Courseiva

AZ-305 · topic practice

Design infrastructure solutions practice questions

Domain 3 (32%) covers designing Azure infrastructure: compute, networking, storage, and monitoring. Expect scenario items on migrating file servers, choosing PaaS vs IaaS, designing backup and disaster recovery, securing networks with NSGs and private endpoints, and centralizing logs with Azure Monitor and Microsoft Defender for Cloud.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design infrastructure solutions

What the exam tests

What to know about Design infrastructure solutions

Be able to map business requirements (protocol, identity, RPO/RTO, compliance) to concrete Azure services and redundancy tiers. The single most important skill is justifying each infrastructure choice against stated constraints rather than defaulting to the most feature-rich or expensive option.

Selecting Azure Files, NetApp Files, or Blob Storage for SMB and Entra ID authentication

Designing hub-spoke or Virtual WAN topologies with Azure Firewall, NSGs, and private endpoints

Choosing Azure Backup, Site Recovery, and geo-redundant storage for RPO/RTO targets

Centralizing security telemetry with Log Analytics, Azure Monitor, and Defender for Cloud

Watch out for

Common Design infrastructure solutions exam traps

  • ▸Confusing Azure Policy (governance and compliance enforcement) with Azure RBAC (identity-based access control) when the scenario asks for either.
  • ▸Assuming Azure Files supports Entra ID Kerberos authentication without domain-joining the storage account to Entra Domain Services or on-premises AD.
  • ▸Picking zone-redundant or geo-redundant storage when the requirement is only local redundancy, inflating cost without meeting a stated SLA.

Practice set

Design infrastructure solutions questions

20 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Review the full routing breakdown →

A company has multiple Azure subscriptions and on-premises data centers connected via ExpressRoute. They want to centralize connectivity to the internet and enforce a single web filtering and security policy for all outbound internet traffic from Azure VMs. Which Azure networking architecture should they implement?

A company is developing a containerized microservices application. They want to minimize operational overhead for managing orchestration. The application has a low-to-medium traffic pattern that can spike unpredictably. They need fast scaling and pay-per-second billing. Which Azure compute service should they use?

A company has an Azure API Management instance deployed in the internal virtual network (VNet) mode. They want to securely expose their backend APIs to external partners over the internet. External partners need to authenticate using OAuth2 tokens. The company also wants to enforce rate limits (throttling) per subscription, cache responses, and enable CORS. Which Azure service should they use to expose the APIs?

A company has deployed Azure virtual machines without public IP addresses. They need to provide secure RDP and SSH access to these VMs for administrators from the corporate network (on-premises). The solution must integrate with Microsoft Entra ID for authentication and support multi-factor authentication (MFA). It must not require any public endpoint exposure on the VMs. Which Azure service should they use?

Question 5hardmultiple choice
Read the full DNS explanation →

A company has multiple Azure virtual networks (VNets) in different regions and an on-premises data center. They need to implement a hub-and-spoke topology where the hub VNet hosts shared services like firewalls and DNS. All traffic between spokes, and between spokes and on-premises, must be routed through the hub for inspection. Additionally, spoke VNets must not be able to directly communicate with each other. Which Azure networking solution should they implement to meet these requirements with minimal administrative overhead?

A company deploys a web application on Azure VMs in an availability set. They need to expose the application to the internet with SSL termination and health probes. Additionally, they need to protect against DDoS attacks and common web vulnerabilities. Which Azure service should they use?

A company plans to deploy a web application on Azure VMs across multiple availability zones. They need to distribute incoming HTTP traffic across the VMs and provide health probes. Which Azure load balancing solution should they use?

You are designing a hybrid identity solution for a company with 5,000 on-premises users. The company wants to use Microsoft Entra ID for single sign-on and self-service password reset. They also need to synchronize user passwords to the cloud. Which feature should you enable to ensure password changes on-premises are immediately propagated to Microsoft Entra ID?

You are an Azure administrator. You attempt to create a new virtual machine with size Standard_DS2_v2 in a subscription where the above Azure Policy is assigned. What will happen?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Compute/virtualMachines"
      },
      "then": {
        "effect": "deny",
        "details": {
          "field": "Microsoft.Compute/virtualMachines/size",
          "notIn": ["Standard_D2s_v3", "Standard_D4s_v3", "Standard_D8s_v3"]
        }
      }
    },
    "parameters": {}
  }
}
```

You run the above KQL query in Azure Monitor Logs. What does the query return?

Exhibit

Refer to the exhibit.

```sql
-- Kusto Query Language (KQL) query
AzureActivity
| where OperationNameValue == 'MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE'
| where ActivityStatusValue == 'Succeeded'
| summarize count() by Caller, bin(TimeGenerated, 1h)
```

A company is designing a multi-region disaster recovery solution for Azure VMs. They need to ensure that if the primary region fails, VMs can be failed over to a secondary region with minimal data loss. The application writes data to Azure SQL Database and Azure Files. Which Azure service should they use to meet the recovery point objective (RPO) of 5 seconds for the SQL Database?

A company is designing a containerized application on Azure Kubernetes Service (AKS). They need to ensure that the control plane is managed by Microsoft and that the worker nodes are isolated to a single tenant. They also require that the worker nodes be automatically patched for security updates. Which AKS node pool type should they use?

A company is designing a network architecture for a three-tier application hosted on Azure VMs. The web tier must be accessible from the internet, while the application and database tiers must not have direct internet access. They also need to encrypt traffic between tiers. Which TWO solutions should they implement?

A company is migrating a legacy application to Azure VMs. The application requires a static IP address that does not change if the VM is stopped and started. Which type of IP address should they assign to the VM?

A financial services company must store sensitive customer data in Azure Blob Storage. The data must be encrypted at rest using a customer-managed key stored in a hardware security module (HSM). The key must be automatically rotated every 90 days. Which combination of Azure services and features should they use?

Your company plans to migrate on-premises SQL Server databases to Azure. The databases require high availability with automatic failover to a secondary region in the event of a regional outage. The solution must minimize data loss and support read-only queries on the secondary replica. Which Azure service should you use?

You are designing a networking solution for a multi-tier application in Azure. The front-end web tier must be accessible from the internet, while the back-end database tier must only be accessible from the web tier. You need to minimize management overhead and ensure that the back-end tier is not directly reachable from the internet. What should you use?

You are designing an identity solution for a multinational corporation that uses Microsoft Entra ID. The company has a complex organizational structure with multiple subsidiaries. You need to ensure that users from one subsidiary cannot access resources in another subsidiary unless explicitly granted. The solution must minimize administrative overhead. What should you use?

Your company plans to migrate a legacy on-premises application to Azure. The application has a monolithic architecture and requires low-latency access to a shared file system. You need to choose a migration strategy that minimizes changes to the application code. Which TWO options should you recommend? (Choose two.)

Your company is designing a new application that will run on Azure VMs. The application must be highly available across two Azure regions. You need to ensure that the application can automatically fail over if a regional outage occurs. Which THREE components should you include in the architecture? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design infrastructure solutions sessions

Start a Design infrastructure solutions only practice session

Every question in these sessions is drawn from the Design infrastructure solutions domain — nothing else.

Related practice questions

Related AZ-305 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-305 exam test about Design infrastructure solutions?
Be able to map business requirements (protocol, identity, RPO/RTO, compliance) to concrete Azure services and redundancy tiers. The single most important skill is justifying each infrastructure choice against stated constraints rather than defaulting to the most feature-rich or expensive option.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design infrastructure solutions questions in a focused session?
Yes — the session launcher on this page draws every question from the Design infrastructure solutions domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-305 topics?
Use the topic links above to move to related areas, or go back to the AZ-305 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-305 exam covers. They are not copied from any real exam or dump site.