy
E.Read scale-out
AnswersA, C, D

Auto-failover groups provide a listener endpoint and automatic failover of one or more databases to a secondary region, addressing regional outage resilience. They satisfy the high-availability design consideration for cross-region database failover in Azure SQL Database.

Why this answer

Auto-failover groups (A) are correct because they enable automatic, policy-driven failover of one or more databases to a secondary region, providing a readable/writable listener endpoint and reducing RTO/RPO for a highly available Azure SQL Database solution. Active geo-replication (C) is correct because it lets you create up to four readable secondaries in different regions and manually fail over, which is a core mechanism for cross-region high availability and disaster recovery. Zone redundancy (D) is correct because it distributes the database across availability zones within a region, protecting against datacenter-level failures and improving local availability with an SLA up to 99.995%.

Transparent Data Encryption (B) is not a high-availability consideration; it is a data-at-rest encryption feature that protects confidentiality but does not affect failover or uptime. Read scale-out (E) is a performance/read-offload capability using read-only replicas, not a high-availability design consideration, since it does not provide failover or redundancy.

Exam trap

The trap here is that candidates often confuse security features (like TDE) or performance features (like read scale-out) with high availability mechanisms, leading them to select options that do not actually provide automatic failover or regional resilience.

16
MCQmedium

Your company is migrating a legacy application to Azure. The application uses a proprietary database that requires file-level access to data files. You need to minimize changes to the application. Which Azure storage solution should you recommend?

A.Azure Files
B.Azure Disk Storage
C.Azure Blob Storage
D.Azure NetApp Files
AnswerA

Azure Files provides fully managed SMB (and optionally NFS) file shares in the cloud, accessible via standard file-sharing protocols such as SMB 3.0. Because the legacy application expects file-level access over a shared filesystem, Azure Files can be mounted as a network drive on the target VM without modifying application code, preserving existing file semantics and minimizing migration changes. It also integrates with Azure Active Directory for Kerberos-based authentication, making it a low-friction drop-in for file-level dependencies.

Why this answer

Azure Files provides fully managed SMB and NFS file shares that offer file-level access over the network, which is exactly what a legacy application requiring file-level access to data files needs. By mapping a drive to an Azure file share, the application can continue using standard file I/O APIs with minimal or no code changes, making it the correct choice for this migration scenario.

Exam trap

The trap here is that candidates often confuse Azure Disk Storage (which is block-level and attached to a single VM) with file-level access, or they overcomplicate the solution by choosing Azure NetApp Files when Azure Files is simpler and sufficient for the stated requirement of minimizing changes.

How to eliminate wrong answers

Option B (Azure Disk Storage) is wrong because it provides block-level storage attached to a single VM as a virtual hard disk (VHD), not file-level network access; the application would need to be rewritten to use block I/O instead of file APIs. Option C (Azure Blob Storage) is wrong because it is an object storage solution accessed via REST APIs, not file-level protocols like SMB or NFS, requiring significant application changes. Option D (Azure NetApp Files) is wrong because while it does offer file-level access via NFS and SMB, it is an enterprise-grade, high-performance solution that is overkill for a simple migration requiring minimal changes and introduces unnecessary complexity and cost.

17
Multi-Selectmedium

You are designing a solution to monitor and analyze security events across your Azure environment. Which TWO Azure services should you include in your design to provide centralized logging and threat detection? (Choose two.)

Select 2 answers
A.Azure Firewall
B.Azure Log Analytics
C.Microsoft Sentinel
D.Azure Policy
E.Azure Network Watcher
AnswersB, C

Azure Log Analytics is the core data-collection and querying service within Azure Monitor, ingesting log data from virtually all Azure resources, virtual machines, and applications into a centralized workspace. It supports Kusto Query Language (KQL) queries that let you correlate security events, identify patterns, and troubleshoot incidents from a single pane of glass. This makes it the correct foundational service for monitoring and analyzing security-related logs, especially before layering on more advanced analytics like Sentinel.

Why this answer

B is correct because Azure Log Analytics is the central repository for log data in Azure Monitor, enabling you to collect, correlate, and query security events from multiple sources using Kusto Query Language (KQL). C is correct because Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests logs from Log Analytics and provides advanced threat detection, investigation, and automated response. Together, they form the foundation for centralized logging and threat detection in Azure.

Exam trap

The trap here is that candidates often confuse Azure Firewall (a network security appliance) or Azure Network Watcher (a diagnostic tool) with logging and threat detection services, when in fact they are not designed for centralized log analysis or SIEM functionality.

18
Multi-Selectmedium

Which TWO of the following are valid considerations when designing a SQL Server Always On availability group in Azure VMs? (Choose two.)

Select 2 answers
A.The availability group listener should use a static IP address in the same subnet as the primary replica.
B.The availability group listener can use DHCP to automatically assign an IP address.
C.The number of replicas should be an odd number to avoid split-brain scenarios.
D.A file share witness is required for the quorum configuration.
E.All replicas must be in the same subnet to use a single internal load balancer.
AnswersA, C

The availability group listener is created as a clustered resource in Windows Server Failover Clustering (WSFC) and must be assigned a static IP address because WSFC does not support dynamic IP assignment for network name resources. In an Azure IaaS deployment, that static IP must be a free address from the same subnet that hosts the primary replica, because the listener's IP is used as the frontend IP of the internal load balancer and must be directly routable to the replica nodes. This ensures that client connections are forwarded to the current primary replica when a failover occurs.

Why this answer

The availability group listener in Azure VMs requires a static IP address in the same subnet as the primary replica. This is necessary because the internal load balancer (ILB) used for the listener must have a static frontend IP that matches the listener's IP, and the IP must reside in the same subnet as the primary replica to ensure proper routing and failover behavior.

Exam trap

The trap here is that candidates often assume a file share witness is mandatory for quorum in Azure VMs, but Azure provides a cloud witness as a simpler alternative, and the requirement for an odd number of replicas is a general best practice to avoid split-brain, not an Azure-specific constraint.

19
MCQmedium

You are designing an authentication solution for a mobile application that uses Azure AD B2C (now Microsoft Entra External ID). The application needs to support social logins (Google, Facebook) and also allow users to sign in with their corporate Microsoft Entra ID accounts. Which of the following identity providers should you configure?

A.Use Microsoft Entra ID as the only identity provider and configure federation with Google and Facebook.
B.Use Microsoft Entra External ID with Google and Facebook only, and advise corporate users to create local accounts.
C.Configure Google and Facebook as social identity providers, and add Microsoft Entra ID as a custom identity provider.
D.Configure only Google and Facebook as identity providers, and use Microsoft account for corporate users.
AnswerC

Microsoft Entra External ID is specifically built for customer-facing apps and supports multiple identity providers within a single tenant. Google and Facebook can be configured as built-in social identity providers for consumer users, while Microsoft Entra ID can be added as a custom identity provider using OpenID Connect (OIDC) or SAML federation, enabling corporate users to sign in with their existing work accounts. This hybrid configuration cleanly handles both consumer social logins and enterprise corporate identities without requiring local account creation or separate authentication flows.

Why this answer

Microsoft Entra External ID (Azure AD B2C) supports social identity providers like Google and Facebook natively, and also allows you to add Microsoft Entra ID as a custom (OpenID Connect) identity provider. This enables corporate users to sign in with their existing Entra ID accounts while external users can use social logins, all within a single B2C tenant.

Exam trap

The trap here is that candidates often assume Microsoft Entra ID can directly federate with social identity providers, but in reality, social identity provider support requires Microsoft Entra External ID (Azure AD B2C) as the authentication platform.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID alone cannot directly federate with Google or Facebook as social identity providers; it requires Azure AD B2C (External ID) for social identity support. Option B is wrong because advising corporate users to create local accounts defeats the purpose of using their existing corporate identities and introduces unnecessary friction and security risks. Option D is wrong because using Microsoft account (personal) for corporate users does not support corporate Entra ID accounts, which require a dedicated identity provider configuration.

20
MCQhard

A multinational corporation is designing a disaster recovery strategy for a critical application running on Azure VMs. The application must have a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The primary region is East US, and the secondary region is West US. The solution must minimize costs while meeting the requirements. What should you recommend?

A.Deploy an active-passive configuration with Azure Front Door and Traffic Manager
B.Implement Azure Site Recovery for the VMs
C.Configure the VMs in an availability zone across East US and West US
D.Use Azure Backup with cross-region restore for the VMs
AnswerB

Azure Site Recovery is the native DR service for IaaS VMs, continuously replicating VM storage to a paired secondary region with an RPO as low as 15 seconds and RTO in minutes. It handles orchestrated failover, failback, and recovery drills, offering a cost-effective, fully managed solution that meets the stringent DR objectives without extra infrastructure. This directly satisfies the requirement for cross-region VM protection.

Why this answer

Azure Site Recovery (ASR) provides orchestrated replication of Azure VMs from a primary to a secondary region with an RPO as low as 15 minutes (Premium SSD) and RTOs that can be met within 1 hour through planned failover. It is the native Azure service designed for disaster recovery of IaaS workloads, offering cost-effective replication without requiring always-on secondary VMs, as it only incurs storage costs for replicated disks until failover.

Exam trap

The trap here is that candidates confuse high-availability solutions (availability zones, load balancers) with disaster recovery solutions, or assume Azure Backup's cross-region restore can meet low RPOs, when in fact only Azure Site Recovery provides the sub-hour replication frequency required for a 15-minute RPO.

How to eliminate wrong answers

Option A is wrong because Azure Front Door and Traffic Manager are global load-balancing and traffic-routing services; they do not provide VM replication or failover orchestration, and an active-passive configuration alone cannot meet the RPO/RTO without a replication mechanism. Option C is wrong because availability zones are within a single Azure region (e.g., East US) and cannot span across East US and West US; they protect against datacenter failures within a region, not regional disasters. Option D is wrong because Azure Backup with cross-region restore has a default RPO of 24 hours (for daily backups) and cannot achieve a 15-minute RPO; it is designed for backup and long-term retention, not low-latency disaster recovery.

21
MCQhard

You are a solutions architect for a financial services company. The company is deploying a new critical application on Azure that processes sensitive customer transactions. The application consists of an ASP.NET Core web app (Azure App Service), a REST API (Azure Kubernetes Service), and an Azure SQL Database. The requirements are: - All data at rest must be encrypted using customer-managed keys (CMK) stored in a managed HSM. - All network traffic between components must be encrypted and traverse the Microsoft backbone network. - The web app must be protected against common web attacks (SQL injection, XSS). - The solution must automatically scale the API based on CPU utilization. - All API calls must be authenticated using OAuth 2.0 with Microsoft Entra ID. - Logs from all components must be sent to a central Log Analytics workspace for analysis. - The solution must have a recovery time objective (RTO) of 1 hour and recovery point objective (RPO) of 5 minutes for the database. Which combination of Azure services should you recommend to meet ALL requirements?

A.Azure Front Door with WAF, Azure SQL Database point-in-time restore, Azure Key Vault Managed HSM, Azure App Service with private endpoint, AKS with HPA, Azure Log Analytics agent, Microsoft Entra ID
B.Azure Front Door with WAF, Azure SQL Database geo-replication, Azure Key Vault (Standard), Azure App Service with private endpoint, AKS with HPA, Azure Diagnostics extension, Microsoft Entra ID
C.Azure Application Gateway with WAF, Azure SQL Database active geo-replication, Azure Key Vault Managed HSM, Azure App Service with VNet integration, AKS with cluster autoscaler, Azure Monitor Agent, Microsoft Entra ID
D.Azure Application Gateway with WAF, Azure SQL Database failover groups, Azure Key Vault Managed HSM, Azure App Service with service endpoint, AKS with HPA, Azure Monitor Agent, Microsoft Entra ID
AnswerD

Correct. Failover groups meet RPO and RTO, Managed HSM meets key storage, service endpoint keeps traffic on Microsoft backbone, AKS with HPA scales based on CPU, Application Gateway WAF protects against attacks, Azure Monitor Agent collects logs, and Microsoft Entra ID authenticates API calls.

Why this answer

Meets all requirements: Azure Application Gateway with WAF protects against SQL injection and XSS; Azure SQL Database failover groups provide an RPO of 5 seconds and an RTO of 1 hour (auto-failover); Azure Key Vault Managed HSM stores customer-managed keys for encryption at rest; App Service with service endpoint ensures traffic to other Azure services stays on the Microsoft backbone network (combined with AKS in a VNet, internal traffic stays on backbone); AKS with Horizontal Pod Autoscaler (HPA) scales pods based on CPU utilization; Azure Monitor Agent sends logs to Log Analytics; Microsoft Entra ID authenticates API calls via OAuth 2.0. Option A uses point-in-time restore, which cannot guarantee RPO of 5 minutes and RTO of 1 hour. Option B uses Key Vault Standard instead of Managed HSM.

Option C uses cluster autoscaler, which scales nodes, not pods, failing the CPU-based scaling requirement.

Exam trap

The trap is confusing cluster autoscaler with Horizontal Pod Autoscaler (HPA). Cluster autoscaler scales the number of node VMs, not pod replicas, and does not respond to CPU utilization; it only responds to pending pods. HPA scales pod replicas based on CPU or memory metrics.

Also, service endpoints vs. private endpoints: both keep traffic on the Microsoft backbone, but private endpoints provide a private IP in the VNet for enhanced security.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database point-in-time restore has an RPO of up to 1 hour (not 5 minutes) and does not meet the RPO requirement; also, Azure Log Analytics agent is deprecated in favor of Azure Monitor Agent. Option B is wrong because Azure Key Vault (Standard) does not support customer-managed keys stored in a managed HSM (requires Premium tier or Managed HSM), and Azure Diagnostics extension is legacy and not the recommended agent for Log Analytics. Option D is wrong because Azure App Service with service endpoint does not ensure traffic traverses the Microsoft backbone network (it uses public IPs with ACLs, not private IPs); also, AKS with HPA (Horizontal Pod Autoscaler) scales pods, not nodes, and the requirement is to scale the API based on CPU utilization, which is better handled by cluster autoscaler for node-level scaling or HPA for pod-level scaling, but the key issue is service endpoint not meeting the private network requirement.

22
MCQhard

A company runs a high-performance computing (HPC) workload on Azure that requires extremely low latency (under 10 microseconds) between multiple VMs for MPI communication. The VMs are part of a single job and must be placed together to minimize network latency. Which VM deployment option should they use?

A.Azure Virtual Machine Scale Sets with a Proximity Placement Group
B.Azure Availability Sets
C.Azure Virtual Machine Scale Sets across Availability Zones
D.Azure Kubernetes Service (AKS)
AnswerA

Azure Virtual Machine Scale Sets with a Proximity Placement Group (PPG) is the correct choice for tightly coupled HPC workloads because a PPG co-locates all VM instances within the same Azure datacenter, minimizing network latency to the sub-10 microseconds required by MPI applications. VMSS integrates with PPG by allowing you to scale the compute cluster out while ensuring every new instance remains within the placement group, preserving low-latency inter-node communication. This combination also enables the use of high-throughput, low-latency networking such as InfiniBand on supported HPC VM SKUs, which is essential for parallel jobs that need frequent, low-latency message passing.

Why this answer

A Proximity Placement Group (PPG) within a Virtual Machine Scale Set ensures that all VMs are physically located as close as possible within an Azure datacenter, reducing network latency to under 10 microseconds for MPI communication. This is the only option that guarantees co-location of VMs for a single HPC job, as PPGs minimize inter-VM latency by placing VMs in the same rack or cluster.

Exam trap

The trap here is that candidates often confuse Availability Sets (which provide high availability) with Proximity Placement Groups (which provide low latency), or assume that Availability Zones offer sufficient performance for HPC, ignoring the significant latency penalty of inter-zone communication.

How to eliminate wrong answers

Option B is wrong because Availability Sets only protect against failures by distributing VMs across fault and update domains, but they do not guarantee low latency or co-location; in fact, they may spread VMs across different racks, increasing latency. Option C is wrong because Virtual Machine Scale Sets across Availability Zones place VMs in physically separate datacenters within a region, which introduces network latency far exceeding the 10-microsecond requirement due to inter-zone communication. Option D is wrong because Azure Kubernetes Service (AKS) abstracts VM placement and does not provide native mechanisms to enforce co-location of pods for low-latency MPI communication; it relies on underlying node placement, which is not guaranteed to be within a single rack.

23
MCQeasy

You are designing a disaster recovery strategy for an Azure virtual machine running a critical application. The VM is in the East US region. Your recovery point objective (RPO) is 15 minutes, and your recovery time objective (RTO) is 1 hour. Which Azure service should you use to replicate the VM to the West US region?

A.Azure Site Recovery
B.Azure Traffic Manager
C.Azure Backup
D.Azure Migrate
AnswerA

Azure Site Recovery orchestrates replication of Azure VMs to a paired secondary region by continuously copying disk writes to a Recovery Services vault, achieving RPOs as low as a few seconds and RTOs in minutes. It supports application-consistent snapshots and includes test failover, scheduled failover, and full orchestration with recovery plans. This continuous, coordinated replication is precisely what makes ASR the correct DR solution.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs between regions. It supports continuous replication with an RPO as low as 30 seconds and can meet your 15-minute RPO, while automated failover and recovery plans can achieve a 1-hour RTO by spinning up replicated VMs in the West US region.

Exam trap

The trap here is that candidates confuse Azure Backup (which provides point-in-time restores with longer RPO/RTO) with Azure Site Recovery (which provides continuous replication and rapid failover), overlooking the specific RPO and RTO requirements stated in the question.

How to eliminate wrong answers

Option B is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes incoming traffic based on routing methods (e.g., performance, priority), but it does not replicate VM data or provide disaster recovery failover capabilities. Option C is wrong because Azure Backup provides crash-consistent or application-consistent backups with a minimum RPO of 1 hour (for hourly backups) and a restore time that typically exceeds 1 hour, failing to meet the 15-minute RPO and 1-hour RTO. Option D is wrong because Azure Migrate is a tool for assessing and migrating on-premises workloads to Azure, not for ongoing replication or disaster recovery between Azure regions.

24
MCQeasy

You need to design a networking solution for a multi-tier application that includes a web front-end, an API layer, and a database. The web and API tiers must be accessible from the internet, while the database tier must be isolated. What is the most secure and efficient design?

A.Place all VMs in the same subnet and use a single Azure Load Balancer to distribute traffic.
B.Use separate VNets for each tier and connect them with VNet peering.
C.Deploy all VMs in a single subnet and use Azure Firewall to inspect all inbound and outbound traffic.
D.Deploy all tiers in the same VNet with separate subnets, and use NSGs to restrict traffic. Place an Azure Application Gateway with WAF in front of the web tier.
AnswerD

This architecture separates each application tier into its own subnet and applies per-subnet NSG rules to allow only required communication (e.g., web-to-app on port 443, app-to-data on port 3306), ensuring that a compromise in one tier does not implicitly expose another. An Azure Application Gateway with its WAF sits in a dedicated gateway subnet, providing the single internet-facing HTTPS endpoint, SSL offload, cookie-based session affinity, path-based routing, and OWASP Top-10 protection—all before traffic reaches the web tier. This is the recommended pattern because it balances security and operational simplicity.

Why this answer

It uses a single VNet with separate subnets for each tier, allowing Network Security Groups (NSGs) to enforce micro-segmentation and restrict traffic between tiers. The Azure Application Gateway with Web Application Firewall (WAF) provides Layer 7 protection and SSL termination for internet-facing web traffic, while the database tier remains isolated with no public endpoint. This design minimizes latency by keeping all tiers within the same VNet and avoids the complexity of VNet peering or unnecessary firewall inspection.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing separate VNets (Option B) thinking it provides better isolation, but they overlook that a single VNet with separate subnets and NSGs is simpler, lower latency, and equally secure for multi-tier applications within the same trust boundary.

How to eliminate wrong answers

Option A is wrong because placing all VMs in the same subnet with a single Azure Load Balancer provides no network isolation between tiers, exposing the database to direct access from the web and API tiers and violating the principle of least privilege. Option B is wrong because using separate VNets for each tier with VNet peering introduces unnecessary latency and administrative overhead, and peering does not inherently provide the granular traffic filtering needed between tiers; NSGs or firewalls would still be required. Option C is wrong because deploying all VMs in a single subnet with Azure Firewall to inspect all traffic creates a bottleneck and adds cost and complexity, while Azure Firewall operates at Layers 3-7 and is overkill for simple east-west traffic filtering that NSGs can handle more efficiently.

25
MCQeasy

You need to design a storage solution for unstructured data that requires low latency (single-digit milliseconds) for frequently accessed files and must support NFS and SMB protocols. Which Azure storage solution should you recommend?

A.Azure Files
B.Azure Blob Storage
C.Azure Disk Storage
D.Azure NetApp Files
AnswerD

Azure NetApp Files delivers single-digit-millisecond latency and natively supports both NFS and SMB, satisfying the performance and protocol constraints. Azure Files and Blob storage cannot meet the sub-millisecond-class latency requirement for frequently accessed unstructured data at this tier.

Why this answer

Azure NetApp Files is a fully managed, high-performance file share service that supports both NFS (v3/v4.1) and SMB protocols natively, and is designed for low-latency (single-digit milliseconds) access to unstructured data. It provides the required protocol flexibility and performance for frequently accessed files, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse Azure Files (which supports SMB and NFS) with Azure NetApp Files, overlooking the critical performance requirement for single-digit millisecond latency that only Azure NetApp Files can consistently deliver for high-frequency access patterns.

How to eliminate wrong answers

Option A is wrong because Azure Files supports SMB and NFS (preview) but is optimized for general-purpose file sharing, not for the ultra-low latency (single-digit milliseconds) required for frequently accessed high-performance workloads. Option B is wrong because Azure Blob Storage is an object storage solution that does not natively support NFS or SMB protocols (NFS 3.0 is available via Blob NFS but with higher latency and limited SMB support). Option C is wrong because Azure Disk Storage provides block-level storage for VMs and does not support NFS or SMB protocols directly; it requires a guest OS or clustering software to share files, adding complexity and latency.

26
MCQmedium

A company deploys a web application on multiple Azure VMs in a single region. They need to distribute incoming HTTP and HTTPS traffic across the VMs, offload SSL/TLS termination, and maintain session persistence (sticky sessions) so that all requests from a user session go to the same backend VM. Which Azure load balancing solution should they use?

A.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is the best fit here because it operates at Layer 7 (HTTP/S) and can route traffic based on URL paths or host headers. More importantly, it performs SSL termination and enforces cookie-based session affinity, ensuring that a client's subsequent requests are consistently directed to the same backend VM. It also offers a Web Application Firewall and integrates tightly with VM scale sets in a regional VNet, making it ideal for a multi-VM web application in a single region.

Why this answer

Azure Application Gateway is a Layer 7 load balancer that can distribute HTTP/HTTPS traffic, offload SSL/TLS termination, and support session persistence via cookie-based affinity (sticky sessions). These capabilities directly match the requirements, making it the correct choice.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming that any load balancer can handle SSL termination and sticky sessions, but only Layer 7 solutions like Application Gateway or Front Door provide these features.

How to eliminate wrong answers

Option B (Azure Load Balancer) is wrong because it operates at Layer 4 (TCP/UDP) and cannot perform SSL/TLS termination or inspect HTTP/HTTPS traffic for session persistence. Option C (Azure Traffic Manager) is wrong because it is a DNS-based traffic router that directs traffic across regions, not within a single region, and it does not handle SSL termination or sticky sessions. Option D (Azure Front Door) is wrong because it is a global Layer 7 load balancer and CDN designed for multi-region distribution, not for a single-region deployment, and its session affinity uses different mechanisms (e.g., ARR affinity) that are not optimized for intra-region VM load balancing.

27
Multi-Selecteasy

Which TWO of the following are valid data storage solutions for an Azure-based microservices architecture that requires high throughput and low latency? (Choose two.)

Select 2 answers
A.Azure Table Storage
B.Azure Cosmos DB
C.Azure Files
D.Azure Cache for Redis
E.Azure SQL Database
AnswersB, D

Azure Cosmos DB is a fully managed, globally distributed, multi-model database that exposes multiple APIs, including Core (SQL), MongoDB, Cassandra, Gremlin, and Table. It provides comprehensive SLAs for single-digit-millisecond read and write latency at the 99th percentile, supports multi-region writes and automatic horizontal partitioning, and scales throughput independently as request units, which makes it a proven valid data storage solution for demanding microservices.

Why this answer

Azure Cosmos DB is a fully managed NoSQL database that provides single-digit millisecond read and write latencies at the 99th percentile, guaranteed by SLAs. It supports multiple APIs (SQL, MongoDB, Cassandra, Gremlin, Table) and can be configured for high throughput with automatic indexing, making it ideal for microservices that require fast, scalable data access.

Exam trap

The trap here is that candidates often confuse Azure Table Storage (a basic key-value store) with Azure Cosmos DB's Table API (which offers much higher performance and SLAs), or they overlook that Azure Cache for Redis is a caching layer, not a primary data store, but it is a valid storage solution for high-throughput, low-latency access patterns in microservices.

28
MCQmedium

Your organization is building a serverless application that processes events from Azure Event Hubs and stores results in Azure Cosmos DB. The processing logic must be scalable and cost-effective, with no idle costs. Which compute service should you use?

A.Azure Functions
B.Azure Container Instances
C.Azure Logic Apps
D.Azure Kubernetes Service
AnswerA

Azure Functions is a true serverless compute service designed for event-driven architectures. It runs on the consumption plan where you pay only for execution time while the platform automatically scales out in response to incoming events and scales to zero when idle, eliminating idle cost. Tight integration with Azure triggers (e.g., HTTP, Event Grid, Service Bus, Blob) makes it the optimal choice for high-throughput, short-lived processing tasks where granular scaling and cost efficiency are required.

Why this answer

Azure Functions is the correct choice because it provides a serverless, event-driven compute service that can be triggered directly by Azure Event Hubs. It scales automatically based on the number of events, and you only pay for execution time, resulting in zero idle costs. This makes it ideal for processing streaming events in a cost-effective, scalable manner without managing infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Functions with Azure Logic Apps, assuming both are serverless, but Logic Apps is designed for workflow integration and not for high-throughput, event-stream processing, leading to incorrect cost and performance assumptions.

How to eliminate wrong answers

Option B (Azure Container Instances) is wrong because it is a container orchestration service that incurs costs for running containers even when idle, and it lacks native Event Hubs integration without additional code or a custom trigger. Option C (Azure Logic Apps) is wrong because it is a workflow orchestration service designed for integrating applications and services, not for high-throughput event processing; it would introduce latency and higher costs per execution compared to Functions. Option D (Azure Kubernetes Service) is wrong because it requires a managed Kubernetes cluster that incurs ongoing costs for nodes even when no events are being processed, and it adds unnecessary complexity for a simple event-processing workload.

29
MCQeasy

A company is planning to migrate its on-premises Active Directory to Microsoft Entra ID. They have a complex on-premises infrastructure with multiple forests and over 50,000 users. They need to synchronize identities and enable single sign-on (SSO) for Office 365. What should you recommend?

A.Microsoft Entra Connect Cloud Sync
B.Microsoft Entra Connect Health
C.Microsoft Entra ID synchronization
D.Microsoft Entra Connect Sync
AnswerD

Microsoft Entra Connect Sync supports multi-forest topologies and synchronises identities from multiple on-premises forests into Microsoft Entra ID, scaling beyond 50,000 users. It also enables SSO for Microsoft 365 through password hash synchronisation or pass-through authentication.

Why this answer

Microsoft Entra Connect Sync is the appropriate tool for synchronizing identities from a complex on-premises infrastructure with multiple forests and over 50,000 users to Microsoft Entra ID. It supports full identity synchronization, password hash synchronization, pass-through authentication, and federation for SSO to Office 365, and it can handle multi-forest environments with advanced configuration options. Microsoft Entra Connect Health only monitors the synchronization infrastructure and does not perform identity synchronization.

Exam trap

The trap is confusing Microsoft Entra Connect Cloud Sync with Microsoft Entra Connect Sync. Cloud Sync is a lightweight synchronization option suited to simple, small environments, while the full Sync version is required for complex, large environments such as multiple forests with 50,000+ users.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Connect Cloud Sync is designed for simpler, smaller environments (typically fewer than 50,000 users) and does not support multi-forest synchronization or advanced SSO configurations like federation. Option B is wrong because 'Microsoft Entra Connect' is a generic term that encompasses both Cloud Sync and Sync; the question requires the specific tool for complex multi-forest environments, which is Entra Connect Sync. Option C is wrong because 'Microsoft Entra ID synchronization' is not a specific product or tool; it is a general concept, and the question asks for a specific recommendation.

30
MCQmedium

Refer to the exhibit. You are analyzing Azure VM performance using Azure Monitor Logs. You run the KQL query shown. What is the purpose of the 'take 10' operator?

A.Limits the results to the first 10 rows after sorting by time.
B.Limits the time range to the last 10 hours.
C.Filters the results to only include the top 10 CPUs.
D.Samples the data to reduce query cost.
AnswerA

`take` in Kusto, also written as `limit`, returns exactly the first N rows from the result set that exists when the operator is evaluated. In this query, because `sort by time` (or `order by`) appears before `take`, the operator deterministically preserves the first 10 rows in chronological order, making it a row-count control rather than a time-window or aggregation operator. If there were no preceding sort, `take 10` could return arbitrary rows.

Why this answer

The 'take 10' operator in Kusto Query Language (KQL) returns a specified number of arbitrary rows from the query result set. When used after a sort operator (e.g., 'order by TimeGenerated desc'), it effectively limits the output to the first 10 rows of the sorted data, which in this context are the 10 most recent log entries. This is the standard behavior of 'take' in KQL, as it does not guarantee any specific order unless preceded by a sort.

Exam trap

The trap here is that candidates may confuse 'take' with time-based filtering (like 'where TimeGenerated > ago(10h)') or assume it samples data to reduce query costs, when in fact it simply limits the number of rows returned after the query has already processed the data.

How to eliminate wrong answers

Option B is wrong because 'take 10' does not filter by time range; it limits the number of rows returned, not the time span. Option C is wrong because 'take 10' does not filter by CPU count or any specific metric; it simply restricts the result set to 10 rows regardless of content. Option D is wrong because 'take 10' does not sample data to reduce cost; it retrieves actual rows from the result set, and cost is based on data scanned, not the number of rows returned after query execution.

31
MCQhard

Your organization is designing a secure microservices architecture using Azure Kubernetes Service (AKS). The application must be compliant with PCI DSS, which requires strict network segmentation and encryption of data at rest and in transit. You need to design a solution that meets these requirements while minimizing operational overhead. The AKS cluster will be deployed in a virtual network. The application consists of multiple microservices that need to communicate with each other and with an Azure SQL Database. Some microservices are public-facing. Which design should you recommend?

A.Deploy AKS with a private API server, enable network policies, and use a service endpoint or private endpoint for Azure SQL Database.
B.Deploy AKS with a public API server and use Network Security Groups (NSGs) to restrict access.
C.Deploy AKS with a private API server and use a jump box for administration.
D.Deploy AKS with a public API server and disable network policies to simplify management.
AnswerA

A private API server removes the Kubernetes control plane from the public internet, so only authorized virtual networks can reach it. Enabling Azure Network Policies provides pod-level microsegmentation, restricting east-west traffic between microservices. Using a private endpoint or service endpoint for Azure SQL Database keeps database traffic on the Microsoft backbone, satisfying PCI DSS requirements that mandate private connectivity and defense in depth.

Why this answer

A private API server ensures the AKS control plane is inaccessible from the public internet, satisfying PCI DSS network segmentation. Enabling network policies (e.g., Calico or Azure Network Policy) enforces micro-segmentation between pods, and using a private endpoint for Azure SQL Database encrypts data in transit over the Microsoft backbone and isolates the database to the virtual network, meeting encryption and segmentation requirements with minimal operational overhead.

Exam trap

The trap here is that candidates may think a private API server alone is sufficient for compliance, but they overlook the need for network policies to enforce micro-segmentation between pods and a private endpoint for Azure SQL Database to meet data-in-transit encryption and isolation requirements.

How to eliminate wrong answers

Option B is wrong because a public API server exposes the Kubernetes control plane to the internet, violating PCI DSS network segmentation requirements; NSGs alone cannot prevent all attack vectors against the API server. Option C is wrong because while a private API server is used, relying on a jump box for administration adds unnecessary operational overhead and does not address the need for network policies to secure inter-microservice traffic or private connectivity to Azure SQL Database. Option D is wrong because a public API server and disabling network policies completely bypass both network segmentation and encryption requirements, leaving the cluster vulnerable and non-compliant with PCI DSS.

32
MCQmedium

Refer to the exhibit. You have an Azure Storage account with the settings shown. A developer reports that they cannot access the storage account from their Azure VM that is connected to subnet-a. The VM's subnet ID matches the one in the rule. What is the most likely cause of the issue?

A.The storage account requires HTTPS and the VM is using HTTP
B.The storage account does not have a firewall rule for the VM's public IP
C.The subnet does not have a service endpoint for Microsoft.Storage enabled
D.The storage account uses GRS replication which is not supported with network rules
AnswerC

Azure Storage virtual network rules are only effective when the client subnet has a service endpoint for `Microsoft.Storage` enabled. Without that service endpoint, the VM's outbound traffic to the storage account is source-NATed to its public IP, so the storage account sees a public internet address and the configured virtual network rule does not match. Enabling the service endpoint on the subnet is required to route traffic over the Azure backbone and present the VM's private IP to the storage account. This missing configuration is the direct cause of the connectivity failure described.

Why this answer

The most likely cause is that the subnet does not have a service endpoint for Microsoft.Storage enabled. When a storage account firewall rule allows access from a specific subnet, that subnet must have a service endpoint configured for Microsoft.Storage; otherwise, traffic from the VM is treated as originating from the VM's public IP and is blocked by the firewall. The exhibit shows a firewall rule for the subnet, but without the service endpoint, the rule is ineffective.

Exam trap

The trap here is that candidates assume adding a subnet rule in the storage account firewall is sufficient, but they overlook the prerequisite of enabling the Microsoft.Storage service endpoint on the subnet, which is a critical step for the rule to take effect.

How to eliminate wrong answers

Option A is wrong because the storage account requires HTTPS (port 443) and the VM using HTTP (port 80) would cause a different error (e.g., 400 Bad Request or connection refused), not a firewall block; the question states the developer 'cannot access' the storage account, which aligns with a network rule denial. Option B is wrong because the storage account has a firewall rule for the subnet (not the VM's public IP), and if the VM is connected to that subnet with a service endpoint, the public IP is irrelevant; the issue is the missing service endpoint, not a missing public IP rule. Option D is wrong because GRS replication is fully supported with network rules; Azure Storage network rules apply to the storage account endpoint regardless of replication type, and there is no restriction preventing GRS from working with firewall or service endpoint configurations.

33
MCQmedium

A company is designing a hybrid identity solution that allows users to access both on-premises applications and Microsoft 365 using a single identity. The solution must support legacy authentication protocols for on-premises apps and modern authentication for cloud apps. Which Azure service should the company use?

A.Active Directory Federation Services (AD FS)
B.Microsoft Entra Application Proxy
C.Microsoft Entra ID
D.Microsoft Entra Connect
AnswerB

Microsoft Entra Application Proxy is a cloud-managed reverse proxy that publishes on-premises web applications through your Microsoft Entra tenant without requiring a VPN or inbound firewall rules. It pre-authenticates users with Entra ID, supports MFA and Conditional Access, and can work with legacy apps that use Integrated Windows Authentication via Kerberos constrained delegation or forms-based authentication. The service installs a connector on-premises, which makes an outbound connection to the cloud, keeping internal endpoints hidden while providing modern identity controls.

Why this answer

Microsoft Entra Application Proxy provides secure remote access to on-premises web applications by publishing them through the Microsoft Entra ID service. It supports legacy authentication protocols (such as Integrated Windows Authentication) for on-premises apps while enabling modern authentication (OAuth 2.0, OpenID Connect) for cloud apps like Microsoft 365, all using a single identity from Microsoft Entra ID. This makes it the correct choice for a hybrid identity solution that bridges on-premises and cloud authentication requirements.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect (a sync tool) with the application proxy capability, or assume AD FS is required for hybrid scenarios, but the question specifically requires support for legacy authentication protocols on on-premises apps, which Application Proxy handles through its connector and KCD integration.

How to eliminate wrong answers

Option A is wrong because Active Directory Federation Services (AD FS) is an on-premises federation service that provides single sign-on but requires additional infrastructure and does not natively support publishing on-premises apps with legacy authentication protocols through Microsoft Entra ID; it is more suited for federating identities rather than proxying legacy apps. Option C is wrong because Microsoft Entra ID alone is a cloud-based identity and access management service that does not include the reverse proxy functionality needed to expose on-premises applications with legacy authentication; it requires a separate service like Application Proxy for that purpose. Option D is wrong because Microsoft Entra Connect is a synchronization tool that syncs on-premises Active Directory objects to Microsoft Entra ID but does not provide application proxy capabilities or support legacy authentication protocols for on-premises apps.

34
MCQeasy

Your company plans to migrate an on-premises application to Azure. The application requires low-latency access to a shared file system that supports SMB protocol. Which Azure storage solution should you recommend?

A.Azure Blob Storage
B.Azure Disk Storage
C.Azure Files
D.Azure Queue Storage
AnswerC

Azure Files is the correct answer because it offers fully managed file shares in the cloud that natively support the SMB (and NFS) protocol, enabling Windows, Linux, or macOS clients to mount the share with a standard UNC path or drive letter. It is designed for lift-and-shift scenarios: on-premises applications that rely on file shares can be migrated without code changes, and Azure Files integrates with Azure Active Directory Domain Services for identity-based access. This directly matches the requirement for a shared file system accessible via SMB.

Why this answer

Azure Files provides fully managed file shares in the cloud that support the SMB protocol, making it the ideal solution for migrating on-premises applications that require low-latency access to a shared file system. It allows you to lift and shift applications that rely on SMB file shares without code changes, and it can be accessed from Azure VMs or on-premises via SMB 3.0.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with file shares because both can store files, but Blob Storage does not support SMB protocol, which is the key requirement for this scenario.

How to eliminate wrong answers

Option A is wrong because Azure Blob Storage is an object storage solution designed for unstructured data (e.g., images, videos, backups) and does not support the SMB protocol; it uses REST APIs or NFS (preview) but not SMB. Option B is wrong because Azure Disk Storage provides block-level storage volumes for Azure VMs, but it is not a shared file system—it is attached to a single VM (unless using shared disks, which still do not provide native SMB file sharing). Option D is wrong because Azure Queue Storage is a messaging service for decoupling application components and does not provide file storage or SMB protocol support.

35
MCQhard

You are designing a storage strategy for a data analytics solution that processes large volumes of streaming data. The data must be stored in a cost-effective manner with low latency for hot data and infrequent access for cold data after 30 days. The solution must support both batch and interactive queries. Which combination of Azure storage services should you recommend?

A.Azure Data Lake Storage Gen2 with lifecycle management
B.Azure SQL Database with geo-replication
C.Azure Blob Storage with hot and cool access tiers
D.Azure Cosmos DB with multiple consistency levels
AnswerA

Azure Data Lake Storage Gen2 combines a hierarchical namespace with Azure Blob Storage's durable, scalable storage, giving analytics engines like Synapse, Databricks, and HDInsight native directory structures and POSIX-style access control. Lifecycle management policies can automatically transition data from hot to cool to archive tiers based on age or usage, slashing storage costs while keeping the data queryable for batch and interactive analytics. This makes it purpose-built for high-volume analytics pipelines where both performance and cost governance matter.

Why this answer

Azure Data Lake Storage Gen2 (ADLS Gen2) combines the scalability and cost benefits of object storage with a hierarchical namespace, enabling both batch and interactive queries via services like Azure Synapse Analytics and Apache Spark. Lifecycle management policies can automatically transition hot data to cooler tiers (e.g., cool or archive) after 30 days, reducing costs for infrequently accessed cold data while maintaining low-latency access for hot data. This makes ADLS Gen2 the ideal choice for streaming data analytics that requires cost-effective tiered storage and supports diverse query patterns.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with ADLS Gen2, overlooking that the hierarchical namespace is essential for analytics workloads, and that lifecycle management alone on standard Blob Storage does not enable the same query performance or directory-level operations.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database is a relational database optimized for transactional workloads, not for storing large volumes of streaming data or supporting batch/interactive analytics at scale; it lacks native lifecycle management for tiered storage and incurs higher costs for massive datasets. Option C is wrong because Azure Blob Storage with hot and cool access tiers does not natively support a hierarchical namespace, which is required for efficient batch and interactive queries in analytics scenarios; ADLS Gen2 provides this capability on top of Blob Storage. Option D is wrong because Azure Cosmos DB is a NoSQL database designed for low-latency, globally distributed transactional workloads, not for cost-effective tiered storage of large-scale streaming data; it lacks lifecycle management for cold data and is not optimized for batch analytics queries.

36
Multi-Selectmedium

Your company is designing a hybrid network architecture to connect an on-premises data center to Azure. The requirements include: high availability, low latency, and cost optimization. Which TWO options should you recommend?

Select 2 answers
A.ExpressRoute Gateway
B.Single ExpressRoute circuit
C.Site-to-Site VPN
D.ExpressRoute Direct
E.Two ExpressRoute circuits from different providers
AnswersA, E

The ExpressRoute Gateway is the Azure-side virtual network gateway that terminates an ExpressRoute circuit and routes traffic between on-premises networks and Azure VNets. It provides low-latency, high-bandwidth connectivity by using a private, dedicated connection rather than the public internet, and it supports active-active mode to maintain availability even if one gateway instance fails. This is the essential component for hybrid connectivity, as it is the actual endpoint that enables traffic flow over ExpressRoute.

Why this answer

ExpressRoute Gateway is correct because it provides a dedicated, private connection from on-premises to Azure, bypassing the public internet for lower latency and more consistent performance. It supports high availability through active-active configurations and can be paired with multiple circuits for redundancy, meeting the hybrid network requirements.

Exam trap

The trap here is that candidates often assume a single ExpressRoute circuit is sufficient for high availability, but Azure requires at least two circuits from different providers to meet carrier-level redundancy, as a single circuit is a single point of failure.

37
MCQhard

A global logistics company is designing a solution that ingests telemetry data from thousands of IoT devices. The data must be processed in near real-time to detect anomalies and trigger alerts. The company wants to use a serverless, event-driven architecture that can scale automatically and minimize operational overhead. Which Azure service should the solutions architect use for the stream processing component?

A.Azure Event Hubs with Capture enabled
B.Azure Functions with an Event Hub trigger
C.Azure Stream Analytics
D.Azure Logic Apps with an IoT Hub connector
AnswerC

Azure Stream Analytics is a fully managed, serverless stream processing service that can analyze and process high volumes of streaming data from sources like IoT Hub or Event Hubs. It supports SQL-like queries for real-time analytics, anomaly detection, and can trigger alerts by outputting to services like Azure Functions or Logic Apps. It scales automatically and requires no infrastructure management.

Why this answer

Azure Stream Analytics is a serverless stream processing service that excels at real-time analytics on streaming data. It can ingest from IoT Hub or Event Hubs, apply SQL-like queries for anomaly detection, and output alerts to various destinations. It scales automatically and eliminates the need to manage infrastructure, aligning with the company's requirements for a serverless, event-driven architecture.

Exam trap

The trap here is assuming that Azure Functions is always the best serverless choice, but for complex stream processing with built-in operators, Stream Analytics is more appropriate.

38
Matchingmedium

Match each Azure identity service to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cloud-based identity and access management

Customer identity and access management for apps

Managed domain services like LDAP and Kerberos

Role-based access control for Azure resources

Policy-based evaluation to enforce access controls

Why these pairings

Azure AD is the core identity service for Microsoft cloud. Azure AD B2B enables external collaboration, Azure AD B2C serves customer-facing apps, and Azure AD DS provides domain services for VMs. Common confusions include swapping B2C with Azure AD or B2B with AD DS.

39
MCQhard

A company has multiple Azure virtual networks (VNets) in different regions and an on-premises data center connected via ExpressRoute. They need to implement a hub-and-spoke topology where a hub VNet hosts shared network virtual appliances (NVAs) for traffic inspection. All traffic between spokes and between spokes and on-premises must be routed through the hub. The company wants to minimize the administrative overhead of configuring and maintaining routing. Which Azure solution should they implement?

A.Use Azure Virtual WAN with a secured virtual hub.
B.Use VNet peering with user-defined routes (UDRs) in each spoke and Azure Route Server.
C.Create a single large VNet and use network security groups (NSGs) to isolate traffic.
D.Use Azure Firewall in the hub VNet and configure forced tunneling via custom routes.
AnswerA

Azure Virtual WAN provides a managed hub-and-spoke architecture with automatic routing. A secured virtual hub can integrate NVAs or Azure Firewall, and it handles transitive routing between spokes and on-premises without manual route tables or UDRs.

Why this answer

Azure Virtual WAN with a secured virtual hub is the correct choice because it provides a managed hub-and-spoke topology with built-in routing, eliminating the need for manual user-defined routes (UDRs) and route tables. The secured virtual hub includes Azure Firewall for traffic inspection, and all inter-spoke and on-premises traffic is automatically routed through the hub via the Virtual WAN routing engine, which uses the Border Gateway Protocol (BGP) to propagate routes dynamically. This minimizes administrative overhead by centralizing routing and security management.

Exam trap

The trap here is that candidates often choose VNet peering with UDRs (Option B) because it is a familiar pattern for hub-and-spoke, but they overlook that Azure Virtual WAN is the managed service designed to eliminate the administrative overhead of manual routing, especially when multiple regions and on-premises connectivity are involved.

How to eliminate wrong answers

Option B is wrong because using VNet peering with UDRs in each spoke and Azure Route Server still requires manual configuration and maintenance of UDRs for each spoke to force traffic through the hub NVAs, which increases administrative overhead and does not provide a fully managed routing solution. Option C is wrong because creating a single large VNet and using NSGs to isolate traffic violates the hub-and-spoke requirement for traffic inspection through NVAs; NSGs are stateless or stateful filters that do not route traffic through a central inspection point, and a single VNet cannot span multiple regions natively without additional complexity. Option D is wrong because using Azure Firewall in the hub VNet with forced tunneling via custom routes still requires manual UDR configuration on each spoke subnet to direct traffic to the firewall, and it does not provide the automated, scalable routing that Azure Virtual WAN offers for multi-region and on-premises connectivity.

40
MCQhard

Your company has a large number of IoT devices sending telemetry to Azure IoT Hub. The data must be processed in near real-time to detect anomalies and trigger alerts. Additionally, the processed data must be stored in a time-series database for historical analysis. Which combination of Azure services should you recommend?

A.Azure Functions and Azure SQL Database
B.Azure HDInsight and Azure Cosmos DB
C.Azure Data Factory and Azure Blob Storage
D.Azure Stream Analytics and Azure Data Explorer
AnswerD

Azure Stream Analytics is a fully managed, serverless stream-processing engine that uses SQL-like syntax to run continuous queries over IoT Hub or Event Hubs data, enabling real-time filtering, windowed aggregations, and pattern detection. Azure Data Explorer (ADX) is a fast, fully managed analytics database specifically optimized for time-series and telemetry data, with native time-based partitioning, high-cardinality grouping, and built-in time-series functions (e.g., series_decompose) for trend and anomaly analysis. This combination is ideal for IoT telemetry: Stream Analytics handles the real-time processing and ingestion while ADX provides low-latency, interactive storage and exploration, making it the correct answer.

Why this answer

Azure Stream Analytics provides real-time stream processing to detect anomalies and trigger alerts from IoT Hub telemetry. Azure Data Explorer (ADX) is a fully managed, high-performance time-series database optimized for storing and analyzing large volumes of time-stamped data, making it the ideal choice for historical analysis. Together, they meet both the near real-time processing and time-series storage requirements.

Exam trap

The trap here is that candidates often confuse Azure Stream Analytics with Azure Data Factory or Azure Functions, mistakenly thinking batch or serverless compute can handle near real-time stream processing, while overlooking that Azure Data Explorer is the only Azure service purpose-built for time-series storage and analytics at scale.

How to eliminate wrong answers

Option A is wrong because Azure Functions is a serverless compute service for event-driven code, not a stream processing engine, and Azure SQL Database is a relational database not optimized for time-series data ingestion or query performance at IoT scale. Option B is wrong because Azure HDInsight is a big data analytics platform (e.g., Spark, Hadoop) that introduces significant latency and operational overhead for near real-time processing, and Azure Cosmos DB is a multi-model NoSQL database that lacks native time-series optimizations like automatic retention policies and time-based partitioning. Option C is wrong because Azure Data Factory is an orchestration and ETL service for batch data movement, not real-time stream processing, and Azure Blob Storage is an object store with no time-series indexing or query capabilities.

41
MCQhard

A company is designing a solution for a global e-commerce platform that requires low-latency access to product catalog data from multiple regions. The data is read-heavy with occasional updates. The solution must support automatic scaling and provide high availability. Which Azure service should you recommend?

A.Azure SQL Database with active geo-replication
B.Azure Cosmos DB with multi-region writes
C.Azure Table Storage
D.Azure Cache for Redis
AnswerB

Azure Cosmos DB with multi-region writes is purpose-built for global distribution, offering turnkey active-active replication across any number of Azure regions. It provides single-digit-millisecond read and write latencies at the 99th percentile, automatic and elastic scaling of throughput and storage, and multiple well-defined consistency models, so a global e-commerce platform can serve users from their nearest region with low latency and high availability, while also supporting multi-region write concurrency for true active-active operation.

Why this answer

Azure Cosmos DB with multi-region writes is the correct choice because it provides global distribution with turnkey multi-master replication, enabling low-latency reads and writes from any Azure region. It supports automatic scaling through request units (RU/s) and offers 99.999% high availability with multiple well-defined consistency levels, making it ideal for a read-heavy, globally distributed e-commerce catalog with occasional updates.

Exam trap

The trap here is that candidates often confuse Azure SQL Database's active geo-replication (which supports only a single write region) with true multi-region writes, or they assume a cache like Redis can serve as the primary data store for a globally distributed, read-heavy workload with occasional updates.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database with active geo-region replication supports only a single writable primary replica; all other regions are read-only secondaries, which cannot handle occasional writes from multiple regions with low latency. Option C is wrong because Azure Table Storage is a NoSQL key-value store that lacks native multi-region write support, automatic scaling is limited to partition-level throughput, and it does not provide the sub-10-millisecond latency guarantees required for a global e-commerce platform. Option D is wrong because Azure Cache for Redis is an in-memory cache, not a primary data store; it does not persist data by default, cannot serve as the authoritative source for product catalog updates, and lacks built-in multi-region write capabilities.

42
MCQmedium

A global e-commerce company runs a web application in multiple Azure regions. They need to distribute incoming HTTPS traffic across regional deployments to provide low latency and high availability. The solution must support SSL offloading, Web Application Firewall (WAF) policies, and content caching to reduce backend load. They also need to route users to the nearest healthy backend region. Which Azure service should they use?

A.Azure Traffic Manager
B.Azure Front Door
C.Azure Application Gateway
D.Azure Content Delivery Network (CDN)
AnswerB

Azure Front Door is the correct choice because it is a true global layer 7 load balancer that terminates TLS at its edge points of presence, offloading encryption processing from the origin web servers. It includes an integrated web application firewall (WAF) capable of inspecting requests before they reach backend applications, and it offers edge caching for static and dynamic content. Additionally, Front Door uses Anycast and intelligent routing to direct each user's request to the nearest available and healthy regional backend, providing automatic global failover and path-based routing that satisfy all requirements of a multi-region e-commerce deployment.

Why this answer

Azure Front Door is the correct choice because it is a global, scalable entry point that provides HTTPS traffic distribution across multiple Azure regions with low latency, SSL offloading, WAF policies, and content caching. It uses Anycast-based routing to direct users to the nearest healthy backend region, meeting all the requirements for high availability and performance.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager (DNS-level routing) with Azure Front Door (HTTP/HTTPS-level routing), overlooking the need for SSL offloading, WAF, and content caching, which Traffic Manager cannot provide.

How to eliminate wrong answers

Option A (Azure Traffic Manager) is wrong because it operates at the DNS level and does not support SSL offloading, WAF policies, or content caching; it only routes traffic based on DNS responses without inspecting the HTTP/HTTPS payload. Option C (Azure Application Gateway) is wrong because it is a regional load balancer that provides SSL offloading and WAF, but it cannot distribute traffic across multiple regions or route users to the nearest healthy backend region globally. Option D (Azure Content Delivery Network (CDN)) is wrong because it focuses on caching static content at edge locations and does not provide SSL offloading, WAF, or intelligent routing to the nearest healthy backend region for dynamic traffic.

43
MCQmedium

A company is deploying an internal web application on Azure VMs. The application requires SSL offloading, session stickiness, and URL-based routing (e.g., /api/* to one backend, /app/* to another). The solution must operate within a single Azure region and must not be exposed to the public internet. Which Azure load balancing solution should they use?

A.A
B.B
C.C
D.D
AnswerC

Azure Application Gateway can be deployed as an internal (private) application gateway with a private frontend IP address inside the VNet, keeping the application fully internal. It offers native Layer 7 features including SSL termination (offloading), cookie-based session affinity, and URL path-based routing through listener and rule configurations. This makes it the only option that satisfies all three requirements—SSL offloading, session stickiness, and URL-based routing—within an internal network boundary.

Why this answer

Azure Application Gateway v2 is the correct choice because it provides SSL offloading (SSL termination at the gateway), session stickiness (cookie-based affinity), and URL-based routing (path-based routing rules) within a single Azure region. It can be deployed with a private IP address only, ensuring it is not exposed to the public internet, meeting all requirements.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway, but Front Door is a global service requiring public endpoints and multi-region support, whereas Application Gateway can be deployed privately within a single region.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL offloading or URL-based routing; it only distributes traffic based on IP and port. Option B is wrong because Azure Traffic Manager is a DNS-based global load balancer that operates across regions and requires public endpoints; it cannot provide SSL offloading or URL-based routing within a single region. Option D is wrong because Azure Front Door is a global Layer 7 load balancer with SSL offloading and URL routing, but it is designed for multi-region deployments and requires public internet exposure; it cannot be restricted to a single region with private-only access.

44
Multi-Selecteasy

You are designing a highly available architecture for a web application that runs on Azure VMs. The solution must distribute incoming traffic across multiple VMs in an availability set. Which TWO Azure components should you include? (Choose two.)

Select 2 answers
B.Azure Traffic Manager
C.Azure Front Door
D.Availability Set
E.Azure Application Gateway
AnswersA, D

Azure Load Balancer is a layer 4 (TCP/UDP) load balancer that distributes traffic to virtual machines in a backend pool within the same Azure region. It uses health probes to detect VM availability and automatically routes traffic only to healthy instances, providing regional high availability. Because the scenario only requires distributing web traffic across VMs in one region, Load Balancer meets the requirement without introducing unnecessary global or application-layer complexity.

Why this answer

Azure Load Balancer (A) is correct because it distributes incoming traffic across multiple VMs in an availability set at the transport layer (TCP/UDP), providing high availability by rerouting traffic away from failed instances. An availability set (D) is required to ensure VMs are placed in different fault domains and update domains, protecting against hardware failures and planned maintenance. Together, they form the core of a highly available architecture for VMs within a single Azure region.

Exam trap

The trap here is that candidates often confuse the regional, layer-4 Azure Load Balancer with the global, layer-7 Azure Front Door or Application Gateway, or mistakenly think Traffic Manager can distribute traffic within a single region, when it is designed for cross-region DNS-based routing.

45
Multi-Selecthard

A company is designing a backup strategy for Azure resources. They have the following resources: Azure VMs, Azure SQL Database, and Azure Files shares. They need to meet the following requirements: 1) Backup of VMs must be application-consistent. 2) SQL Database backups must be retained for 10 years. 3) Azure Files backups must support soft delete. Which THREE services or features should they use?

Select 3 answers
A.Azure Backup
B.Soft delete for Azure Files
C.Long-term retention (LTR) for Azure SQL Database
D.Azure Site Recovery
E.Azure Policy
AnswersA, B, C

Azure Backup is the native backup service that creates application-consistent recovery points for Azure VMs using VSS for Windows and file-system-consistent snapshots for Linux. Recovery points are stored in a Recovery Services vault or Backup vault, and you can define backup policies for schedule and retention, enabling point-in-time restores across disks or the entire VM. This is a true backup solution because it preserves historical versions of data independent of live replication.

Why this answer

Azure Backup is the correct service for VM backups because it supports application-consistent backups for Windows VMs via Volume Shadow Copy Service (VSS) and for Linux VMs via file-system-consistent snapshots with pre/post-scripts, ensuring that applications are in a consistent state at the time of backup. This directly meets requirement 1.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with Azure Backup (backup), or assume Azure Policy can enforce backup configurations, but only the specific services listed (Azure Backup, soft delete for Azure Files, and LTR for SQL Database) directly address the stated requirements.

46
MCQmedium

A company deploys a web application on Azure VMs across multiple availability zones in a region. They need to distribute incoming traffic across VMs in all zones, maintain session persistence, and support SSL offloading and URL-based routing (e.g., /api/* to one pool, /app/* to another). Which Azure load balancing solution should they use?

B.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerB

Azure Application Gateway is a regional, layer-7 web traffic load balancer that understands HTTP(S) and offers native SSL termination (offloading), URL/path-based routing, multi-site hosting, cookie-based session affinity, and a built-in Web Application Firewall (WAF). This makes it the appropriate choice for a web application spread across multiple Azure VMs within the same region, because it can inspect each request's URL and steer it to the right backend pool. Its ability to offload encryption, rewrite HTTP headers, and perform health checks at the application layer matches the stated requirements precisely, and it is commonly deployed in front of VM scale sets for web workloads.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 (HTTP/HTTPS) load balancer that supports SSL offloading, URL-based routing (e.g., /api/* and /app/* to different backend pools), and session persistence (cookie-based affinity). It can distribute traffic across VMs in multiple availability zones within a region, meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support HTTP-level features like URL routing and SSL offloading, but only Layer 7 solutions do.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and does not support SSL offloading or URL-based routing; it cannot inspect HTTP paths. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that distributes traffic across regions, not within a single region, and it does not support SSL offloading or URL-based routing. Option D is wrong because Azure Front Door is a global Layer 7 service that supports SSL offloading and URL-based routing but is designed for multi-region distribution, not for distributing traffic across VMs within a single region's availability zones.

47
MCQmedium

A company is designing a backup strategy for a critical Azure SQL Database. The database is used in a production environment and the company requires the ability to restore to any point within the last 35 days with a maximum granularity of 5 minutes. Which backup configuration should the company choose?

A.Use Azure Backup for SQL Server in Azure VM
B.Configure point-in-time restore with a retention period of 35 days and a backup frequency of 5 minutes
C.Use Azure SQL Database automatic backups with a retention period of 35 days
D.Configure geo-redundant backup with long-term retention
AnswerC

Azure SQL Database automatic backups provide the exact capabilities required: full, differential, and transaction log backups are taken automatically, and you can configure the retention period for point-in-time restore (PITR) up to 35 days. With automatic backups, you can restore to any point in time within the retention period at 5-minute granularity, which satisfies the requirement of a 5-minute recovery point objective (RPO). This is the correct and simplest approach because no external backup solution is needed.

Why this answer

Azure SQL Database's built-in automatic backups provide point-in-time restore (PITR) with a configurable retention period of up to 35 days and a default backup frequency that enables restore granularity of 5 minutes. This meets the requirement without additional configuration or cost, as automatic backups are enabled by default and include differential and transaction log backups every 5-10 minutes.

Exam trap

The trap here is that candidates confuse the configurable backup frequency of Azure Backup for VMs with the automatic, service-managed backup schedule of Azure SQL Database, leading them to select Option B or A when the native PITR feature already meets the requirement.

How to eliminate wrong answers

Option A is wrong because Azure Backup for SQL Server in Azure VM is designed for SQL Server running on virtual machines, not for Azure SQL Database (a PaaS service), and it does not offer the native 5-minute granularity or 35-day retention without custom policy configuration. Option B is wrong because point-in-time restore is a feature of Azure SQL Database automatic backups, not a separate configuration; you cannot set a backup frequency of 5 minutes manually—the frequency is determined by the service's transaction log backup schedule. Option D is wrong because geo-redundant backup with long-term retention addresses disaster recovery and archival retention beyond 35 days, not the granular point-in-time restore requirement within 35 days.

48
MCQmedium

A company has multiple on-premises sites and Azure VNets in different regions. They need to connect all networks with a single mesh topology, ensuring that any network can communicate with any other network directly. They also want to minimize administrative overhead. Which Azure service should they use?

A.Azure Virtual WAN
B.Azure VPN Gateway
C.Azure ExpressRoute
D.Azure Peering Service
AnswerA

Azure Virtual WAN is the correct choice because it provides a cloud-native mesh connectivity solution built on a hub-and-spoke architecture with regional hubs. It automates the creation of any-to-any connections between branch offices, remote users, and VNets, with integrated routing that eliminates the need to manually configure individual VPN tunnels or peer each VNet. Virtual WAN uses the Microsoft backbone for transit, ensuring consistent low-latency routing across regions and on-premises sites, and supports both Site-to-Site VPN and ExpressRoute in a single managed topology.

Why this answer

Azure Virtual WAN is the correct choice because it provides a managed, global mesh network that automatically connects on-premises sites and Azure VNets across regions using a hub-and-spoke architecture with built-in transitive routing. This eliminates the need to manually configure individual VPN gateways or ExpressRoute circuits for each pair of networks, directly supporting the requirement for any-to-any direct communication with minimal administrative overhead.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway's ability to create multiple site-to-site connections with a true mesh topology, overlooking that VPN Gateway lacks automatic transitive routing and requires manual configuration for any-to-any connectivity, whereas Virtual WAN provides this natively.

How to eliminate wrong answers

Option B (Azure VPN Gateway) is wrong because it only creates point-to-site or site-to-site connections between individual networks; it does not natively support a full mesh topology without complex, manual configuration of multiple VPN tunnels and route tables, which increases administrative overhead. Option C (Azure ExpressRoute) is wrong because it provides private, dedicated connectivity between on-premises sites and Azure, but it does not inherently create a mesh between multiple on-premises sites or VNets; additional routing and gateway configurations are required to achieve transitive connectivity. Option D (Azure Peering Service) is wrong because it is designed to optimize connectivity to Microsoft cloud services over the internet, not to create a mesh network between customer-owned on-premises sites and Azure VNets.

49
MCQmedium

Your company is deploying a web application that experiences unpredictable traffic spikes. You need to ensure the application can handle sudden increases in load automatically without manual intervention and minimize costs during low traffic periods. Which Azure service should you use?

A.Azure App Service with manual scale-out
B.Azure Functions with consumption plan
C.Virtual Machine Scale Set with autoscale
D.Azure Container Instances
AnswerC

Virtual Machine Scale Sets with autoscale rules are the correct choice because they automatically adjust the number of VM instances based on metrics like CPU percentage, memory, or custom thresholds. This enables horizontal scaling to handle traffic spikes by adding instances and also scaling in during low demand to reduce costs. The approach is ideal for hosting web applications that require full control over the VM image, dependencies, or infrastructure-level configuration.

Why this answer

Virtual Machine Scale Sets with autoscale rules can automatically adjust the number of VM instances based on demand. Option A (Azure App Service with manual scaling) does not autoscale automatically. Option B (Azure Functions) is for event-driven workloads, not web apps.

Option D (Azure Container Instances) does not autoscale natively.

50
MCQeasy

A company has multiple Azure virtual networks (VNets) in different Azure regions and an on-premises data center connected via ExpressRoute. They want to connect all VNets to each other and to the on-premises network securely over the Microsoft global backbone. They also want to simplify management by using a single orchestration interface. Which Azure service should they use?

A.Azure Virtual WAN
B.VNet peering
C.Azure VPN Gateway
D.Azure ExpressRoute
AnswerA

Azure Virtual WAN deploys regional hubs that are connected by a Microsoft-backbone mesh, enabling any-to-any transit between spokes, branches, and on-premises sites without manually defining each pairing. Each hub aggregates VPN, ExpressRoute, and point-to-site gateways, and route propagation is automatically managed with virtual hub routing tables, so organizations can scale to multiple VNets and regions with a single orchestration plane. This is exactly the centralized multi-region interconnection and branch integration the scenario requires.

Why this answer

Azure Virtual WAN is correct because it provides a hub-and-spoke architecture that connects branch offices, VNets, and on-premises networks over the Microsoft global backbone. It offers a single orchestration interface for managing connectivity, routing, and security policies across multiple regions and ExpressRoute circuits, meeting the requirement for secure, global connectivity with simplified management.

Exam trap

The trap here is that candidates often confuse VNet peering (which is point-to-point) with the hub-and-spoke model of Virtual WAN, or assume ExpressRoute alone can connect multiple VNets, missing the requirement for a single orchestration interface and transitive routing across regions.

How to eliminate wrong answers

Option B (VNet peering) is wrong because it only connects two VNets directly and does not provide a single orchestration interface for multiple VNets across regions; it also requires manual transitive routing configuration and does not natively integrate with ExpressRoute for on-premises connectivity. Option C (Azure VPN Gateway) is wrong because it creates site-to-site VPN tunnels over the public internet, not over the Microsoft global backbone, and does not offer a unified management interface for multiple VNets and ExpressRoute connections. Option D (Azure ExpressRoute) is wrong because it only provides a dedicated private connection from on-premises to Azure, but does not connect multiple VNets to each other or offer a single orchestration interface for managing inter-VNet and hybrid connectivity.

51
MCQmedium

You are designing a disaster recovery solution for a critical application hosted in Azure VMs. The primary region is East US. The application requires a recovery time objective (RTO) of 30 minutes and a recovery point objective (RPO) of 15 minutes. Which Azure service should you use to replicate the VMs?

A.Azure Front Door
B.Azure Backup
C.Azure Traffic Manager
D.Azure Site Recovery
AnswerD

Azure Site Recovery orchestrates continuous, block-level replication of Azure VMs to a secondary region by using a mobility service extension that copies every write to a cache storage account and then to replicated managed disks. In Azure-to-Azure scenarios, this provides an RPO of 15–30 seconds, while crash-consistent and app-consistent snapshots are taken to balance performance and data loss. Recovery plans enable you to define failover sequences, execute runbooks or scripts, and update DNS or load balancer settings, which can compress RTO to minutes with predictable, testable outcomes. That coordination of replication state and application failover is exactly what makes Site Recovery the appropriate choice for a critical workload's DR solution.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs between regions, meeting the RTO of 30 minutes and RPO of 15 minutes by using continuous replication with crash-consistent or app-consistent snapshots. It is the native Azure service designed specifically for disaster recovery of IaaS workloads with granular recovery objectives.

Exam trap

The trap here is that candidates often confuse Azure Backup (which is for long-term retention and archival) with Azure Site Recovery (which is for replication and rapid failover), failing to recognize that Backup's default RPO of 24 hours cannot satisfy sub-hour recovery objectives.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global load balancer and application delivery service that routes HTTP/HTTPS traffic, not a VM replication or disaster recovery service; it cannot replicate VM state or meet RPO/RPO requirements. Option B is wrong because Azure Backup provides backup and restore of VMs with a typical RPO of 1 day (daily snapshots) and RTO measured in hours, far exceeding the required 15-minute RPO and 30-minute RTO. Option C is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that directs user traffic to endpoints based on routing methods, but it does not replicate VM data or provide failover of compute and storage; it only controls traffic routing.

52
MCQeasy

A company needs to provide secure access to Azure resources for remote employees. They want to enforce multi-factor authentication and conditional access policies. The solution should not require a VPN connection. Which Azure service should they implement?

A.Microsoft Intune
B.Azure VPN Gateway
C.Azure Bastion
D.Microsoft Entra ID
AnswerD

Microsoft Entra ID is the foundational identity and access management (IAM) service for Azure and acts as the central authentication and authorization control plane. It authenticates users, issues access tokens via OAuth 2.0 and OpenID Connect, and enforces Conditional Access policies, including MFA, device compliance, and risk detection. All Azure Resource Manager and data-plane access ultimately depends on Entra ID tokens, making it the correct identity-based solution for secure access to Azure resources.

Why this answer

Microsoft Entra ID (formerly Azure Active Directory) provides identity and access management services that include multi-factor authentication (MFA) and conditional access policies. These capabilities allow you to enforce security requirements like MFA and device compliance before granting access to Azure resources, all without requiring a VPN connection. Entra ID acts as the identity provider and policy engine, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse network-level security services (like VPN Gateway or Bastion) with identity-level security services (like Entra ID), mistakenly thinking a VPN is required to enforce MFA or conditional access, when in fact Entra ID handles these controls at the authentication layer without any network tunnel.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service; it does not natively enforce MFA or conditional access policies on its own—it relies on Entra ID for those controls. Option B is wrong because Azure VPN Gateway creates an encrypted tunnel between on-premises networks and Azure, but the requirement explicitly states no VPN is needed, and VPN Gateway does not enforce MFA or conditional access policies at the identity level. Option C is wrong because Azure Bastion provides secure RDP/SSH access to Azure VMs without exposing public IPs, but it does not enforce MFA or conditional access policies—it is a jump server service, not an identity and access management solution.

53
MCQeasy

A company wants to implement a backup strategy for their Azure virtual machines. They need to retain backups for 7 years for compliance and ensure backups are encrypted at rest. Which solution should you recommend?

A.Azure Disk Snapshot with a lifecycle management policy.
B.Azure Backup with a vault configured for 7-year retention and encryption at rest.
C.Azure Files Backup to a Recovery Services vault.
D.Azure Site Recovery with custom retention policies.
AnswerB

Azure Backup with a Recovery Services vault is the correct service for long-term VM backup, supporting retention up to 10 years (or 7 years easily) with flexible weekly/monthly/yearly retention policies. Backups are application-consistent using VSS on Windows and file-system-consistent on Linux, with encryption at rest using platform-managed keys and secure network access via private endpoints. The vault stores recovery points across regions if you enable cross-region restore, providing the durability and compliance needed for keeping backups for 7 years.

Why this answer

Azure Backup is the correct solution because it provides long-term retention (up to 99 years) and supports encryption at rest using platform-managed keys (PMK) or customer-managed keys (CMK). It meets the 7-year compliance requirement and ensures backups are encrypted by default using Azure Storage Service Encryption (SSE).

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with Azure Backup (long-term backup), or assume that disk snapshots with lifecycle management can achieve 7-year retention, but snapshots have a maximum retention of 5 years and lack the integrated encryption and compliance features of Azure Backup.

How to eliminate wrong answers

Option A is wrong because Azure Disk Snapshots do not support retention policies beyond the snapshot lifecycle management (max 5 years) and are not inherently encrypted at rest with a managed backup service; they rely on the underlying disk encryption. Option C is wrong because Azure Files Backup is designed for file shares, not Azure virtual machines, and does not provide VM-consistent backup or 7-year retention for VMs. Option D is wrong because Azure Site Recovery is a disaster recovery solution focused on replication and failover, not long-term backup retention; its custom retention policies are limited to crash-consistent recovery points and do not support 7-year archival.

54
MCQeasy

A company wants to run a containerized application on Azure without managing virtual machines. They need automatic scaling, load balancing, and rolling updates. Which Azure compute service should they choose?

A.Azure Virtual Machine Scale Sets
B.Azure Kubernetes Service (AKS)
C.Azure App Service
D.Azure Container Instances
AnswerB

Azure Kubernetes Service (AKS) is a fully managed container orchestration platform that abstracts the Kubernetes control plane—including etcd and the API server—so you never have to manage those components. It provides managed node pools, cluster autoscaler, seamless integration with Azure Load Balancer and Application Gateway, and declarative rolling updates through Kubernetes Deployments and ReplicaSets. AKS handles scheduling, self-healing, service discovery, and secret management natively, making it the appropriate choice when you need robust, production-grade orchestration for containerized applications without managing the underlying orchestration infrastructure.

Why this answer

Azure Kubernetes Service (AKS) is the correct choice because it provides a fully managed Kubernetes orchestration platform that handles containerized applications with automatic scaling (via Horizontal Pod Autoscaler), built-in load balancing (via Azure Load Balancer integration), and rolling updates (via Kubernetes deployment strategies). This meets the requirement of running containers without managing VMs, as AKS abstracts the underlying node management.

Exam trap

The trap here is that candidates often confuse Azure Container Instances (ACI) as a full orchestration solution, but ACI lacks the automatic scaling, load balancing, and rolling update capabilities that AKS provides for multi-container applications.

How to eliminate wrong answers

Option A is wrong because Azure Virtual Machine Scale Sets require you to manage VMs and the container runtime, and they do not natively support container orchestration features like rolling updates or service discovery. Option C is wrong because Azure App Service is a Platform-as-a-Service (PaaS) for web apps and APIs, not designed for containerized applications with full orchestration; it lacks native Kubernetes features like pod-level scaling and rolling update strategies. Option D is wrong because Azure Container Instances (ACI) is a serverless container service that does not provide built-in orchestration for automatic scaling, load balancing across multiple containers, or rolling updates; it is intended for simple, single-container scenarios.

55
MCQmedium

A company is designing private access to a PaaS database from workloads in a VNet. The database should not be reachable over its public endpoint. What should be recommended?

A.A public IP address with NSG rules
B.A route table to the internet gateway
C.Private Endpoint with public network access disabled
D.Azure CDN endpoint
AnswerC

Create a private endpoint in the workloads' VNet, which provisions a private IP address from the chosen subnet and maps it to the PaaS database via Azure Private Link, allowing connections over the Microsoft backbone. Then disable public network access on the PaaS resource so the only valid path is through the private endpoint, eliminating internet exposure entirely. This is the intended architecture when workloads must reach a PaaS database without traversing the public internet.

Why this answer

Private Endpoint with public network access disabled is the correct recommendation because it assigns a private IP address from the VNet to the PaaS database, making it accessible only over the private network. This eliminates exposure to the public internet by disabling the public endpoint, aligning with the requirement that the database should not be reachable over its public endpoint.

Exam trap

The trap here is that candidates may confuse Private Endpoint with Service Endpoint, but Service Endpoint does not remove the public endpoint and still allows internet-based access if the firewall permits it, whereas Private Endpoint with public access disabled fully isolates the resource.

How to eliminate wrong answers

Option A is wrong because a public IP address with NSG rules still exposes the database to the internet, and NSGs only filter traffic at the subnet/NIC level, not prevent public endpoint access. Option B is wrong because a route table to the internet gateway directs traffic to the internet, which does not provide private access and would actually route traffic away from the private endpoint. Option D is wrong because an Azure CDN endpoint is a content delivery network for caching static content at edge locations, not a mechanism for private network access to a PaaS database.

56
MCQeasy

A company deploys a web application on multiple Azure VMs. They need to distribute incoming HTTP traffic across the VMs, offload SSL/TLS termination, and maintain session persistence (sticky sessions) so that all requests from a user session go to the same backend VM. Which Azure load balancing solution should they use?

A.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is a dedicated layer-7 (HTTP/HTTPS) load balancer that offers SSL offloading by terminating client SSL connections and re-encrypting traffic to backends if needed. It provides cookie-based session affinity, which ensures a user's requests are consistently routed to the same backend VM—a critical requirement for stateful web applications. Additionally, it supports URL path-based routing and an integrated Web Application Firewall, making it the correct choice for a web application deployed on multiple VMs within a single Azure region.

Why this answer

Azure Application Gateway is a Layer 7 load balancer that can route HTTP/HTTPS traffic, offload SSL/TLS termination, and support session persistence using cookie-based affinity. This makes it the correct choice for distributing incoming HTTP traffic across multiple VMs while maintaining sticky sessions and handling SSL termination at the gateway.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), forgetting that SSL termination and cookie-based sticky sessions require Layer 7 capabilities, not just Layer 4 load balancing.

How to eliminate wrong answers

Option B is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL/TLS termination or HTTP-level session persistence; it only supports source IP affinity, which is not cookie-based sticky sessions. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that does not handle SSL termination or session persistence; it directs traffic at the DNS level, not at the application layer. Option D is wrong because Azure Front Door is a global Layer 7 load balancer and CDN that can offload SSL and provide session affinity, but it is designed for global distribution across regions, not for distributing traffic within a single region to multiple VMs; using it for regional load balancing would introduce unnecessary latency and complexity.

57
Drag & Dropmedium

Drag and drop the steps to set up Azure Private Link for an Azure SQL Database into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for setting up Azure Private Link for an Azure SQL Database is: first create the private endpoint in the virtual network, then approve the private link connection from the Azure SQL Database side, next configure DNS (typically using a private DNS zone) to resolve the database's FQDN to the private endpoint IP, test connectivity from within the virtual network, and finally disable public access to the database to enforce private connectivity. This order ensures each step builds on the previous one, avoiding connectivity issues or premature security restrictions.

58
MCQeasy

A company deploys a web application across multiple Azure VMs in a single region. They want to distribute incoming HTTP traffic evenly across the VMs, offload SSL encryption, and provide a fixed public IP address for clients. Which Azure load balancing solution should they use?

A.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is a regional, layer 7 (HTTP/HTTPS) load balancer that terminates client SSL/TLS connections at the gateway, eliminating backend SSL overhead and enabling centralized certificate management. It exposes a single, fixed public VIP for all incoming web traffic, supports cookie-based session affinity, URL-path-based routing, and WebSocket forwarding, making it the natural choice for an HTTP workload spread across multiple VMs in one Azure region. Unlike layer 4 devices, it inspects HTTP headers and can redirect traffic based on host names or paths, so it fully satisfies the requirement for SSL offloading and a stable public IP for the web application.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that supports HTTP/HTTPS traffic, SSL termination, and cookie-based session affinity. It can distribute incoming HTTP traffic evenly across VMs, offload SSL encryption to reduce backend processing, and provide a fixed public IP address (VIP) for client access. This aligns with all three requirements: load balancing, SSL offload, and a static public IP.

Exam trap

The trap here is confusing Layer 4 (Azure Load Balancer) with Layer 7 (Application Gateway) capabilities, leading candidates to pick Azure Load Balancer because it is the default choice for distributing traffic across VMs, but it cannot offload SSL or handle HTTP-specific features like session affinity.

How to eliminate wrong answers

Option B (Azure Load Balancer) is wrong because it operates at Layer 4 (TCP/UDP) and cannot perform SSL termination or inspect HTTP traffic; it only forwards packets without understanding application-layer protocols. Option C (Azure Traffic Manager) is wrong because it is a DNS-based traffic router that distributes traffic across regions, not within a single region, and it does not provide a fixed public IP for clients (it uses DNS names) nor offloads SSL. Option D (Azure Front Door) is wrong because it is a global Layer 7 service designed for multi-region scenarios with advanced WAF and acceleration features; it does not provide a fixed public IP for clients (it uses a dynamic anycast IP) and is overkill for a single-region deployment.

59
MCQeasy

A company plans to migrate an on-premises application with strict low-latency requirements to Azure. The application must communicate with an Azure SQL Database. Which of the following is the best design to minimize latency?

A.Deploy the application in one region and Azure SQL Database in a different region, using Azure Traffic Manager.
B.Deploy the application on-premises and use a Point-to-Site VPN to connect to Azure SQL Database.
C.Deploy the application and Azure SQL Database in the same Azure region, and connect via Azure Private Link.
D.Deploy the application on-premises and use ExpressRoute to connect to Azure SQL Database.
AnswerC

Deploying the application and Azure SQL Database in the same Azure region minimizes physical distance between compute and data, drastically reducing network round-trip time. Azure Private Link creates a private endpoint with a NIC in the application's virtual network, so all SQL traffic flows over the Microsoft backbone and never traverses the public internet. This combination delivers the lowest possible latency and a secure, isolated connectivity path, meeting the performance and migration requirements in a best-practice architecture.

Why this answer

The best design because deploying both the application and Azure SQL Database in the same Azure region minimizes network distance and latency. Using Azure Private Link creates a private endpoint for the SQL Database within the application's virtual network, eliminating internet routing and reducing latency further by keeping traffic entirely within the Microsoft backbone network.

Exam trap

The trap here is that candidates often overestimate ExpressRoute's ability to eliminate latency, forgetting that physical distance from on-premises to Azure still adds delay, while co-locating both application and database in the same region with Private Link provides the lowest possible latency.

How to eliminate wrong answers

Option A is wrong because deploying the application and database in different regions introduces cross-region network latency, and Azure Traffic Manager only handles DNS-level load balancing, not direct low-latency connectivity. Option B is wrong because a Point-to-Site VPN over the internet adds significant latency due to encryption overhead and variable internet routing, failing to meet strict low-latency requirements. Option D is wrong because ExpressRoute provides a dedicated private connection from on-premises to Azure, but the application remains on-premises, so the network round-trip from on-premises to the Azure region still introduces higher latency compared to keeping both resources in the same Azure region.

60
MCQmedium

A company is designing a disaster recovery solution for a critical application that runs on Azure VMs in a single region. The RTO is 4 hours, and the RPO is 1 hour. The application uses Azure SQL Database. The company wants to minimize the cost of the disaster recovery solution while meeting the RTO and RPO. You need to recommend a solution. What should you recommend?

A.Use Azure SQL Database active geo-replication for the database and Azure Backup for VMs.
B.Use Azure Backup to back up VMs and Azure SQL Database to a secondary region.
C.Use Azure Traffic Manager to distribute traffic to VMs in multiple regions and Azure SQL Database failover groups.
D.Use Azure Site Recovery to replicate VMs to a secondary region and Azure SQL Database geo-replication for the database.
AnswerD

Azure Site Recovery continuously replicates managed disks of Azure VMs to the paired region with an RPO typically measured in seconds to a few minutes, and it supports automated, testable failover, so the compute tier comfortably meets the 1-hour RPO. Azure SQL Database geo-replication (or failover groups) asynchronously replays committed transactions to a secondary database, providing an RPO of seconds and enabling simple failover for the data tier. This combination covers both compute and data with continuous replication rather than backup or traffic routing, making it the correct DR architecture.

Why this answer

Azure Site Recovery provides orchestrated replication and failover for Azure VMs, meeting the 4-hour RTO with automated recovery plans. Azure SQL Database active geo-replication (or failover groups) enables continuous data synchronization with an RPO of 1 hour. This combination minimizes cost by using only the necessary replication services without over-provisioning resources.

Exam trap

The trap here is that candidates often confuse Azure Backup (long-term backup) with Azure Site Recovery (disaster recovery replication), leading them to choose a backup-only solution that cannot meet the RTO/RPO for rapid failover.

How to eliminate wrong answers

Option A is wrong because Azure Backup for VMs is designed for long-term retention and point-in-time restore, not for rapid failover to a secondary region; its RTO typically exceeds 4 hours for full VM recovery. Option B is wrong because Azure Backup for Azure SQL Database backs up to a secondary region as a backup copy, not as a continuously synchronized replica, so it cannot achieve a 1-hour RPO for disaster recovery failover. Option C is wrong because Azure Traffic Manager handles DNS-level traffic distribution but does not replicate VMs or databases; it requires pre-existing multi-region deployments, which contradicts the single-region design and would increase costs unnecessarily.

61
MCQhard

Refer to the exhibit. You are assigned an Azure policy that restricts resource group locations to eastus, westus, and centralus. A user attempts to create a resource group in 'eastus2' and receives a denial. The user argues that there are existing resources in 'eastus2' and that the policy should allow it. What is the best course of action to allow the resource group creation while maintaining compliance?

A.Instruct the user to create the resource group in an allowed location and then deploy resources to 'eastus2'
B.Add 'eastus2' to the list of allowed locations in the policy parameters
C.Create an Azure Policy exemption for the user's subscription
D.Disable the policy assignment for that subscription
AnswerA

The Azure Policy assignment targets the resource group resource type (Microsoft.Resources/subscriptions/resourceGroups), denying creation only when the group's location is not in the allowed list. Resource groups are logical containers, not regional boundaries; individual resources can be deployed to any region supported by the subscription, including eastus2. Instructing the user to create the resource group in an allowed location and then deploy to eastus2 satisfies the policy while preserving the intended geo-compliance controls.

Why this answer

Azure Policy evaluates resource group location at creation time, not the location of individual resources within it. A resource group is a logical container that can hold resources in any region, regardless of the resource group's own location. By creating the resource group in an allowed location (eastus, westus, or centralus), the user satisfies the policy constraint while still being able to deploy resources to 'eastus2' within that resource group.

Exam trap

The trap here is that candidates mistakenly believe a resource group's location restricts where its resources can be deployed, when in fact Azure resource groups can contain resources from any region regardless of the resource group's own location.

How to eliminate wrong answers

Option B is wrong because it modifies the policy to allow 'eastus2' globally, which weakens the compliance boundary and may violate organizational requirements. Option C is wrong because an exemption would bypass the policy entirely for the subscription, which is an over-engineered solution that reduces security posture and auditability. Option D is wrong because disabling the policy assignment removes all location restrictions for the subscription, which is a drastic measure that abandons compliance goals entirely.

62
Multi-Selecteasy

Your organization is implementing a security strategy for Azure resources. You need to enforce consistent security policies across all subscriptions and ensure compliance with regulatory standards. Which TWO services should you use?

Select 2 answers
A.Azure RBAC
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Azure Blueprints
E.Azure Policy
AnswersB, E

Microsoft Defender for Cloud continuously assesses Azure resources against regulatory benchmarks such as ISO 27001 and PCI DSS, surfacing compliance posture across every subscription through its regulatory compliance dashboard. This satisfies the stem's requirement for consistent policy enforcement and demonstrated regulatory compliance, complementing Azure Policy's preventive controls with detection and recommendations.

Why this answer

Microsoft Defender for Cloud (B) is correct because it provides continuous security assessment and regulatory compliance dashboards against standards such as ISO 27001, PCI DSS, and NIST, letting you measure and enforce compliance across subscriptions. Azure Policy (E) is correct because it enforces organizational standards and assesses compliance at scale by evaluating resource properties against policy definitions and applying deny, audit, or deployIfNotExists effects across all subscriptions. Together they cover both policy enforcement and regulatory compliance monitoring.

Azure RBAC (A) only controls who can perform actions on resources and does not enforce configuration or regulatory standards. Microsoft Sentinel (C) is a SIEM/SOAR solution for threat detection and incident response, not policy or compliance enforcement. Azure Blueprints (D) orchestrates deployments of artifacts including policies, but it is a deployment/governance packaging tool rather than the service that itself enforces and reports compliance across subscriptions.

63
MCQhard

Your organization is migrating an on-premises application to Azure. The application consists of a load-balanced web tier and a backend SQL Server database. The web tier requires session persistence (sticky sessions) and SSL offload. You need to design a solution that meets these requirements with minimal operational overhead. Which Azure service should you use for the web tier load balancing?

A.Azure Traffic Manager
B.Azure Application Gateway
C.Azure Front Door
AnswerB

Azure Application Gateway is a regional, Layer 7 reverse proxy explicitly built for HTTP/HTTPS workloads, making it the correct choice for an on-premises migration that needs session affinity and SSL termination. Its cookie-based session affinity preserves client sessions to the same backend server, and its SSL offload capability decrypts HTTPS traffic at the gateway so backend VMs avoid CPU-intensive encryption work. These features map directly to the requirements, and the gateway operates within a single region, aligning with the migration scale.

Why this answer

Azure Application Gateway is the correct choice because it is a Layer 7 load balancer that natively supports HTTP-based session persistence (sticky sessions) via cookie affinity and SSL termination (offload) at the gateway. This meets both requirements while minimizing operational overhead, as it handles SSL certificates and session affinity without requiring changes to the web tier.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers support SSL offload and sticky sessions, but only Layer 7 services can inspect HTTP traffic for these features.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager is a DNS-level traffic router that operates at Layer 3/4 and cannot perform SSL offload or maintain session persistence based on HTTP cookies. Option C is wrong because Azure Front Door is a global Layer 7 load balancer and CDN that supports SSL offload and session affinity, but it is designed for global distribution with edge caching and WAF, introducing unnecessary complexity and cost for a single-region web tier requiring minimal overhead. Option D is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot inspect HTTP headers for session persistence or terminate SSL, making it unsuitable for sticky sessions and SSL offload.

64
MCQhard

A company has multiple Azure virtual networks (VNets) spread across three Azure regions (West US, East US, and West Europe). They also have an on-premises network connected to East US via ExpressRoute. They need to connect all VNets to each other and to the on-premises network. They require centralized management of routing and the ability to enforce security policies such as forcing all internet-bound traffic from any VNet to pass through a central firewall in East US. Which Azure solution should they implement?

A.VNet peering between all VNets and use route tables for forced tunneling.
B.Azure Virtual WAN with a secured hub in East US.
C.ExpressRoute Global Reach with VNet peering to connect all VNets.
D.VPN gateways with BGP to connect all VNets.
AnswerB

Azure Virtual WAN provides a scalable hub-and-spoke architecture with centralized routing. A secured hub can include a firewall to enforce forced tunneling and security policies. All VNets and on-premises connect to the hub(s), simplifying management.

Why this answer

Azure Virtual WAN with a secured hub in East US provides a centralized hub-and-spoke architecture that connects all VNets and the on-premises network via ExpressRoute. The secured hub includes Azure Firewall, enabling forced tunneling of all internet-bound traffic from any VNet through the central firewall in East US, while Virtual WAN automatically manages routing between all spokes and the on-premises network.

Exam trap

The trap here is that candidates often assume VNet peering with route tables (Option A) is sufficient for centralized security, but they overlook the operational complexity and lack of built-in forced tunneling enforcement across multiple regions, which Virtual WAN's secured hub solves natively.

How to eliminate wrong answers

Option A is wrong because VNet peering alone creates a full mesh that lacks centralized routing management and cannot enforce forced tunneling through a single firewall without complex route table configurations that become unmanageable across multiple regions. Option C is wrong because ExpressRoute Global Reach only connects on-premises networks to Azure and does not provide inter-VNet connectivity or centralized security policy enforcement; VNet peering would still be needed but without centralized routing. Option D is wrong because VPN gateways with BGP can connect VNets but require a full mesh of VPN tunnels and do not natively support forced tunneling of all internet traffic through a central firewall without additional complex routing and gateway configurations.

65
MCQmedium

You are designing a connectivity solution for a hybrid network. The company has an on-premises network connected to an Azure virtual network via ExpressRoute. They also have a site-to-site VPN to the same Azure virtual network as a backup. When the ExpressRoute connection fails, traffic should automatically fail over to the VPN. How should you configure the routes to ensure automatic failover?

A.Configure Azure Traffic Manager with a priority routing method to direct traffic to ExpressRoute first.
B.Ensure the ExpressRoute connection has a lower BGP metric than the VPN connection; Azure automatically prefers lower metric.
C.Set the BGP metrics (local preference) on the ExpressRoute connection to be higher than the VPN connection.
D.Configure Azure Route Server to propagate routes with a lower metric for the VPN connection.
AnswerB

ExpressRoute and VPN gateway BGP peering allow Azure to choose between the two paths by comparing BGP attributes; a lower BGP metric (such as MED) on the ExpressRoute connection makes it the preferred route because Azure selects the path with the lowest metric. When the ExpressRoute circuit fails, its route is withdrawn and the VPN route with the higher metric becomes the only available path, enabling automatic failover. This is the standard, supported coexistence design for resilient hybrid networking, and no additional traffic-management or routing services are required.

Why this answer

B is correct because when both ExpressRoute and VPN connections use BGP to advertise routes to Azure, Azure automatically selects the route with the lowest BGP metric (MED). By configuring the ExpressRoute connection with a lower BGP metric than the VPN connection, Azure will prefer the ExpressRoute path under normal conditions. If the ExpressRoute fails, its routes are withdrawn, and Azure falls back to the VPN routes, providing automatic failover.

Exam trap

The trap here is confusing BGP metrics (MED) with local preference; local preference is used for outbound path selection within an AS, while MED influences inbound path selection from a neighbor AS, and Azure uses MED for route preference in hybrid connectivity.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager operates at the DNS level and cannot influence routing within a hybrid network; it directs user traffic to endpoints based on DNS resolution, not IP-level path selection for existing connections. Option C is wrong because setting a higher BGP local preference on the ExpressRoute connection would make it less preferred (Azure prefers higher local preference), which would cause the VPN to be used as the primary path, not the backup. Option D is wrong because Azure Route Server is used to exchange routes between virtual network gateways and network virtual appliances (NVAs), not to set metrics for failover between ExpressRoute and VPN; lowering the metric for the VPN connection would make it preferred over ExpressRoute, defeating the failover purpose.

66
MCQhard

You executed the above Azure CLI commands. The remote VNet (yourVNet) has address space 10.1.0.0/16. What is the result?

A.The peering command fails because the remote VNet does not exist.
B.A VNet with one subnet is created, and no peering is established.
C.A VNet with two subnets is created, and a VNet peering is established.
D.Only the first subnet is created, and the peering is established.
AnswerC

The sequence of Azure CLI commands creates the VNet, adds a second subnet, and then creates a VNet peering from the local to the remote VNet. Both subnets are created before peering, and the peering resource is successfully provisioned, allowing resources in the two VNets to communicate.

Why this answer

The Azure CLI commands create a VNet named 'myVNet' with two subnets ('subnet1' and 'subnet2') using the 'az network vnet create' command, which supports multiple subnet configurations in a single call. The subsequent 'az network vnet peering create' command establishes a VNet peering from 'myVNet' to the remote VNet 'yourVNet' (address space 10.1.0.0/16). Since both VNets exist and the commands are syntactically correct, the result is a VNet with two subnets and a successful peering.

Exam trap

The trap here is that candidates may think the 'az network vnet create' command only creates a single subnet or that the peering command will fail due to missing parameters, but the CLI defaults allow both subnets and peering to succeed without explicit flags.

How to eliminate wrong answers

Option A is wrong because the remote VNet 'yourVNet' is assumed to exist (the question states it has address space 10.1.0.0/16), and the peering command would only fail if the remote VNet did not exist, but no error is indicated. Option B is wrong because the 'az network vnet create' command with '--subnets subnet1 subnet2' creates two subnets, not one, and the peering command is executed successfully. Option D is wrong because the '--subnets' parameter in 'az network vnet create' creates both specified subnets, not just the first, and the peering is established after the VNet creation.

67
MCQeasy

You are designing a solution to grant external partners access to specific Azure resources. The partners must authenticate using their own corporate credentials. You need to manage their access centrally. Which Microsoft Entra ID feature should you use?

A.Microsoft Entra ID Domain Services
B.Microsoft Entra ID B2C
C.Microsoft Entra ID B2B collaboration
D.Microsoft Entra ID Connect
AnswerC

Microsoft Entra ID B2B collaboration is the correct choice because it allows external partners to use their own corporate identities (from any Azure AD tenant, Microsoft account, or even Google/SAML/WS-Fed identity provider) to access your applications and resources. You invite the partner's users or enable self-service sign-up; they are represented as guest users in your Entra ID tenant, while their authentication is handled by their home organization. This preserves the partner's identity lifecycle and enables fine-grained conditional access policies, multi-factor authentication, and governance controls like access reviews, making it the standard for partner access scenarios.

Why this answer

Microsoft Entra ID B2B collaboration is the correct choice because it allows external partners to authenticate using their own corporate credentials (via their home tenant or identity provider) while enabling centralized management of their access to Azure resources. B2B collaboration supports features like cross-tenant synchronization, conditional access policies, and entitlement management, making it ideal for granting granular, centrally managed access to external users without requiring them to create new accounts.

Exam trap

The trap here is confusing B2B collaboration (for external partners with existing corporate identities) with B2C (for customer-facing applications with social or local accounts), as both involve external users but serve fundamentally different scenarios.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Domain Services provides managed domain services (e.g., LDAP, Kerberos, NTLM) for legacy applications, not for granting external partner access with their own credentials. Option B is wrong because Microsoft Entra ID B2C is designed for customer-facing identity management (e.g., social logins, self-service sign-up) for applications, not for business-to-business partner access to Azure resources. Option D is wrong because Microsoft Entra ID Connect is used for synchronizing on-premises Active Directory identities to the cloud, not for managing external partner access.

68
Multi-Selectmedium

Your organization is planning to migrate a large number of on-premises file servers to Azure. The data includes millions of small files. You need to select a storage solution that supports SMB protocol and can handle high file counts. Which TWO Azure services meet these requirements?

Select 2 answers
A.Azure Stack Edge
B.Azure Blob Storage with NFS 3.0
C.Azure Files
D.Azure NetApp Files
E.Azure Disk Storage
AnswersC, D

Azure Files provides fully managed, cloud-native SMB (and NFS) file shares that are accessible over the internet or via private endpoints, with integration into Azure Active Directory for identity-based access control. It can scale to store millions of files across standard and premium tiers, making it a straightforward and cost-effective choice for migrating on-premises file servers without rearchitecting applications. Performance is suitable for most workloads, and the service handles patching, availability, and durability automatically, so it requires the least operational overhead among the options.

Why this answer

Azure Files provides fully managed SMB file shares in the cloud, supporting the SMB protocol natively and capable of handling high file counts (up to 100 million files per share with large shares enabled). This makes it a direct match for migrating on-premises file servers with millions of small files.

Exam trap

The trap here is that candidates often confuse Azure Blob Storage with NFS 3.0 as an SMB-compatible solution, but NFS and SMB are distinct protocols, and the question explicitly requires SMB support.

69
Multi-Selecthard

Which THREE of the following are best practices for securing an Azure Kubernetes Service (AKS) cluster? (Choose three.)

Select 3 answers
A.Enable Azure Policy for Kubernetes to enforce security policies.
B.Enable Azure AD integration for cluster authentication.
C.Use managed identities for pods to access Azure resources securely.
D.Allow all pod-to-pod communication within the cluster without network policies.
E.Disable Kubernetes RBAC and use only Azure RBAC for simplicity.
AnswersA, B, C

Azure Policy for Kubernetes extends Gatekeeper to audit and deny non-compliant workloads at admission time, enforcing pod security standards, resource limits and allowed registries directly inside the cluster. This satisfies the stem's requirement to secure AKS by preventing insecure configurations from being deployed, rather than merely detecting them afterwards.

Why this answer

Option A is correct because Azure Policy for Kubernetes (via the Azure Policy add-on) enforces governance and security controls at scale, such as restricting privileged containers, hostPath mounts, and allowed registries, and it reports compliance for AKS clusters. Option B is correct because integrating Azure AD (Microsoft Entra ID) with AKS enables centralized, identity-based authentication using Azure AD credentials and supports Kubernetes RBAC authorization, eliminating static local admin accounts. Option C is correct because managed identities (or workload identity) let pods obtain Azure AD tokens without storing credentials, enabling secure, secretless access to Azure resources like Key Vault and Storage.

Option D is not a best practice: allowing unrestricted pod-to-pod traffic removes segmentation and increases lateral movement risk; network policies (Calico or Azure NPM) should restrict traffic. Option E is incorrect because disabling Kubernetes RBAC removes fine-grained, namespace-scoped authorization; Azure RBAC alone does not replace Kubernetes RBAC for in-cluster permissions, and both should be used together.

70
MCQeasy

Your company has an Azure subscription with multiple virtual networks (VNets) in different regions. You need to ensure that resources in all VNets can communicate with each other privately over the Microsoft backbone network. Which Azure solution should you implement?

A.VNet peering
B.Azure ExpressRoute
C.Azure DNS
D.Azure VPN Gateway
AnswerA

VNet peering establishes one-to-one connectivity between two Azure virtual networks over Microsoft's private backbone, allowing resources in separate VNets to communicate using private IP addresses without any public internet traversal, gateways, or extra cost per flow. This is the native Azure solution for inter-VNet connectivity because it is direct, unilateral, and supports both regional and global peering, making it the correct choice for joining spoke VNets to a hub or linking peered environments.

Why this answer

VNet peering connects Azure virtual networks privately over the Microsoft backbone network, enabling resources in different VNets (including those in different regions) to communicate directly without traversing the public internet. It uses the Azure infrastructure to route traffic between peered VNets with low latency and high bandwidth, meeting the requirement for private inter-VNet communication.

Exam trap

The trap here is that candidates often confuse VNet peering with VPN Gateway, assuming a VPN is required for private connectivity, but VNet peering provides direct private connectivity over the Microsoft backbone without any public internet exposure or gateway overhead.

How to eliminate wrong answers

Option B is wrong because Azure ExpressRoute extends on-premises networks into Azure over a private connection, not for connecting multiple Azure VNets to each other. Option C is wrong because Azure DNS provides domain name resolution services, not network connectivity between VNets. Option D is wrong because Azure VPN Gateway creates encrypted tunnels over the public internet or ExpressRoute, but it is typically used for site-to-site or point-to-site connectivity, not for direct private VNet-to-VNet communication across regions without additional configuration and public internet exposure.

71
MCQhard

You are designing a solution for a critical application that requires low latency between multiple Azure regions. The application must handle failover automatically if a region becomes unavailable. You need to distribute traffic across regions and ensure that users are directed to the closest healthy endpoint. What should you implement?

A.Azure Standard Load Balancer with cross-region load balancing
B.Azure Front Door with priority routing
C.Azure Traffic Manager with geographic routing and endpoint monitoring
D.Azure Application Gateway with autoscaling
AnswerC

Azure Traffic Manager is a DNS-based global traffic manager that resolves user queries to the most appropriate endpoint based on routing methods like geographic, priority, weighted, or performance; when combined with geographic routing and endpoint monitoring, it can direct users from specific geographies to their closest configured regional endpoint and automatically fail over if health checks fail. Because it operates at the DNS layer rather than the anycast or network layer, it provides a clean, global routing mechanism that matches the requirement for critical application availability.

Why this answer

Azure Traffic Manager with geographic routing and endpoint monitoring is the correct choice because it operates at the DNS level, directing users to the closest healthy endpoint based on geographic location. This ensures low latency by routing traffic to the nearest region and provides automatic failover by continuously monitoring endpoint health and rerouting traffic if a region becomes unavailable.

Exam trap

The trap here is that candidates often confuse Azure Front Door's priority routing with geographic routing, but priority routing does not direct users to the closest endpoint—it only provides a static failover order, whereas Traffic Manager's geographic routing dynamically selects the nearest healthy region.

How to eliminate wrong answers

Option A is wrong because Azure Standard Load Balancer with cross-region load balancing operates at Layer 4 and distributes traffic across regional backends, but it does not provide geographic proximity-based routing to direct users to the closest endpoint; it uses a hash-based distribution. Option B is wrong because Azure Front Door with priority routing is designed for global HTTP/S traffic with advanced features like SSL termination and WAF, but priority routing sends all traffic to a primary region and only fails over to a secondary region, not to the closest healthy endpoint based on user location. Option D is wrong because Azure Application Gateway with autoscaling is a regional Layer 7 load balancer that operates within a single Azure region and cannot distribute traffic across multiple regions or provide geographic proximity routing.

72
MCQhard

A company is designing a solution for a data analytics workload. The company receives streaming data from multiple sources, including IoT devices and social media feeds. The data must be ingested, processed in real-time, and stored for historical analysis. The company also wants to use Power BI to create real-time dashboards from the streaming data. You need to recommend a data pipeline architecture. What should you include?

A.Use Azure IoT Hub for ingestion, Azure Stream Analytics for processing, and Power BI for dashboards.
B.Use Azure Event Hubs for ingestion, Azure Data Lake Analytics for processing, and Power BI for dashboards.
C.Use Azure Event Hubs for ingestion, Azure Stream Analytics for real-time processing, and Power BI for dashboards.
D.Use Azure Event Hubs for ingestion, Azure Synapse Analytics for processing, and Power BI for dashboards.
AnswerC

This option is the only one that correctly assembles a real-time analytics pipeline: Azure Event Hubs ingests high-throughput, time-ordered event streams (such as social media posts) with low latency and native support for multiple independent consumers; Azure Stream Analytics then queries that stream in-memory using SQL-like temporal windows (e.g., tumbling, hopping, sliding) to aggregate and detect patterns as events arrive; Power BI consumes the Stream Analytics output via its streaming API or pre-aggregated datasets to render live dashboards. Together these three services provide the necessary ingestion speed, continuous processing, and real-time visualization, with no batch layer in the critical path.

Why this answer

Azure Event Hubs is designed for high-throughput ingestion of streaming data from multiple sources, including IoT devices and social media feeds. Azure Stream Analytics provides real-time processing with low latency, and it can output directly to Power BI for live dashboards, meeting all requirements for ingestion, real-time processing, and visualization.

Exam trap

The trap here is confusing Azure IoT Hub (device management and bi-directional communication) with Azure Event Hubs (general-purpose event ingestion), and assuming that batch processing services like Azure Data Lake Analytics or Azure Synapse Analytics can handle real-time streaming requirements.

How to eliminate wrong answers

Option A is wrong because Azure IoT Hub is optimized for bi-directional communication with IoT devices and is not the best choice for ingesting social media feeds or general streaming data; it also lacks the native integration with Power BI for real-time dashboards that Event Hubs provides. Option B is wrong because Azure Data Lake Analytics is a batch processing service (U-SQL) and does not support real-time stream processing required for live dashboards. Option D is wrong because Azure Synapse Analytics is primarily a data warehouse for analytics on stored data, not a real-time stream processing engine; it would introduce unnecessary latency for live dashboards.

73
Multi-Selectmedium

Your company is designing a hybrid identity solution that will allow users to authenticate to Azure resources using their on-premises Active Directory credentials. The solution must support multi-factor authentication (MFA) and conditional access policies. Which TWO components should you include?

Select 2 answers
A.Microsoft Entra Connect
B.Active Directory Federation Services (AD FS)
C.Microsoft Entra ID
D.Azure AD Application Proxy
E.Microsoft Intune
AnswersA, C

Microsoft Entra Connect is the synchronization engine that replicates on-premises Active Directory Domain Services (AD DS) objects and hashed password or pass-through authentication information to Microsoft Entra ID. It enables users to sign in to Azure resources with their corporate AD credentials without needing a separate cloud account, and supports Password Hash Synchronization (PHS), Pass-through Authentication (PTA), and Seamless SSO as managed authentication options. This makes it the correct component because it establishes the identity bridge between the on-premises directory and Entra ID, which is the tenant that authenticates Azure resource access.

Why this answer

Microsoft Entra Connect synchronizes on-premises Active Directory identities to Microsoft Entra ID, enabling users to authenticate with their corporate credentials. Microsoft Entra ID is the cloud-based identity and access management service that processes authentication requests, enforces multi-factor authentication (MFA), and evaluates conditional access policies. Together, they form the core of a hybrid identity solution that supports MFA and conditional access.

Exam trap

The trap here is that candidates often assume AD FS is mandatory for hybrid identity with MFA and conditional access, but Microsoft Entra Connect combined with Microsoft Entra ID natively supports these features without federation.

74
MCQmedium

A company has deployed several Azure VMs that do not have public IP addresses. Administrators need to securely connect to these VMs using RDP and SSH from the internet over a browser without deploying a jump box or managing VPN connections. The solution must use Microsoft Entra ID authentication for single sign-on. Which Azure service should they use?

A.Azure Jump Box VM
B.Azure Bastion
C.Azure VPN Gateway
D.Azure ExpressRoute
AnswerB

Azure Bastion is a fully managed, PaaS-based RDP/SSH proxy deployed directly into a dedicated subnet within your virtual network, allowing browser-based or native client connections to VMs that have no public IP addresses. It natively integrates with Microsoft Entra ID for user authentication, enabling single sign-on, passwordless sign-in, and Conditional Access enforcement, and it also supports Azure RBAC to control which users can reach which VMs. Because it is a hardened, managed service, it eliminates the need to maintain jump box VMs or public endpoints, and it can enforce session revocation and time-based access policies for enhanced security.

Why this answer

Azure Bastion provides secure, seamless RDP and SSH connectivity to Azure VMs directly from the Azure portal over TLS, without requiring public IP addresses, jump boxes, or VPN connections. It supports Microsoft Entra ID authentication for single sign-on, meeting the requirement for browser-based access with no additional management overhead.

Exam trap

The trap here is that candidates often confuse Azure Bastion with a jump box VM or assume VPN Gateway is required for secure remote access, overlooking that Bastion provides browser-based RDP/SSH without any public IP or VPN infrastructure.

How to eliminate wrong answers

Option A is wrong because a jump box VM would itself require a public IP address or VPN connectivity, and would need to be managed and patched, violating the 'without deploying a jump box' requirement. Option C is wrong because Azure VPN Gateway establishes site-to-site or point-to-site VPN tunnels, requiring client software and VPN configuration, not browser-based access, and does not inherently support Microsoft Entra ID authentication for RDP/SSH sessions. Option D is wrong because Azure ExpressRoute provides a dedicated private network connection from on-premises to Azure, not internet-based browser access, and does not offer RDP/SSH connectivity over a browser.

75
Multi-Selectmedium

Your company is designing a hybrid network architecture that connects multiple on-premises sites to Azure. You need to ensure high availability and redundancy for the connection. Which TWO solutions should you recommend? (Choose two.)

Select 2 answers
A.Deploy two ExpressRoute circuits in active-passive mode
B.Implement Azure DNS Private Resolver for resolution
C.Use Azure VPN Gateway in active-active mode
D.Use a single VPN gateway with active-standby mode
E.Use a single ExpressRoute circuit with a VPN gateway as failover
AnswersA, C

Deploying two ExpressRoute circuits in active-passive mode is correct because each circuit represents a physically distinct path, ideally from different providers and peering locations, to Microsoft's edge, eliminating a single point of failure in the private network. BGP determines the primary path through route preference mechanisms such as local preference or AS path prepend, and on failure the secondary circuit automatically takes over without any configuration change. This architecture satisfies a high-availability hybrid networking requirement and enables the ExpressRoute service-level agreement.

Why this answer

Deploying two ExpressRoute circuits in active-passive mode provides redundancy for the on-premises-to-Azure connection. If the primary circuit fails, traffic automatically fails over to the passive circuit, ensuring high availability. Option C is correct because an Azure VPN Gateway in active-active mode uses two active tunnels to provide redundancy and load balancing, which is essential for a highly available hybrid network.

Exam trap

The trap here is that candidates often confuse redundancy at the gateway level (active-active vs. active-standby) with redundancy at the circuit level, and may incorrectly select a single ExpressRoute circuit with a VPN failover, which still has a single point of failure for the circuit itself.

Page 1 of 4 · 241 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure Solutions questions.