Courseiva

CCNA Infrastructure Solutions Questions

75 of 241 questions · Page 2/4 · Infrastructure Solutions topic · Answers revealed

76
MCQeasy

A startup is building a web application that will be used by a small number of users initially but is expected to grow rapidly. The application runs on Linux and uses a PostgreSQL database. The company wants to minimize operational overhead and costs during the early stages. You need to recommend a platform as a service (PaaS) solution for both the application and the database. What should you recommend?

A.Deploy the application on Azure App Service for Linux and use Azure Database for PostgreSQL.
B.Deploy the application on Azure Kubernetes Service (AKS) and use Azure Database for PostgreSQL.
C.Deploy the application as Azure Functions and use Azure Cosmos DB for storage.
D.Deploy the application on Azure Virtual Machines and use PostgreSQL on the same VM.
AnswerA

Azure App Service for Linux is an enterprise-grade PaaS that fully manages the application runtime and operating system patching, with built-in load balancing, TLS termination, and autoscaling. Pairing it with Azure Database for PostgreSQL yields a fully managed relational database with automated backups, high availability, and predictable scaling, eliminating both application- and data-tier administrative chores. This combination keeps the startup focused only on business logic and precisely satisfies the requirement to minimize operational overhead.

Why this answer

Azure App Service for Linux provides a fully managed PaaS environment for hosting web applications, handling scaling, patching, and load balancing with minimal operational overhead. Azure Database for PostgreSQL is a managed PaaS database service that offers built-in high availability, automated backups, and scaling, which aligns with the startup's need to minimize costs and operational complexity during rapid growth.

Exam trap

The trap here is that candidates may over-engineer the solution by choosing AKS (Option B) for its scalability features, forgetting that PaaS services like App Service can also scale automatically with far less operational burden, especially for a startup with initially few users.

How to eliminate wrong answers

Option B is wrong because Azure Kubernetes Service (AKS) is a container orchestration platform that introduces significant operational overhead (cluster management, node scaling, networking) and is overkill for a small user base, contradicting the goal of minimizing overhead. Option C is wrong because Azure Functions is a serverless compute service designed for event-driven, short-lived workloads, not for hosting a full web application with persistent connections, and Azure Cosmos DB is a NoSQL database, not compatible with the PostgreSQL requirement. Option D is wrong because deploying on Azure Virtual Machines is an IaaS solution that requires manual OS patching, database administration, and scaling, which increases operational overhead and costs, contrary to the PaaS requirement.

77
MCQeasy

A company has virtual machines in Azure that need to be grouped across multiple fault domains and update domains to ensure high availability. They plan to deploy three VMs running the same application tier. Which Azure feature should they use to provide redundancy within a single region?

A.Availability Zone
B.Availability Set
C.Virtual Machine Scale Set with manual scaling
D.Azure Site Recovery
AnswerB

An Availability Set is the correct grouping construct because it logically groups VMs so that Azure automatically distributes them across fault domains (distinct hardware racks with shared power and network switches) and update domains (groups that undergo planned maintenance one at a time). This placement ensures that during either hardware failure or Azure patching, at least one VM in the set remains available, meeting the high-availability requirement within a single datacenter. Availability Sets do not require identical VM configurations, allowing heterogeneous workloads to be protected together.

Why this answer

An Availability Set distributes VMs across multiple fault domains (shared hardware, power, and networking) and update domains (planned maintenance) within a single Azure datacenter. This ensures that at least one VM remains available during both hardware failures and Azure patching cycles. For three VMs running the same application tier, an Availability Set provides the required redundancy without the complexity of zone-level isolation.

Exam trap

The trap here is that candidates often confuse Availability Zones (which provide datacenter-level isolation) with Availability Sets (which provide rack-level isolation within a single datacenter), leading them to select Availability Zones when the scenario only requires intra-datacenter redundancy.

How to eliminate wrong answers

Option A is wrong because Availability Zones provide physical separation across different datacenters within a region, which is overkill and incurs cross-zone latency; the question specifies redundancy within a single region but not across zones. Option C is wrong because Virtual Machine Scale Sets with manual scaling still place VMs across fault and update domains automatically, but the question explicitly asks for grouping across multiple fault and update domains, which is the core purpose of an Availability Set, not a scale set. Option D is wrong because Azure Site Recovery is a disaster recovery solution for replicating VMs to a secondary region, not for providing redundancy within a single region.

78
MCQmedium

A company deploys a web application across multiple Azure VMs in a single region. They need to distribute incoming HTTP traffic, offload SSL termination, and perform URL-based routing to different backend pools (e.g., /images to one pool, /api to another). Which Azure load balancing solution should they use?

A.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is the correct choice because it operates at Layer 7 (HTTP/HTTPS), enabling URL path-based routing to distribute traffic to backend Azure VM pools based on request paths. It also provides SSL termination at the gateway, reducing the backend VMs' TLS processing overhead, and supports features like cookie-based session affinity, Web Application Firewall (WAF), and autoscaling—all within a single Azure region, which directly matches the deployment architecture.

Why this answer

Azure Application Gateway is a Layer 7 load balancer that can distribute HTTP traffic, offload SSL termination, and perform URL-based routing to different backend pools. This directly matches the requirements for routing /images and /api traffic to separate pools while handling SSL termination at the gateway.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming all load balancers can handle HTTP routing and SSL termination, but only Layer 7 solutions like Application Gateway or Front Door can perform URL-based routing and SSL offloading.

How to eliminate wrong answers

Option B is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and cannot perform SSL termination or URL-based routing, which are Layer 7 features. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic router that directs traffic based on DNS resolution, not HTTP-level routing or SSL termination. Option D is wrong because Azure Front Door is a global Layer 7 service designed for multi-region scenarios with CDN capabilities, but the question specifies a single-region deployment, making Application Gateway the more appropriate and cost-effective choice.

79
Multi-Selecthard

You are designing a microservices architecture on Azure Kubernetes Service (AKS). The solution must handle traffic spikes by automatically scaling pods based on CPU utilization. Additionally, you need to minimize cost by scaling down nodes when not in use. Which two features should you implement? (Choose two.)

Select 2 answers
B.Horizontal Pod Autoscaler (HPA)
C.Vertical Pod Autoscaler (VPA)
D.Azure Container Instances (ACI)
E.Cluster Autoscaler
AnswersB, E

Horizontal Pod Autoscaler is a Kubernetes control loop that queries the Metrics API for CPU, memory, or custom application metrics and automatically updates the replica count of a Deployment or ReplicaSet. This scaling mechanism is fundamental to microservices on AKS because it dynamically matches the number of running pod instances to the observed demand, ensuring high availability and cost efficiency without manual intervention.

Why this answer

Horizontal Pod Autoscaler (HPA) automatically scales the number of pod replicas based on observed CPU utilization (or custom metrics), directly addressing the requirement to handle traffic spikes by scaling pods. Cluster Autoscaler automatically adjusts the number of AKS nodes by scaling down unused nodes and scaling up when pods are unschedulable, which minimizes cost by reducing node count during low usage.

Exam trap

The trap here is that candidates often confuse Horizontal Pod Autoscaler (which scales pods) with Cluster Autoscaler (which scales nodes), or mistakenly think that a load balancer or ACI can handle the scaling requirements directly, but the question explicitly requires both pod-level and node-level scaling for cost minimization.

80
Multi-Selecthard

A multinational corporation is designing a backup and disaster recovery strategy for Azure IaaS VMs. The solution must support cross-region failover, meet a recovery point objective (RPO) of 15 minutes, and a recovery time objective (RTO) of 1 hour. Which TWO options should you include in the design?

Select 2 answers
A.Azure Backup with geo-redundant storage (GRS)
B.Azure Backup with locally redundant storage (LRS)
C.Managed disk snapshots
D.Azure Backup with zone-redundant storage (ZRS)
E.Azure Site Recovery
AnswersA, E

Azure Backup with GRS replicates backup data to a secondary region, meeting the cross-region failover requirement and RPO of 15 minutes.

Why this answer

Azure Backup with geo-redundant storage (GRS) (A) is correct because GRS replicates backup data to a secondary Azure region hundreds of miles away, enabling cross-region restore and satisfying the cross-region failover requirement while supporting the 15-minute RPO through frequent backup schedules. Azure Site Recovery (E) is correct because it continuously replicates IaaS VM disks to a target region and can orchestrate failover with RTOs typically under an hour, directly meeting the 1-hour RTO and 15-minute RPO objectives. Azure Backup with LRS (B) is incorrect because locally redundant storage keeps three copies within a single datacenter in one region, providing no cross-region protection.

Managed disk snapshots (C) are incorrect because they are stored regionally and are not a cross-region DR mechanism by themselves. Azure Backup with ZRS (D) is incorrect because zone-redundant storage only replicates across availability zones within one region, not across regions.

Exam trap

Candidates often mistakenly pair Azure Backup with ZRS thinking it provides cross-region redundancy, but ZRS is zone-redundant, not geo-redundant. Additionally, they may overlook that Azure Site Recovery is essential for orchestrated failover with low RTO, while Azure Backup alone (even with GRS) requires a restore operation that may not meet the 1-hour RTO.

81
MCQeasy

Your organization needs to provide temporary, limited-privilege access to Azure resources for external auditors. The access must be time-bound and require approval from a manager. Which Azure feature should you use?

A.Managed identities
B.Conditional Access policies
C.Azure RBAC roles
D.Microsoft Entra Privileged Identity Management (PIM)
AnswerD

Microsoft Entra Privileged Identity Management (PIM) is the correct solution because it provides just-in-time role activation with time-bound assignments and approval-based workflows. Users become eligible for a role and activate it for a limited period by providing a justification, and if required an approver must approve the request. PIM also enforces alerts, auditing, and Multi-Factor Authentication, making it the purpose-built service for temporary limited privileged access.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing time-bound activation of roles with approval workflows. This directly meets the requirement for temporary, limited-privilege access that requires manager approval, making it the correct choice for external auditor scenarios.

Exam trap

The trap here is confusing Azure RBAC roles (static assignments) with PIM's just-in-time activation, leading candidates to choose option C because they overlook the need for time-bound access and approval workflows.

How to eliminate wrong answers

Option A is wrong because Managed identities are designed for Azure resources to authenticate to services without storing credentials, not for granting temporary human access with approval. Option B is wrong because Conditional Access policies enforce access controls based on conditions like location or device state, but they do not provide time-bound role activation or an approval workflow for privileged access. Option C is wrong because Azure RBAC roles define static permissions that are assigned directly to users or groups; they lack built-in time-bound activation and approval workflows, which are required for temporary auditor access.

82
MCQmedium

You are designing a storage solution for a media company that needs to store large video files (up to 50 GB each) and serve them to a global audience with low latency. The solution must be cost-effective and support resumable uploads. Which Azure storage solution should you recommend?

A.Azure Files with Azure File Sync and Azure CDN.
B.Azure Disk Storage with Azure Load Balancer.
C.Azure Blob Storage with Azure CDN
D.Azure NetApp Files with Azure Front Door.
AnswerC

Azure Blob Storage with Azure CDN is the correct choice for a media company because Blob Storage provides at-scale object storage designed for large binary assets, with support for anonymous read access, SAS tokens, hot/cool/archive tiers, and Azure CDN integration to cache content at edge PoPs for low latency. Blob Storage is considerably more cost-effective for terabytes of media files than any file or block service, and it natively supports AzCopy's resumable uploads, which is critical for transferring very large video assets over intermittent pipelines. The CDN endpoint fronting the blob container offloads origin requests, ensures global low-latency delivery, and can be configured with session affinity, query-string caching, and custom domains, making it the canonical architecture for media distribution in Azure.

Why this answer

Azure Blob Storage is optimized for storing large unstructured data like video files, and Azure CDN ensures low-latency global delivery. Blob Storage natively supports resumable uploads via block blob APIs, making additional services like Azure Files unnecessary. This solution is cost-effective due to Blob Storage's tiered pricing and CDN edge caching.

Exam trap

The trap is that candidates may assume they need Azure Files (option A) or another service for resumable uploads, but Azure Blob Storage's block blob API natively supports resumable uploads, making it the simplest and most cost-effective choice.

How to eliminate wrong answers

Option A is wrong because Azure Files is designed for SMB file shares and shared access, not for serving large video files to a global audience; Azure File Sync adds sync overhead without improving low-latency delivery, and Azure CDN cannot cache Azure Files effectively without additional configuration. Option B is wrong because Azure Disk Storage is for VM disks (block-level storage), not for object storage or serving content globally; Azure Load Balancer distributes traffic to VMs but does not provide low-latency content delivery or resumable uploads. Option D is wrong because Azure NetApp Files is a high-performance NFS/SMB file service for enterprise workloads, not cost-effective for large-scale video serving; Azure Front Door provides global load balancing but does not natively support resumable uploads or replace Blob Storage's object storage capabilities.

83
MCQhard

A large enterprise is designing a hybrid network architecture. The company has an on-premises data center connected to Azure via ExpressRoute. They want to extend their on-premises network to Azure by using a site-to-site VPN as a backup connection. The company has multiple VNets in Azure that need to communicate with each other and with the on-premises network. The solution must be highly available and provide redundancy for the ExpressRoute connection. You need to recommend a network connectivity design. What should you include?

A.Use Azure ExpressRoute as the primary connection, and configure VNet-to-VNet VPN as a backup for ExpressRoute.
B.Use Azure VPN Gateway to connect the on-premises network to Azure, and use VNet peering for VNet-to-VNet connectivity.
C.Use Azure ExpressRoute as the primary connection, and use Azure Firewall to inspect traffic between VNets.
D.Use Azure ExpressRoute as the primary connection, and configure a site-to-site VPN as a backup. Use VNet peering for VNet-to-VNet connectivity.
AnswerD

This is the architecturally correct hybrid design: ExpressRoute serves as the primary private path with consistent low latency and high throughput, while a site-to-site VPN is provisioned as a failover connection over the public internet to maintain access during an ExpressRoute outage. The VPN is terminated on an Azure VPN Gateway, which, when configured in an active-passive or co-existing setup, can automatically redirect traffic to the encrypted tunnel. VNet peering is then used to enable direct, low-latency connectivity between VNets within Azure, which is independent of the on-premises connections.

Why this answer

It combines ExpressRoute as the primary connection with a site-to-site VPN as a backup, ensuring redundancy for on-premises connectivity. VNet peering is used for VNet-to-VNet communication, which is the recommended method for low-latency, high-bandwidth connectivity between VNets in the same region. This design meets the high availability and redundancy requirements without introducing unnecessary complexity.

Exam trap

The trap here is that candidates often confuse VNet-to-VNet VPN as a backup for ExpressRoute, when in fact a site-to-site VPN from on-premises is required to provide a redundant path for the on-premises connection.

How to eliminate wrong answers

Option A is wrong because VNet-to-VNet VPN is used for connecting VNets to each other, not as a backup for ExpressRoute to the on-premises network; it does not provide a backup path for on-premises connectivity. Option B is wrong because it uses only a VPN Gateway for on-premises connectivity, which lacks the primary high-bandwidth, low-latency ExpressRoute connection and does not meet the requirement for ExpressRoute redundancy. Option C is wrong because Azure Firewall inspects traffic but does not provide a backup connection for ExpressRoute; it addresses security, not redundancy for the WAN link.

84
MCQhard

A company has multiple Azure VNets deployed in a hub-spoke topology. They want to inspect all outbound internet traffic from spoke VMs using a central firewall and ensure that traffic from all VNets goes through the firewall before reaching the internet. They also need to log all outbound connections. Which architecture should they implement?

A.Deploy network virtual appliances (NVAs) in each spoke VNet and configure user-defined routes (UDRs) to route internet traffic to the NVAs
B.Deploy Azure Firewall in the hub VNet and configure a default route (0.0.0.0/0) in each spoke's route table pointing to Azure Firewall as the next hop
C.Use Azure Application Gateway with Web Application Firewall (WAF) in the hub VNet to inspect all traffic
D.Deploy Azure Firewall in each spoke VNet and use Azure Monitor to aggregate logs
AnswerB

In this design, Azure Firewall is deployed into a dedicated AzureFirewallSubnet in the hub, and each spoke's route table contains a 0.0.0.0/0 UDR with the firewall's private IP as the next hop. Because Azure Firewall performs destination NAT and source network address translation (SNAT), all spoke egress emerges from the hub with a single public IP while every connection is logged and inspectable. This creates a true central enforcement point for outbound traffic, supports policy consistency, and is the standard hub-spoke egress pattern.

Why this answer

Azure Firewall is a managed, stateful firewall-as-a-service that can centrally inspect and log outbound internet traffic. By deploying Azure Firewall in the hub VNet and configuring a default route (0.0.0.0/0) in each spoke's route table with the Azure Firewall private IP as the next hop, all outbound traffic from spoke VMs is forced through the firewall before reaching the internet. This satisfies both the inspection and logging requirements, as Azure Firewall provides built-in outbound connection logging via diagnostic settings.

Exam trap

The trap here is that candidates often confuse Azure Firewall with Azure Application Gateway, mistakenly thinking WAF can inspect outbound traffic, or they assume deploying NVAs per spoke is acceptable for central inspection, missing the requirement for a single central firewall in the hub.

How to eliminate wrong answers

Option A is wrong because deploying NVAs in each spoke VNet violates the central inspection requirement and introduces management overhead; it also does not ensure traffic from all VNets goes through a single central firewall. Option C is wrong because Azure Application Gateway with WAF is a Layer 7 load balancer designed for inbound HTTP/S traffic inspection, not for routing or inspecting all outbound internet traffic (including non-HTTP protocols). Option D is wrong because deploying Azure Firewall in each spoke VNet creates a decentralized model that fails the central inspection requirement, and Azure Monitor alone does not enforce routing—it only aggregates logs without controlling traffic flow.

85
MCQeasy

Your organization has a policy that all administrative access to Azure resources must be performed using just-in-time (JIT) access. Which Azure service allows you to enable JIT VM access?

A.Azure Policy
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Azure AD Privileged Identity Management
AnswerB

Microsoft Defender for Cloud is the correct answer because its Just-In-Time (JIT) VM access feature dynamically locks down inbound traffic to VMs using network security groups (NSGs) and opens configured ports only when an authorized user requests access for a predefined time window. The feature integrates with Azure AD and MFA to validate requests, and then automatically restores the NSG rules to a denied state, thereby reducing brute-force and port exhaustion attack vectors.

Why this answer

Microsoft Defender for Cloud provides just-in-time (JIT) VM access, which locks down inbound traffic to Azure VMs by creating network security group (NSG) rules that deny all inbound traffic except for specific ports. When a user requests access, Defender for Cloud temporarily creates an allow rule for the requested ports and source IP, then automatically removes it after the configured time period. This directly enforces the policy that administrative access must be JIT.

Exam trap

The trap here is that candidates often confuse Azure AD Privileged Identity Management (PIM), which handles just-in-time role activation at the Azure RBAC control plane, with Defender for Cloud's JIT VM access, which handles just-in-time network-level access to VM ports at the data plane.

How to eliminate wrong answers

Option A is wrong because Azure Policy is used to enforce organizational standards and assess compliance at scale (e.g., requiring specific VM SKUs or tagging), but it does not provide the time-bound, on-demand access control mechanism for VM ports that JIT requires. Option C is wrong because Microsoft Sentinel is a security information and event management (SIEM) and security orchestration automated response (SOAR) solution that ingests logs and alerts; it can detect threats but does not natively manage JIT VM access. Option D is wrong because Azure AD Privileged Identity Management (PIM) manages just-in-time activation of Azure AD roles and Azure resource roles (e.g., Contributor, Owner) at the control plane level, but it does not control network-level access to VM ports (data plane).

86
MCQmedium

Your company has a hybrid network with multiple on-premises sites connected to Azure via ExpressRoute. You need to design a DNS resolution strategy that allows Azure resources to resolve on-premises hostnames and on-premises clients to resolve Azure hostnames. The solution must minimize administrative overhead. What should you use?

A.Azure Bastion
B.Azure DNS public zones with conditional forwarding
C.Azure DNS Private Resolver
D.Azure Firewall DNS proxy
AnswerC

Azure DNS Private Resolver is the correct choice because it provides managed inbound and outbound DNS endpoints within an Azure virtual network, enabling bidirectional name resolution between on-premises infrastructure and Azure private DNS zones. An inbound endpoint gives on-premises DNS servers a fixed IP address for forwarding queries to Azure private zones, while an outbound endpoint with forwarding rulesets lets Azure query on-premises DNS for internal names. This service supports conditional forwarding natively and removes the need to deploy and patch custom DNS VMs, making it a truly hybrid-native resolution option.

Why this answer

Azure DNS Private Resolver enables hybrid DNS resolution by forwarding DNS queries between on-premises networks and Azure virtual networks without requiring domain-joined VMs or custom DNS servers. It supports conditional forwarding to on-premises DNS servers via ExpressRoute, allowing Azure resources to resolve on-premises hostnames and vice versa, while minimizing administrative overhead through a managed service.

Exam trap

The trap here is that candidates often confuse Azure DNS public zones with private DNS resolution, overlooking that conditional forwarding requires a DNS resolver or forwarder, not just a zone, and that Azure DNS Private Resolver is the managed service designed specifically for hybrid DNS scenarios.

How to eliminate wrong answers

Option A is wrong because Azure Bastion is a managed jump box service for secure RDP/SSH access to VMs, not a DNS resolution service. Option B is wrong because Azure DNS public zones are for internet-facing DNS resolution and do not support conditional forwarding to on-premises DNS servers; conditional forwarding is a feature of DNS servers, not public zones. Option D is wrong because Azure Firewall DNS proxy can forward DNS queries but is designed for outbound traffic filtering and inspection, not for bidirectional hybrid DNS resolution with on-premises conditional forwarding, and it adds unnecessary complexity and cost.

87
Multi-Selecthard

You are designing a governance and compliance solution for a large Azure environment with multiple subscriptions. The solution must enforce tagging policies, restrict resource types, and ensure compliance with regulatory standards. Which THREE Azure services or features should you use? (Choose three.)

Select 3 answers
A.Azure Resource Graph
B.Azure Management Groups
C.Azure Cost Management
D.Azure Blueprints (or Policy Initiatives)
E.Azure Policy
AnswersB, D, E

Azure Management Groups provide a hierarchical structure above subscriptions, allowing you to organize and govern enterprise subscription fleets at scale. Policies and role-based access control assignments placed on a management group are inherited by all descendant subscriptions and resource groups, enabling consistent compliance baselining. They are fundamental for applying governance in a multi-subscription enterprise.

Why this answer

Azure Management Groups (B) are essential for organizing subscriptions hierarchically, enabling the application of governance policies and compliance controls at scale. They allow you to enforce tagging policies, restrict resource types, and ensure regulatory compliance across multiple subscriptions by inheriting Azure Policy and RBAC assignments from the root management group down to individual subscriptions.

Exam trap

The trap here is that candidates often confuse Azure Resource Graph's discovery and query capabilities with actual enforcement, but it only provides read-only resource inventory and cannot apply or enforce governance policies.

88
MCQhard

You are designing a network architecture for a multi-tier application. The front-end tier is an Azure Application Gateway that routes traffic to a web app on Azure App Service. The back-end tier is an Azure SQL Database. You need to ensure that all traffic between the Application Gateway and the web app remains within the Azure backbone network, and that the web app can only be accessed through the Application Gateway. What should you configure?

A.Use Azure Private Link for the web app and disable public access.
B.Enable Service Endpoints for the web app and configure the Application Gateway with a private IP.
C.Deploy Azure Firewall in front of the Application Gateway.
D.Use a site-to-site VPN between the App Service and Application Gateway.
AnswerB

Service Endpoints for the web app restrict inbound traffic to the front-end subnet of the Application Gateway, so only the gateway's subnet can reach the App Service over the Azure backbone, avoiding a hop through the internet. Configuring the Application Gateway with a private IP ensures the gateway itself is not publicly reachable and acts as the sole, internal ingress point. Together they satisfy the 'only via the gateway' requirement without moving the web app off its public endpoint or requiring an Azure Private Link connection.

Why this answer

Enabling Service Endpoints for the web app allows traffic from the Application Gateway to reach the App Service over the Azure backbone network, bypassing the public internet. Configuring the Application Gateway with a private IP and restricting the web app's access to only that private IP ensures the web app can only be accessed through the gateway, meeting both requirements.

Exam trap

The trap here is that candidates often confuse Service Endpoints with Private Link, assuming Private Link is required for private connectivity, but for App Service, Service Endpoints with IP restrictions are the correct and simpler solution for this scenario.

How to eliminate wrong answers

Option A is wrong because Azure Private Link for a web app (App Service) is not directly supported; Private Link is used for PaaS services like SQL Database or Storage, not for App Service. Option C is wrong because deploying Azure Firewall in front of the Application Gateway does not ensure traffic between the gateway and web app stays on the backbone; it only adds inspection and filtering, not private connectivity. Option D is wrong because a site-to-site VPN between App Service and Application Gateway is not a supported configuration; App Service does not support VPN connections, and this would not enforce backbone-only traffic.

89
Multi-Selecthard

A multinational corporation is designing a hybrid identity solution using Microsoft Entra ID. The company has multiple on-premises Active Directory forests with complex trust relationships. They require that users can authenticate to both cloud and on-premises resources using the same credentials, and they want to minimize changes to the existing infrastructure. Which THREE components should be part of the solution? (Choose three.)

Select 3 answers
A.Microsoft Entra Connect Sync
B.Password hash synchronization
C.Microsoft Entra Connect Health
D.Active Directory Federation Services (AD FS)
E.Microsoft Entra Domain Services
AnswersA, B, D

Microsoft Entra Connect Sync is the foundational synchronization engine that replicates object metadata and credential hashes from on-premises Active Directory forests into Microsoft Entra ID, creating a unified identity for each user across both environments. It uses a rule-based sync engine to handle multiple on-premises forests, merging them into a single Entra tenant and resolving conflicts with a deterministic source anchor. Without this component, neither Password Hash Synchronization nor federation (AD FS) can function, because the user objects must first be provisioned in Entra ID. It is the core service that makes hybrid identity possible.

Why this answer

Microsoft Entra Connect Sync is correct because it synchronizes user identities from multiple on-premises Active Directory forests to Microsoft Entra ID, enabling single sign-on and unified credential usage across cloud and on-premises resources. It supports complex forest trust relationships by using the source anchor and UPN mapping to ensure each user has a unique identity in the cloud without requiring changes to the existing on-premises infrastructure.

Exam trap

The trap here is that candidates often select Microsoft Entra Domain Services (option E) thinking it provides hybrid identity synchronization, but it actually creates a standalone managed domain in Azure that does not sync credentials from on-premises AD forests and cannot handle complex trust relationships.

90
Multi-Selectmedium

Which TWO Azure networking services provide DDoS protection at the application layer (Layer 7)?

Select 2 answers
A.Azure Front Door Premium with WAF
B.Azure Firewall
C.Azure DDoS Protection Standard
D.Azure Web Application Firewall on Azure Application Gateway
E.Azure Bastion
AnswersA, D

Azure Front Door Premium includes an integrated web application firewall (WAF) that provides Layer 7 DDoS protection by inspecting HTTP/S traffic at Microsoft's global edge. Its distributed anycast architecture absorbs and mitigates application floods close to the source, preventing malicious requests from overwhelming backend origins, which is why this is a correct choice.

Why this answer

Azure Front Door Premium includes a web application firewall (WAF) that operates at Layer 7, inspecting HTTP/HTTPS traffic for application-layer attacks such as SQL injection and cross-site scripting. This integration provides both global load balancing and application-layer DDoS protection, making it a correct answer for Layer 7 DDoS defense.

Exam trap

The trap here is that candidates often confuse Azure DDoS Protection Standard (Layer 3/4) with application-layer protection, or assume Azure Firewall provides Layer 7 inspection, when in fact only WAF-enabled services like Front Door Premium and Application Gateway offer Layer 7 DDoS defense.

91
Multi-Selectmedium

Your organization needs to ensure that all Azure resources are compliant with corporate security policies. You need to design a solution that can enforce policies at scale, audit compliance, and automatically remediate non-compliant resources. Which THREE Azure services should you include?

Select 2 answers
A.Azure Policy
B.Azure Monitor
C.Azure Automation
D.Azure RBAC
E.Azure Blueprints
AnswersA, C

Azure Policy enforces corporate security standards at scale by evaluating resource properties against built-in or custom definitions, denying non-compliant deployments and auditing existing estate state. Its remediation tasks deploy correction via managed identities, satisfying the automatic remediation requirement. Policy assignments scoped to management groups apply governance consistently across all subscriptions.

Why this answer

Azure Policy (A) is the core governance service that defines, assigns, and evaluates policy definitions and initiatives at management-group, subscription, and resource-group scopes, providing the enforce and audit-at-scale capabilities required. Azure Automation (C) supplies runbooks and, via its integration with Azure Policy's deployIfNotExists and modify effects (or remediation tasks), performs the automatic remediation of non-compliant resources. Azure Blueprints is deprecated/retired and should not be used for new designs, so it is not a valid AZ-305 answer.

Azure Monitor (B) is for telemetry, metrics, and alerts rather than policy enforcement or remediation, and Azure RBAC (D) governs who can perform actions on resources through role assignments, not whether resource configurations comply with security policies.

Exam trap

AZ-305 often tests the confusion between Azure Policy (enforcement/audit) and Azure Blueprints (packaging and deployment). Note that Azure Blueprints is deprecated/retired, so it should not be selected as the answer; the enforcement, audit, and remediation capabilities are provided by Azure Policy and Azure Automation.

92
MCQhard

A company runs a critical application on Azure VMs in a single region. They need to improve availability to meet an SLA of 99.99% while minimizing costs. The application is stateless and can run on multiple VMs. Which solution should you recommend?

A.Deploy a virtual machine scale set across multiple availability zones in a single region.
B.Deploy two VMs in the same availability set in a single region.
C.Deploy a single VM with Azure Site Recovery to another region.
D.Deploy two VMs in two different Azure regions with Azure Traffic Manager.
AnswerA

A virtual machine scale set deployed across multiple availability zones distributes VM instances among distinct fault domains and update domains in separate Azure datacenters within the same region. This architecture meets the 99.99% availability SLA for virtual machines while also enabling elastic scaling and automatic rebalancing of instances, making it a cost-effective and resilient single-region solution. Because all instances reside in the same region, latency remains low and the setup avoids the expense of replicating data across geo-disparate regions.

Why this answer

A virtual machine scale set deployed across multiple availability zones in a single region provides zone-level redundancy, protecting against datacenter failures while keeping traffic within a single region for low latency. This configuration can achieve up to 99.99% availability (when using two or more zones) without the cost and complexity of multi-region replication, making it the most cost-effective solution for a stateless application.

Exam trap

The trap here is that candidates often over-engineer by choosing multi-region solutions (Option D) or under-engineer with availability sets (Option B), failing to recognize that a single-region, multi-zone scale set is the optimal balance of cost and availability for a stateless app targeting 99.99%.

How to eliminate wrong answers

Option B is wrong because an availability set protects against rack-level failures within a single datacenter, not against full datacenter or zone outages, so it cannot meet a 99.99% SLA (which requires zone or region redundancy). Option C is wrong because a single VM with Azure Site Recovery provides disaster recovery but does not offer high availability within the primary region; failover time and potential data loss prevent achieving 99.99% uptime for the application. Option D is wrong because deploying across two regions with Traffic Manager adds significant cost (cross-region data transfer, duplicate resources) and complexity, which is unnecessary for a stateless app that can achieve 99.99% with a multi-zone scale set in a single region.

93
MCQmedium

Your company is planning to migrate a large number of on-premises servers to Azure. The migration must be completed within 3 months. You need to assess the current on-premises environment and recommend the most appropriate Azure VM sizes and costs. What should you do?

A.Create a manual inventory of all servers and use Azure Pricing Calculator to estimate costs.
B.Use Azure Migrate to discover and assess the on-premises environment, and generate sizing and cost recommendations.
C.Use Azure Advisor to analyze on-premises server usage and recommend Azure VM sizes.
D.Use Azure Cost Management to estimate costs based on manual input of server specifications.
AnswerB

Azure Migrate is the correct service for migration planning because it performs agentless discovery of on-premises servers, collects performance history, and maps application dependencies. Its assessment engine can right-size Azure VM SKUs based on actual utilization rather than nominal hardware, and it generates cost recommendations that account for Azure Hybrid Benefit and Reserved Instances. This gives you a data-driven, repeatable basis for migration decisions.

Why this answer

Azure Migrate is the correct tool because it provides automated discovery and assessment of on-premises servers, including performance data, dependencies, and configuration details. It then generates right-sized Azure VM recommendations and cost estimates based on actual usage, which is essential for a large-scale migration with a tight 3-month deadline.

Exam trap

The trap here is that candidates may confuse Azure Advisor (which optimizes existing Azure resources) with Azure Migrate (which assesses on-premises environments for migration), or assume that manual inventory and pricing calculators are sufficient for large-scale migrations despite the lack of performance-based sizing.

How to eliminate wrong answers

Option A is wrong because a manual inventory of all servers is time-consuming, error-prone, and impractical for a large number of servers within a 3-month timeframe; it also lacks performance-based sizing. Option C is wrong because Azure Advisor is designed to optimize existing Azure resources, not to discover or assess on-premises environments. Option D is wrong because Azure Cost Management is a cost monitoring and analysis tool for existing Azure resources, not a discovery or assessment tool for on-premises servers.

94
MCQmedium

Your organization is deploying a critical application on Azure virtual machines. You need to ensure that the VMs are distributed across multiple fault domains and update domains within an availability set. You create an availability set with 3 fault domains and 5 update domains. How many VMs can you add to this availability set to maximize fault tolerance?

A.5 VMs
B.Unlimited
C.15 VMs
D.3 VMs
AnswerB

The correct answer is that an availability set has no prescribed maximum number of VMs; instead, you can place as many VMs as your Azure subscription and regional capacity support. Availability sets are primarily a placement construct that separates VMs across fault and update domains to maximize availability, and they do not impose a numeric ceiling on the number of instances you can add. This means your critical application can scale to hundreds of VMs within a single availability set, constrained only by Azure quota limits and not by the availability set design.

Why this answer

B is correct because Azure availability sets do not limit the number of VMs you can place into them; you can add an unlimited number of VMs. The fault domains (3) and update domains (5) define the maximum distribution groups, but Azure will place VMs across these domains as evenly as possible. Adding more VMs beyond the number of fault or update domains does not reduce fault tolerance—it simply means multiple VMs will share the same fault or update domain, but the set still provides the best possible distribution given the defined domain counts.

Exam trap

The trap here is that candidates often multiply fault domains by update domains (3 × 5 = 15) and assume that is the maximum number of VMs, but Azure does not enforce such a product limit—the domains are logical groups, not slots that can hold only one VM each.

How to eliminate wrong answers

Option A is wrong because 5 VMs is not a limit; it confuses the number of update domains (5) with a maximum VM count, but update domains only control how many groups of VMs are updated sequentially during planned maintenance, not the total number of VMs. Option C is wrong because 15 VMs (3 fault domains × 5 update domains) is a common misconception that each fault domain can hold only one VM per update domain, but Azure allows multiple VMs per fault domain and update domain, so the product of these numbers is not a cap. Option D is wrong because 3 VMs incorrectly assumes the limit equals the number of fault domains, ignoring that each fault domain can host multiple VMs and that update domains also allow multiple VMs.

95
MCQhard

Your company is designing a new cloud-native application on Azure that consists of multiple microservices running on Azure Kubernetes Service (AKS). The application must be accessible from the internet via a custom domain name (app.contoso.com) and must support SSL/TLS termination. You need to design a secure ingress solution that provides Web Application Firewall (WAF) capabilities, SSL offloading, and automatic scaling. The solution should also support path-based routing to different microservices (e.g., /api, /web). You have the following options: Option A: Deploy an Azure Application Gateway v2 with WAF in front of the AKS cluster. Configure Application Gateway Ingress Controller (AGIC) to route traffic to the services. Option B: Deploy an Azure Load Balancer with a public IP and install an NGINX ingress controller on AKS. Configure SSL termination on NGINX and use a third-party WAF. Option C: Deploy an Azure Front Door with WAF policy in front of the AKS cluster. Use Azure Private Link to connect Front Door to the internal load balancer of AKS. Option D: Deploy an Azure API Management instance with WAF and expose the microservices through API endpoints. Use Azure Application Gateway as a reverse proxy. Which option best meets the requirements for a high-performance, integrated, and managed solution with minimal operational overhead?

A.Deploy an Azure Front Door with WAF policy in front of the AKS cluster. Use Azure Private Link to connect Front Door to the internal load balancer of AKS.
B.Deploy an Azure Application Gateway v2 with WAF in front of the AKS cluster. Configure Application Gateway Ingress Controller (AGIC) to route traffic to the services.
C.Deploy an Azure Load Balancer with a public IP and install an NGINX ingress controller on AKS. Configure SSL termination on NGINX and use a third-party WAF.
D.Deploy an Azure API Management instance with WAF and expose the microservices through API endpoints. Use Azure Application Gateway as a reverse proxy.
AnswerB

Application Gateway v2 is a regional, autoscaling, Layer 7 load balancer with a managed WAF that includes OWASP rule sets, making it a strong fit for exposing AKS-based microservices. By deploying AGIC, the Kubernetes Ingress resources are automatically translated into Application Gateway routing rules, so no separate ingress controller pod is required. It provides SSL termination, path-based routing, and zone redundancy, all while being fully managed by Azure, which reduces operational burden compared to self-managed ingress.

Why this answer

Azure Application Gateway v2 with WAF provides a fully managed, integrated ingress solution that natively supports SSL/TLS offloading, path-based routing, and Web Application Firewall capabilities. By using the Application Gateway Ingress Controller (AGIC), traffic is automatically routed to the appropriate AKS microservices based on URL paths (e.g., /api, /web), and the gateway can scale automatically based on load. This minimizes operational overhead while meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse Azure Front Door's global load balancing capabilities with the need for a regional, AKS-integrated ingress controller that supports path-based routing and WAF, leading them to choose Option A despite its lack of native AKS ingress controller support.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global load balancer and application delivery controller that does not natively integrate with AKS for path-based routing to microservices; using Private Link adds complexity and latency, and Front Door lacks the direct ingress controller integration that AGIC provides. Option C is wrong because deploying an Azure Load Balancer with a public IP and a third-party WAF on NGINX introduces significant operational overhead for managing SSL certificates, WAF rules, and scaling, and does not provide a managed, integrated solution. Option D is wrong because Azure API Management is designed for API management and governance, not as a primary ingress controller; adding Application Gateway as a reverse proxy creates unnecessary complexity and does not directly support path-based routing to AKS microservices with minimal overhead.

96
MCQeasy

You are designing a high-availability solution for a stateless web application running on Azure VMs. The solution must provide automatic failover to another region in the event of a regional outage. Which Azure service should you use to distribute traffic across regions?

A.Azure Application Gateway
C.Azure Front Door
D.Azure Traffic Manager
AnswerC

Azure Front Door is a global, layer 7 service that uses anycast to route HTTP(S) traffic to the nearest healthy origin, with automatic failover if a backend region becomes unhealthy. It supports SSL termination, path-based routing, session affinity, and a built-in WAF, making it well-suited for stateless web applications that require both low-latency global access and resiliency. Front Door continuously probes health endpoints in each region and instantly shifts traffic to the next-capable origin without relying on DNS caching clients.

Why this answer

Azure Front Door is the correct choice because it is a global, scalable entry point that uses HTTP/HTTPS traffic to provide cross-region load balancing and automatic failover. It supports path-based routing, SSL offload, and health probes that can detect a regional outage and instantly reroute traffic to a healthy region, meeting the requirement for stateless web applications.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager (DNS-based, slower failover) with Azure Front Door (application-layer, faster failover), but the question's emphasis on 'automatic failover' and 'regional outage' points to Front Door's superior health probe and anycast capabilities over Traffic Manager's DNS-dependent routing.

How to eliminate wrong answers

Option A is wrong because Azure Application Gateway is a regional load balancer that operates at Layer 7 (HTTP/HTTPS) but cannot distribute traffic across multiple Azure regions; it is confined to a single region. Option B is wrong because Azure Load Balancer is a Layer 4 (TCP/UDP) load balancer that is also regional and does not support cross-region failover or global traffic distribution. Option D is wrong because Azure Traffic Manager is a DNS-based traffic router that can distribute traffic across regions, but it relies on DNS resolution and does not provide automatic failover at the application layer with health probes that react as quickly as Front Door's anycast network; it also lacks native HTTP/HTTPS features like SSL offload and path-based routing.

97
MCQhard

A company deploys a multi-tier web application on Azure VMs across availability zones. The web tier must have SSL termination, session persistence, and health probe monitoring. Additionally, all traffic must be inspected by a central firewall for compliance. The solution must be highly available. Which combination of Azure services should they implement?

A.Azure Application Gateway (WAF) in front of web VMs, with Azure Firewall in a hub VNet for central inspection
B.Azure Load Balancer (Standard) in front of web VMs, with a third-party Network Virtual Appliance (NVA) for inspection
C.Azure Front Door in front of web VMs, with Azure Firewall for inspection
D.Azure Traffic Manager + Azure Application Gateway
AnswerA

Application Gateway (WAF) is an L7 load balancer that terminates TLS, provides web application firewall rules (SQL injection, XSS), and supports cookie-based session affinity at the HTTP layer. By placing it in front of the web VMs, you get protocol-aware routing and protection. Azure Firewall in a hub VNet then serves as the centralized inspection point for all east-west and outbound traffic via UDR or forced tunneling, enabling consistent security policy enforcement without separate L4/L7 devices. This hub-spoke design is the industry-standard pattern for multi-tier web workloads.

Why this answer

Azure Application Gateway provides SSL termination, session persistence (via cookie-based affinity), and health probes at Layer 7, which are required for a web tier. Placing Azure Firewall in a hub VNet for central inspection ensures all traffic is inspected for compliance, and deploying the web VMs across availability zones meets the high-availability requirement.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming the Load Balancer can handle SSL termination and session persistence, or they overlook that Azure Front Door lacks session persistence and central inspection capabilities.

How to eliminate wrong answers

Option B is wrong because Azure Load Balancer operates at Layer 4 and cannot perform SSL termination or session persistence at the application layer; it also lacks native WAF capabilities, and using a third-party NVA introduces a single point of failure unless also deployed in a highly available manner. Option C is wrong because Azure Front Door is a global load balancer and CDN that does not support session persistence (sticky sessions) natively, and it cannot enforce central firewall inspection for all traffic as it terminates SSL at the edge, bypassing the central firewall. Option D is wrong because Azure Traffic Manager is a DNS-level load balancer that does not provide SSL termination, session persistence, or health probes at the application layer; combining it with Application Gateway adds unnecessary complexity without addressing the central firewall inspection requirement.

98
MCQmedium

A company is designing a serverless architecture for a real-time data processing pipeline. The pipeline ingests data from IoT devices, processes the data using Azure Functions, and stores the results in Azure Cosmos DB. The solution must scale automatically and minimize cold starts. Which Azure service should the company use to trigger the Azure Functions?

A.Azure Event Grid
B.Azure Queue Storage
C.Azure Event Hubs
D.Azure Service Bus
AnswerA

Event Grid is a fully managed event routing service that delivers events to subscribers via push-based HTTP calls, enabling Azure Functions to execute with near-zero latency and minimal cold starts. It can ingest device telemetry events directly from IoT Hub and route them to a function trigger without any polling layer. This push model is purpose-built for real-time serverless processing, making it the correct choice for this architecture.

Why this answer

Azure Event Grid is the correct choice because it provides a fully managed event routing service that can trigger Azure Functions in near real-time with sub-second latency, minimizing cold starts through its push-based model and support for serverless event handlers. It is ideal for IoT data ingestion scenarios where each device event needs to trigger a function independently, and it scales automatically to handle high throughput without requiring polling or batching.

Exam trap

The trap here is that candidates often confuse Azure Event Hubs (a streaming ingestion service) with Azure Event Grid (an event routing service), mistakenly choosing Event Hubs for real-time triggers when it is actually designed for high-throughput data capture and requires additional processing layers, not direct function invocation.

How to eliminate wrong answers

Option B (Azure Queue Storage) is wrong because it uses a pull-based model where the function must poll the queue for messages, introducing latency and potential cold starts due to idle polling intervals, and it is not designed for real-time event-driven triggers. Option C (Azure Event Hubs) is wrong because it is optimized for high-throughput data streaming and big data ingestion, not for triggering individual functions per event; it typically requires a separate consumer or stream processing job to process events, and it does not natively support direct function triggers without additional configuration. Option D (Azure Service Bus) is wrong because it is a message broker designed for enterprise messaging with features like sessions and transactions, but it uses a pull-based model for functions (via the Service Bus trigger) that can incur cold starts and is not optimized for the high-frequency, low-latency event pattern required by IoT device data.

99
MCQeasy

A company is deploying a web application that must scale out automatically based on CPU usage. The application runs on Azure App Service. Which Azure feature should they configure?

A.Autoscale rules
B.Azure Front Door
D.Azure Traffic Manager
AnswerA

Autoscale rules are the only option that directly modifies the compute capacity of the App Service plan. They let you configure scale conditions based on runtime metrics such as CPU percentage, request queue length, or a custom Application Insights metric, and you can set minimum and maximum instance counts. When a metric threshold is breached, the service adds or removes instances to keep the app responsive, and you can even schedule scale actions for known load patterns.

Why this answer

Autoscale rules in Azure App Service allow the application to automatically increase or decrease the number of instances based on CPU usage metrics. This is the correct feature for scaling out a web application horizontally in response to load, as it directly adjusts the instance count of the App Service Plan.

Exam trap

The trap here is that candidates often confuse load-balancing services (Front Door, Load Balancer, Traffic Manager) with autoscaling, but only Autoscale rules directly adjust the number of compute instances based on a metric like CPU usage.

How to eliminate wrong answers

Option B is wrong because Azure Front Door is a global load balancer and application delivery controller that provides SSL offloading, path-based routing, and acceleration, but it does not scale the underlying App Service instances based on CPU usage. Option C is wrong because Azure Load Balancer distributes incoming traffic at the transport layer (TCP/UDP) to virtual machines in a backend pool, but it does not provide automatic scaling based on CPU metrics for App Service. Option D is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes users to different endpoints based on geographic location or endpoint health, but it does not scale out the application instances based on CPU usage.

100
MCQmedium

Your company has a critical application running on Azure Virtual Machines that processes financial transactions. You need to ensure that the application remains available during an Azure region failure. The application is stateless and can scale horizontally. What is the most cost-effective design to meet the availability requirement?

A.Deploy VMs in an active-active configuration across two Azure regions using Traffic Manager and Azure Front Door.
B.Deploy VMs in an availability zone in the primary region and use Azure Site Recovery to replicate to a secondary region.
C.Deploy VMs in an availability set in the primary region and use Azure Site Recovery to failover to a secondary region.
D.Deploy VMs in a single region using Virtual Machine Scale Sets with automatic scaling.
AnswerB

This design places VMs in an availability zone in the primary region to guard against datacenter-level failures, while Azure Site Recovery (ASR) continuously replicates the VMs to a secondary region using asynchronous disk replication. ASR enables an orchestrated, controlled failover to the secondary region when the entire primary region becomes unavailable, and because the secondary resources are only started during failover (or remain deallocated), you avoid paying for idle compute capacity in the passive region. This active-passive approach provides both zone-level and region-level resilience, making it the optimal cost-availability balance for a critical stateless application.

Why this answer

Deploying VMs across availability zones within a region protects against datacenter-level failures, but for region-level failures, Azure Site Recovery (ASR) provides cost-effective disaster recovery by replicating VMs to a secondary region. Since the application is stateless and horizontally scalable, you can run a minimal footprint in the primary region and use ASR for orchestrated failover, avoiding the cost of always-on active-active infrastructure.

Exam trap

The trap here is that candidates often assume active-active across regions is always the best for high availability, but the question specifically asks for the most cost-effective design, and Azure Site Recovery with a single-region primary and DR replication is cheaper than maintaining dual-region active-active compute.

How to eliminate wrong answers

Option A is wrong because deploying active-active across two regions with Traffic Manager and Azure Front Door is over-engineered and costly for a stateless application that can scale horizontally; it incurs continuous egress and compute costs in both regions without necessity. Option C is wrong because an availability set only protects against rack-level failures within a single datacenter, not an Azure region failure, and ASR failover to a secondary region is still needed but the primary region design is insufficient. Option D is wrong because deploying VMs in a single region with Virtual Machine Scale Sets provides no protection against a full region outage, regardless of auto-scaling capabilities.

101
MCQmedium

A company is deploying a web application on Azure App Service. They need to guarantee that all traffic from the internet goes through a Web Application Firewall (WAF) before reaching the app. The solution must be cost-effective for a single application. Which Azure service should they place in front of the App Service?

A.Azure Application Gateway with WAF.
B.Azure Front Door with WAF policy.
C.Azure Firewall with application rules.
D.Azure Traffic Manager.
AnswerA

Application Gateway is a regional Layer 7 load balancer that integrates WAF. It can be placed directly in front of App Service to inspect all incoming traffic. This is a cost-effective solution for a single-region application.

Why this answer

Azure Application Gateway with WAF is the correct choice because it provides a regional, layer-7 load balancer with built-in Web Application Firewall capabilities, designed to protect web applications from common exploits and vulnerabilities. For a single application, it is more cost-effective than Azure Front Door, which is a global service with higher minimum costs and additional features not required here. Application Gateway can be deployed directly in front of App Service to inspect and filter all internet traffic before it reaches the app.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway, assuming Front Door is always the better choice for WAF, but the question's emphasis on cost-effectiveness for a single application points to the regional, lower-cost Application Gateway instead.

How to eliminate wrong answers

Option B is wrong because Azure Front Door is a global, multi-region load balancer and application delivery network; while it supports WAF policies, it is designed for multi-region deployments and incurs higher costs, making it less cost-effective for a single application. Option C is wrong because Azure Firewall is a network-layer firewall that filters traffic based on IP addresses, ports, and protocols, not at the application layer (HTTP/HTTPS), so it cannot provide Web Application Firewall capabilities to inspect and block web application attacks like SQL injection or cross-site scripting. Option D is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes traffic based on routing methods (e.g., performance, priority) but does not include any WAF or application-layer inspection capabilities.

102
MCQmedium

Your company is migrating a legacy on-premises application to Azure. The application requires persistent storage for configuration files that must be accessible from multiple virtual machines in a virtual network. The storage must be accessible only from within the virtual network and should not be exposed to the internet. Which Azure storage solution should you use?

A.Azure Disk Storage with shared disks
B.Azure NetApp Files with network security groups
C.Azure Blob Storage with a service endpoint
D.Azure Files with a private endpoint
AnswerD

Azure Files provides fully managed SMB file shares (also supports NFS for premium tiers) that can be mounted concurrently by multiple VMs, making it the most direct migration target for a legacy on-premises file-based application. By configuring a private endpoint, the file share is assigned a private IP address within your Azure virtual network, eliminating exposure to the public internet and ensuring traffic stays on the Microsoft backbone. Private endpoints also integrate with NSGs, private DNS zones, and Azure Active Directory authentication, giving you fine-grained access control and meeting security requirements without sacrificing the native file-protocol compatibility that legacy applications rely on.

Why this answer

Azure Files with a private endpoint is the correct choice because it provides fully managed file shares accessible via SMB or NFS protocols, supports persistent storage for configuration files, and ensures the storage is accessible only from within the virtual network by assigning a private IP address from the VNet, eliminating internet exposure. This meets the requirement for multi-VM access with network isolation.

Exam trap

The trap here is that candidates often confuse service endpoints (which still expose the storage to the internet at the endpoint level) with private endpoints (which fully isolate the resource within the VNet), and they may overlook that Azure Files supports SMB for shared file access while Blob Storage does not.

How to eliminate wrong answers

Option A is wrong because Azure Disk Storage with shared disks is a block-level storage solution designed for clustered applications (e.g., SQL Server FCI) and does not natively support file-level access or SMB/NFS protocols required for configuration files; it also cannot be easily accessed from multiple VMs without complex clustering. Option B is wrong because Azure NetApp Files is a high-performance file service that can use network security groups, but it is overkill for simple configuration files and incurs higher cost and complexity; more critically, NSGs alone do not guarantee complete internet isolation—a private endpoint is the proper method for VNet-only access. Option C is wrong because Azure Blob Storage with a service endpoint still exposes the storage account to the public internet (though restricted to the VNet), and Blob Storage is object storage not designed for file-sharing protocols like SMB, making it unsuitable for configuration files that need to be mounted as a drive.

103
MCQeasy

A company is using Azure SQL Database for a critical application. They need to ensure that the database is automatically backed up and that backups are retained for 35 days. What should they configure?

A.Enable long-term retention (LTR) for backups
B.Configure the point-in-time restore (PITR) retention to 35 days
C.Configure active geo-replication
D.Use Azure Backup to back up the SQL Database
AnswerB

Azure SQL Database automatically takes full, differential, and transaction log backups, and PITR retention is configurable up to 35 days for most service tiers. This enables restoring to any point in time within that window, directly meeting the requirement. By configuring the PITR retention to 35 days, the organization ensures that automated backups are retained long enough to recover to any second within the past 35 days, which is the standard mechanism for backup retention in Azure SQL Database.

Why this answer

Azure SQL Database has a default point-in-time restore (PITR) retention period of 7 days, which can be configured up to 35 days. By setting the PITR retention to 35 days, the company ensures that automated backups are retained for the required duration, allowing restoration to any point within that window. This meets the requirement without additional services or configurations.

Exam trap

The trap here is that candidates may confuse long-term retention (LTR) with the standard automated backup retention, thinking LTR is required for any retention beyond the default 7 days, when in fact PITR can be extended to 35 days without enabling LTR.

How to eliminate wrong answers

Option A is wrong because long-term retention (LTR) is used for retaining backups beyond 35 days (up to 10 years), not for meeting a 35-day retention requirement. Option C is wrong because active geo-replication provides disaster recovery by maintaining a readable secondary database in a different region, but it does not control backup retention periods. Option D is wrong because Azure Backup is not used for Azure SQL Database; automated backups are built-in and managed by the platform, and Azure Backup is intended for on-premises SQL Server or Azure VMs running SQL Server.

104
MCQeasy

Your company has a web application deployed on Azure App Service that experiences periodic traffic spikes. You need to ensure the application scales out quickly without manual intervention. The solution must minimize cost during low-traffic periods. What should you configure?

A.Enable pre-warming in the App Service plan
B.Configure Autoscale rules based on CPU or memory metrics
C.Deploy the app to a Virtual Machine Scale Set
D.Manually increase the instance count before expected spikes
AnswerB

Configuring autoscale rules is the proper PaaS-native mechanism for Azure App Service to automatically adjust the instance count of your App Service plan. You define scale conditions based on metrics such as CPU percentage, memory consumption, or request queue length, and Autoscale adds or removes instances in response to those thresholds. This is a fully automated, reactive approach that continuously monitors load and eliminates the need for manual intervention.

Why this answer

Autoscale rules based on CPU or memory metrics allow the App Service to automatically increase or decrease the number of instances in response to traffic spikes, meeting the requirement for quick scaling without manual intervention. By scaling down during low-traffic periods, it minimizes cost, as you only pay for the instances you use. This is the native Azure App Service scaling feature that directly addresses the need for elastic, cost-effective scaling.

Exam trap

The trap here is that candidates often confuse pre-warming (Option A) with autoscaling, thinking it handles scaling automatically, but pre-warming only prepares instances for a planned scale event and does not react to real-time metrics.

How to eliminate wrong answers

Option A is wrong because pre-warming is a feature for reducing cold-start latency on new instances, not for triggering scale-out events; it does not automate scaling based on load. Option C is wrong because Virtual Machine Scale Sets are designed for IaaS workloads, not for PaaS web apps on App Service, and would require additional management overhead and cost for the same functionality. Option D is wrong because manually increasing the instance count violates the requirement for 'quickly without manual intervention' and cannot react to unexpected spikes in real time.

105
MCQhard

Your company, Contoso Ltd., operates a global e-commerce platform hosted on Azure. The architecture consists of: (1) A web front-end running on Azure App Service in multiple regions (East US, West Europe, Southeast Asia). (2) A microservices backend running on Azure Kubernetes Service (AKS) in East US. (3) A SQL Database in East US with geo-replication to West Europe and Southeast Asia for read scaling. (4) Azure Redis Cache for session state. (5) Azure Front Door for global load balancing. The platform experiences periodic traffic spikes, and during a recent spike, users reported slow page loads and intermittent errors. The operations team observed that the SQL Database in East US reached 100% DTU consumption, causing timeouts. The geo-replicated databases in other regions were underutilized. The application logic is read-heavy but also writes to a separate write-only table. You need to design a solution to improve scalability and reduce database load. The solution must: minimize latency for users, ensure write consistency, and handle traffic spikes without over-provisioning. What should you do?

A.Upgrade the SQL Database in East US to a higher DTU tier and enable auto-scaling.
B.Configure read-only routing in the application connection string to use the geo-replicated databases for read queries, and keep writes directed to the primary.
C.Implement a second-level cache using Azure Cache for Redis with a local cache pattern in the web front-end.
D.Shard the database by customer region and deploy shards in each region.
AnswerB

For an Azure SQL Database with active geo-replication, you can set the application connection string to include ApplicationIntent=ReadOnly; the gateway then automatically routes incoming read-only queries to the nearest readable secondary, while the login remains pointed at the primary for any write transactions. This offloads the bulk of the SELECT traffic from the primary DTU pool, effectively increasing total system throughput without changing the database tier and saving the primary for writes. Because the geo-replicas already exist, the only change is a connection string property, making this the lowest-complexity, highest-leverage fix for a global read-heavy workload and the reason it is the correct answer.

Why this answer

It leverages the existing geo-replicated SQL Databases for read scaling without additional cost. By configuring read-only routing in the application connection string, read queries are automatically directed to the readable secondary replicas in West Europe and Southeast Asia, offloading the primary East US database. This reduces DTU consumption on the primary while maintaining write consistency, as all writes still go to the primary.

Azure SQL Database's active geo-replication supports this pattern, and Azure Front Door can route users to the nearest region for low latency.

Exam trap

The trap here is that candidates often choose Option A (upgrade DTU) because it seems like a direct fix for high DTU consumption, but they overlook the underutilized geo-replicated databases and the requirement to minimize latency globally without over-provisioning.

How to eliminate wrong answers

Option A is wrong because upgrading to a higher DTU tier and enabling auto-scaling only addresses the symptom (high DTU consumption) but does not utilize the underutilized geo-replicated databases, leading to over-provisioning and higher costs without improving global read latency. Option C is wrong because implementing a second-level cache with Azure Cache for Redis and a local cache pattern reduces database load for cached data but does not address the write-only table or the need to offload read traffic from the primary database; it also introduces cache invalidation complexity for write-heavy scenarios. Option D is wrong because sharding by customer region requires significant application redesign, complicates cross-region queries, and does not leverage the existing geo-replication; it also risks write consistency issues if shards are not properly synchronized.

106
MCQmedium

A company deploys a containerized application on Azure Kubernetes Service (AKS). They need to expose the application to the internet and provide TLS termination. The solution must also include a Web Application Firewall (WAF) to protect against common attacks. Which Azure service should they use as the ingress controller?

A.Azure Application Gateway
B.Azure Front Door
D.Azure Traffic Manager
AnswerA

Azure Application Gateway, when integrated as the Application Gateway Ingress Controller (AGIC), is the native Azure L7 load balancer that serves as an ingress gateway for AKS clusters. It terminates TLS connections at the gateway, decrypts HTTP traffic, and enforces Web Application Firewall policies (such as OWASP CRS rules) before forwarding requests to AKS pods. This makes it the correct solution for the requirement of TLS termination and WAF in an AKS environment.

Why this answer

Azure Application Gateway is the correct choice because it is a layer-7 load balancer that can act as an ingress controller for AKS, providing TLS termination and a built-in Web Application Firewall (WAF) to protect against common attacks like SQL injection and cross-site scripting. It integrates directly with AKS via the Application Gateway Ingress Controller (AGIC) add-on, allowing it to route external HTTP/HTTPS traffic to containerized applications while offloading SSL/TLS processing and enforcing WAF policies at the edge.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway because both provide WAF and TLS termination, but Front Door is a global service for multi-region traffic distribution, not a direct AKS ingress controller that can route to pods within a single cluster.

How to eliminate wrong answers

Option B (Azure Front Door) is wrong because it is a global, multi-region load balancer and application delivery network that operates at layer 7, but it is not designed as an AKS ingress controller; it sits in front of the cluster and cannot directly route traffic to AKS pods without an additional ingress controller like Application Gateway or NGINX. Option C (Azure Load Balancer) is wrong because it operates at layer 4 (TCP/UDP) and cannot perform TLS termination or WAF inspection; it only distributes traffic at the network level without understanding HTTP/HTTPS protocols. Option D (Azure Traffic Manager) is wrong because it is a DNS-based traffic router that operates at layer 3/4 and does not provide TLS termination or WAF capabilities; it only directs traffic based on DNS resolution and health probes, not application-layer routing.

107
MCQmedium

Your organization has a hybrid identity infrastructure with Microsoft Entra ID Connect Sync. You plan to enable Microsoft Entra ID Seamless Single Sign-On (Seamless SSO) for domain-joined Windows devices. What is the minimum requirement for the on-premises Active Directory forest functional level?

A.Windows Server 2016
B.Windows Server 2012
C.Windows Server 2008
D.Windows Server 2003
AnswerC

Windows Server 2008 is the exact minimum forest functional level required to enable Azure AD Seamless SSO. Microsoft's prerequisite documentation specifies that an on-premises forest must be at this level or higher, because the feature relies on Kerberos-based authentication and the creation of an AzureADKerberos computer account that is only supported on 2008 FFL and above. Thus, it is the only correct answer when identifying the minimum.

Why this answer

Microsoft Entra ID Seamless SSO works by having the client computer attempt Kerberos authentication against a local Active Directory domain controller using a special service principal name (AZUREADSSOACC). This process requires the on-premises Active Directory forest functional level to be at least Windows Server 2008, because the Kerberos service ticket used for Seamless SSO relies on the AES encryption type, which is only supported in domains with a Windows Server 2008 or higher functional level. Lower functional levels (2003 or earlier) do not support AES encryption, causing the authentication to fail.

Exam trap

The trap here is that candidates often assume the minimum requirement is based on the operating system version of the domain controllers (e.g., Windows Server 2012 or 2016) rather than the forest/domain functional level, which is a separate configuration that controls available Kerberos encryption types and features.

How to eliminate wrong answers

Option A is wrong because Windows Server 2016 is not the minimum requirement; the feature works with any functional level from Windows Server 2008 onward, so requiring 2016 would be unnecessarily restrictive. Option B is wrong because Windows Server 2012 is also above the minimum; while it supports Seamless SSO, it is not the lowest possible functional level. Option D is wrong because Windows Server 2003 functional level does not support AES encryption for Kerberos, which is required for the Seamless SSO authentication flow, and thus cannot be used.

108
Multi-Selecthard

Which THREE of the following are valid methods to secure access to Azure Storage accounts? (Choose three.)

Select 3 answers
A.Generate Shared Access Signatures (SAS) with limited permissions and expiry
B.Configure firewall rules and virtual network service endpoints
C.Enable Azure Front Door to authenticate requests
D.Use Azure AD RBAC to assign roles to users and applications
E.Use storage account access keys for authentication
AnswersA, B, D

SAS tokens provide scoped, time-bound delegated access to specific Azure Storage resources, such as a single blob, container, or queue, with granular permissions (read, write, delete, list) and an explicit expiry. A service SAS or user delegation SAS can be issued to clients without exposing the account key, and a stored access policy allows revocation by changing the policy. However, a poorly configured SAS with broad permissions or no expiry reduces its security value.

Why this answer

Shared Access Signatures (SAS) allow you to grant time-limited, delegated access to specific storage resources (e.g., blobs, queues) with granular permissions (read, write, delete) and an expiry time, without exposing the account key. This is a key security method for controlling access at the resource level.

Exam trap

The trap here is that candidates often confuse Azure Front Door (a traffic routing and CDN service) with an authentication gateway, or mistakenly think storage account access keys are a secure method for user access, when in fact they are equivalent to a root password and should be rotated and protected.

109
Multi-Selectmedium

A company is designing a backup and disaster recovery solution for an on-premises SQL Server database that will be migrated to Azure. The solution must meet the following requirements: 1) Point-in-time restore up to 30 days. 2) Cross-region restore in case of a regional disaster. 3) Long-term retention of backups for 7 years for compliance. Which THREE Azure services or features should the company use? (Choose three.)

Select 3 answers
A.Azure Backup Server
B.Azure Site Recovery
C.Azure Blob Storage
D.Azure Backup
E.Azure Recovery Services vault
AnswersB, D, E

Azure Site Recovery (ASR) is the Azure-native disaster recovery service that replicates Azure VMs from a primary region to a secondary region using continuous, asynchronous disk replication. It delivers a measurable RPO and RTO by enabling you to failover to replicated copies of the VMs, with options for planned, unplanned, and test failovers, all orchestrated through recovery plans. Because the company needs a disaster recovery solution, ASR is the exact service that meets that need, working alongside Azure Backup for point-in-time restore.

Why this answer

Azure Site Recovery (B) is correct because it provides cross-region replication and orchestrated failover for SQL Server, enabling disaster recovery with the ability to restore in a secondary Azure region. This directly meets the requirement for cross-region restore in case of a regional disaster.

Exam trap

The trap here is that candidates often confuse Azure Backup Server (a legacy on-premises tool) with Azure Backup (a cloud-native service), or assume Azure Blob Storage alone can fulfill backup and DR requirements without the orchestration and retention capabilities of Azure Backup and Site Recovery.

110
MCQeasy

A company is migrating on-premises applications to Azure. They require that all traffic between Azure resources and on-premises resources traverse a private connection. They also want to reduce the attack surface by eliminating exposure of management endpoints over the internet. Which solution should they implement?

A.Azure Firewall
B.Azure Front Door
C.Azure ExpressRoute with Private Link for Azure services
D.Azure VPN Gateway
AnswerC

Azure ExpressRoute creates a dedicated private circuit from your on-premises network into Azure through an MPLS or other network provider, completely bypassing the public internet to reduce latency and improve security. Pairing it with Azure Private Link extends your virtual network's private IP space to Azure PaaS services via private endpoints, so traffic between your datacenter and those services never traverses a public endpoint. This combination offers both a private transit network and private access to individual services, meeting strict compliance and isolation requirements.

Why this answer

Azure ExpressRoute provides a private, dedicated connection from on-premises to Azure, bypassing the public internet. By combining ExpressRoute with Private Link for Azure services, you ensure that traffic to Azure PaaS services (e.g., Azure SQL, Storage) traverses only the private connection and that the service endpoints are not exposed over the internet, reducing the attack surface. This directly meets the requirement for private connectivity and elimination of public management endpoints.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway with ExpressRoute, thinking that an encrypted tunnel provides equivalent privacy and security, but VPN Gateway still uses the public internet for transit, whereas ExpressRoute is a dedicated private connection that completely bypasses the internet.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a managed network security service that filters traffic, but it does not provide a private connection between on-premises and Azure; traffic still flows over the internet or through a VPN/ExpressRoute, and it does not eliminate exposure of management endpoints. Option B is wrong because Azure Front Door is a global load balancer and application delivery controller that operates over the public internet; it does not provide a private connection and does not remove internet exposure of endpoints. Option D is wrong because Azure VPN Gateway creates an encrypted tunnel over the public internet, which still exposes traffic to internet transit and does not provide the dedicated private connection required; it also does not eliminate exposure of management endpoints.

111
MCQhard

A company is designing a hub-spoke network topology across multiple Azure regions. They plan to deploy a third-party network virtual appliance (NVA) in the hub for traffic inspection. They require that all traffic between spokes in different regions must be routed through the hub NVA, and they want to minimize the number of peered connections. Which solution should they implement?

A.VNet peering with user-defined routes (UDRs) in each spoke pointing to the NVA IP in the hub
B.Azure Virtual WAN with a secured hub using Azure Firewall
C.Azure VNet-to-VNet VPN gateways between all spokes
D.Azure ExpressRoute with private peering
AnswerA

VNet peering with UDRs is the correct approach because Azure VNet peering is non-transitive, so spokes cannot reach each other through the hub unless traffic is explicitly directed to the NVA. You associate a route table with each spoke subnet, adding a UDR with next hop type 'Virtual Appliance' and the NVA's private IP, and you must enable IP forwarding on the NVA's NIC. This enforces all inter-spoke traffic through the NVA while maintaining only one peering connection per spoke, which is the minimal, cost-effective hub-and-spoke design for a third-party firewall or router.

Why this answer

VNet peering combined with user-defined routes (UDRs) allows traffic between spokes in different regions to be forced through the NVA in the hub for inspection. By configuring UDRs in each spoke with the next hop set to the NVA's private IP, you ensure inter-spoke traffic traverses the hub without requiring a full mesh of peering connections. This minimizes the number of peered connections (only hub-to-spoke peering is needed) while meeting the routing requirement.

Exam trap

The trap here is that candidates often assume Virtual WAN (Option B) is the only way to simplify hub-spoke routing, but it does not support custom third-party NVAs for traffic inspection without complex workarounds, making VNet peering with UDRs the correct choice for this specific requirement.

How to eliminate wrong answers

Option B is wrong because Azure Virtual WAN with a secured hub using Azure Firewall introduces a managed service that may not support a third-party NVA for traffic inspection; it is designed for Azure Firewall or third-party security providers via integrated partners, not a custom NVA. Option C is wrong because Azure VNet-to-VNet VPN gateways between all spokes would create a full mesh of VPN connections, increasing complexity and cost, and it does not force traffic through the hub NVA unless additional routing is configured, which still requires more connections than hub-spoke peering. Option D is wrong because Azure ExpressRoute with private peering provides a dedicated private connection to on-premises networks, not routing between spokes in different regions; it does not address inter-spoke traffic inspection or minimize peered connections.

112
MCQmedium

Your organization plans to migrate a legacy on-premises application that uses a proprietary authentication mechanism to Azure. The application must run as a virtual machine and must not require any code changes. You need to design an identity solution that integrates with the application without modifying it. What should you use?

A.Azure VPN Gateway
B.Microsoft Entra Application Proxy with Kerberos Constrained Delegation
C.Microsoft Entra Domain Services
D.Azure Bastion
AnswerB

Microsoft Entra Application Proxy with Kerberos Constrained Delegation is the correct approach because it publishes the legacy on-premises web app as an enterprise application in Entra ID, allowing pre-authentication via Entra ID (including MFA and conditional access). The Application Proxy connector, running on-premises, then uses KCD to obtain a Kerberos ticket for the user and forwards it to the backend app, enabling Windows-integrated authentication without any code changes. This gives a seamless SSO experience while protecting the app from direct exposure.

Why this answer

Microsoft Entra Application Proxy with Kerberos Constrained Delegation (KCD) allows you to publish on-premises applications that use Kerberos authentication without modifying the application code. The Application Proxy pre-authenticates users via Entra ID, then uses KCD to obtain a Kerberos ticket on behalf of the user and pass it to the legacy application running on a VM. This meets the requirement of no code changes while integrating the proprietary authentication mechanism with Azure identity.

Exam trap

The trap here is that candidates often confuse network-level solutions (VPN, Bastion) or domain services (Entra DS) with identity proxy solutions, failing to recognize that Application Proxy with KCD is the only option that provides seamless authentication integration without code changes.

How to eliminate wrong answers

Option A is wrong because Azure VPN Gateway provides network-level connectivity between on-premises and Azure, not an identity integration solution for application authentication. Option C is wrong because Microsoft Entra Domain Services provides managed domain services (LDAP, Kerberos, NTLM) but does not itself proxy or translate authentication for a legacy application that uses a proprietary mechanism; it would require the application to be domain-joined and use Kerberos directly, which may still need code changes. Option D is wrong because Azure Bastion is a secure RDP/SSH gateway for VM management, not an identity or application authentication solution.

113
MCQeasy

You are designing a web application that will be hosted on Azure App Service. The application must authenticate users from your company's Microsoft Entra ID tenant. You need to implement authentication without writing any authentication code. What should you use?

A.Azure API Management with OAuth 2.0 policy
B.Microsoft Authentication Library (MSAL) integrated into the application code
C.App Service Authentication (EasyAuth)
D.Azure Front Door with authentication rules
AnswerC

App Service Authentication, also known as EasyAuth, runs natively in the App Service platform overlay and automatically handles the full OAuth 2.0 and OpenID Connect flow against Microsoft Entra ID. When a request arrives, EasyAuth validates the identity, establishes an encrypted session cookie, and injects security claims into HTTP headers such as X-MS-CLIENT-PRINCIPAL and X-MS-TOKEN-AAD-ID-TOKEN for the app to read. Since this all occurs at the platform level, the application requires zero authentication code; the developer simply enables the feature and configures the identity provider in the Azure portal. For multitenant apps, it also manages tenant restrictions without changes to the app.

Why this answer

App Service Authentication (also known as EasyAuth) is the correct choice because it provides built-in authentication for Azure App Service without requiring any custom code. It integrates directly with Microsoft Entra ID (formerly Azure AD) and automatically handles token validation, session management, and redirects by intercepting HTTP requests before they reach your application code.

Exam trap

The trap here is that candidates often confuse Azure API Management's OAuth 2.0 policy with end-user authentication, but API Management secures APIs at the gateway level and does not provide the login UI or session management needed for a web application without custom code.

How to eliminate wrong answers

Option A is wrong because Azure API Management with OAuth 2.0 policy is designed to secure APIs and validate tokens at the gateway layer, not to authenticate end users of a web application without writing authentication code. Option B is wrong because the Microsoft Authentication Library (MSAL) requires explicit integration into the application code to handle login flows, token acquisition, and caching, which contradicts the requirement of 'without writing any authentication code.' Option D is wrong because Azure Front Door with authentication rules can enforce access policies at the edge but does not provide built-in authentication flows (like login pages or token exchange) for a web application; it relies on backend services or custom rules for actual authentication.

114
MCQmedium

An on-premises datacenter must connect privately to Azure with predictable bandwidth and avoid traversal of the public internet. Which connectivity option should be recommended?

A.Azure Bastion
B.Point-to-site VPN
C.Site-to-site VPN only
D.ExpressRoute
AnswerD

ExpressRoute provides a private, dedicated Layer 3 connection between your on-premises datacenter and Azure through a connectivity provider, using redundant Microsoft Enterprise Edge routers and BGP peering. Traffic never traverses the public internet, enabling consistent latency, higher bandwidth, and an availability SLA. With private peering, virtual networks can be reached directly over this backbone, making it the correct service for private datacenter-to-Azure connectivity.

Why this answer

ExpressRoute provides a dedicated private connection from on-premises to Azure, bypassing the public internet entirely. It offers predictable bandwidth, low latency, and high reliability through a Layer 3 MPLS or direct fiber link from a connectivity provider. This meets the requirement for a private, consistent network path without internet traversal.

Exam trap

The trap here is that candidates may confuse Site-to-site VPN (which also provides a private IP tunnel) as meeting the 'private' requirement, but it still traverses the public internet and cannot guarantee predictable bandwidth like ExpressRoute.

How to eliminate wrong answers

Option A is wrong because Azure Bastion is a managed PaaS service for secure RDP/SSH access to Azure VMs over TLS, not a connectivity option for on-premises datacenters. Option B is wrong because Point-to-site VPN uses SSTP or IKEv2 over the public internet, which cannot guarantee predictable bandwidth and does traverse the internet. Option C is wrong because Site-to-site VPN only uses IPsec tunnels over the public internet, which introduces variable latency and bandwidth due to internet routing, failing the requirement for predictable bandwidth and no public internet traversal.

115
Multi-Selectmedium

A hub-and-spoke Azure network must centralize outbound inspection and still allow spokes to resolve private endpoint DNS names. Which two components are commonly required? (Choose 2.)

Select 2 answers
A.User-defined routes from spoke subnets to the firewall or NVA.
B.Private DNS zones linked to the VNets or resolved through a central DNS design.
C.A public IP address on every private endpoint.
D.Basic SKU load balancers in each spoke.
AnswersA, B

User-defined routes (UDRs) are essential in a hub-and-spoke topology because they force all outbound traffic from spoke subnets to traverse the central firewall or NVA by specifying the inspection appliance as the next hop. Without a UDR, spoke traffic follows Azure's default system routes and reaches the internet directly, bypassing the hub's security controls. Associating a route table with each spoke subnet—and setting the next hop type to Virtual Appliance—is the mechanism that makes centralized outbound inspection and egress traffic deterministic.

Why this answer

User-defined routes (UDRs) on spoke subnets force all outbound traffic (including internet-bound traffic) to the central firewall or network virtual appliance (NVA) in the hub, enabling centralized inspection. Without UDRs, spoke VMs would bypass the firewall and use default outbound internet access, breaking the inspection requirement.

Exam trap

The trap here is that candidates often assume private endpoints require public IPs for DNS resolution, but Azure Private DNS zones resolve FQDNs to private IPs, and UDRs handle traffic routing without needing public exposure.

116
MCQmedium

Refer to the exhibit. You are reviewing an ARM template that deploys a virtual network with two subnets. Subnet-b includes a delegation to Microsoft.Web/serverFarms. What is the purpose of this delegation?

A.It allows subnet-b to use a different address space
B.It configures a firewall policy for subnet-b
C.It creates a peering connection to another virtual network
D.It enables Azure App Service instances to be deployed into subnet-b
AnswerD

With 'serviceName': 'Microsoft.Web/serverFarms', the delegation tells Azure that the subnet is reserved for App Service infrastructure, enabling an App Service plan or App Service Environment to deploy worker instances directly into subnet-b. The service then creates and manages the required network interfaces and permissions within that delegated subnet. This is the intended meaning of the delegation in the ARM template and the only option consistent with how subnet delegation works.

Why this answer

Delegating a subnet to Microsoft.Web/serverFarms explicitly authorizes Azure App Service (specifically, the App Service Plan's infrastructure) to inject network interfaces into that subnet. This is required for features like regional VNet Integration, where an App Service instance needs direct access to resources in the virtual network without going through a public endpoint. Without this delegation, the App Service cannot use the subnet for its internal networking.

Exam trap

The trap here is that candidates confuse subnet delegation with general VNet integration or peering, but delegation is specifically a resource provider permission model that allows a PaaS service (like App Service) to own and manage the subnet's network interfaces.

How to eliminate wrong answers

Option A is wrong because a subnet's address space is defined by its address prefix in the virtual network configuration, not by a delegation; delegation does not change IP addressing. Option B is wrong because firewall policies (e.g., Azure Firewall or NSG rules) are applied separately via network security groups or Azure Firewall policies, not through a subnet delegation. Option C is wrong because VNet peering is configured at the virtual network level using peering connections, not by delegating a subnet to a resource provider.

117
MCQhard

You execute the above PowerShell script to create a Windows VM in Azure. After the script completes, you try to RDP to the public IP address but the connection fails. What is the most likely reason?

A.The network interface is not attached to the VM.
B.The public IP address is not assigned correctly.
C.The NSG rule blocks RDP traffic.
D.The VM size does not support RDP.
AnswerA

A virtual machine fundamentally requires an attached network interface to establish any network connectivity, including responding to inbound RDP requests. If the PowerShell script successfully created both the VM and the network interface but omitted the crucial step to attach the interface to the VM, the VM would lack the necessary component to communicate. Consequently, RDP connections to the public IP address would fail because the VM cannot receive or process the connection attempt.

Why this answer

The PowerShell script creates a VM but does not explicitly associate the network interface (NIC) with the VM. In Azure, a NIC must be attached to a VM for network connectivity; without this association, the VM has no network path, and RDP (TCP/3389) cannot reach the VM even if a public IP and NSG rules are correctly configured.

Exam trap

The trap here is that candidates assume the script's `New-AzVM` command automatically attaches the NIC created earlier, but Azure requires an explicit NIC attachment parameter, and the script omits it, leaving the NIC orphaned.

How to eliminate wrong answers

Option B is wrong because the public IP address is assigned correctly in the script (via `New-AzPublicIpAddress` and `New-AzNetworkInterface`), so the IP exists and is associated with the NIC; the failure is due to the NIC not being attached to the VM. Option C is wrong because the script does not create any NSG, meaning no NSG is blocking RDP by default (Azure allows all inbound traffic when no NSG is applied to the subnet or NIC). Option D is wrong because all Azure VM sizes support RDP; RDP is a protocol-level feature independent of VM size, and size only affects performance, not connectivity.

118
MCQeasy

Your organization has a large number of virtual machines running in Azure. You need to centrally manage backup policies, monitor backup jobs, and ensure compliance with retention requirements. Which Azure service should you use?

A.Azure Policy
B.Azure Site Recovery
C.Azure Backup Center
D.Azure Monitor
AnswerC

Azure Backup Center provides a single pane of glass for managing backup estates, including monitoring backup jobs, configuring policies, and analyzing alerts across Azure Backup and Azure Site Recovery (for VM replication). It centralizes inventory, compliance, and governance of backups, making it ideal for managing a large number of VMs' backup jobs. This directly matches the requirement to manage and monitor backup jobs at scale.

Why this answer

Azure Backup Center provides a single, unified management experience for backup estates, enabling centralized policy management, monitoring of backup jobs and alerts, and compliance reporting across multiple vaults and subscriptions. It is specifically designed to address the need for a central console to govern backup operations at scale, unlike other services that focus on policy enforcement, disaster recovery, or general monitoring.

Exam trap

The trap here is that candidates often confuse Azure Backup Center with Azure Monitor or Azure Policy, mistakenly thinking that a general monitoring or policy enforcement tool can provide the same centralized backup management and compliance tracking that Backup Center is purpose-built for.

How to eliminate wrong answers

Option A is wrong because Azure Policy enforces organizational standards and compliance rules on Azure resources (e.g., requiring backups to be enabled), but it does not provide a centralized interface to manage backup policies, monitor backup jobs, or track retention compliance. Option B is wrong because Azure Site Recovery is a disaster recovery service that orchestrates replication and failover of workloads to a secondary region, not a tool for managing backup policies or monitoring backup jobs. Option D is wrong because Azure Monitor collects and analyzes telemetry from Azure resources, including backup-related metrics and logs, but it lacks the dedicated backup-specific views, policy management, and compliance dashboards that Azure Backup Center offers.

119
Multi-Selectmedium

Your organization is migrating a legacy application to Azure that requires Windows authentication and a fixed IP address. The application will run on an Azure VM. You need to design a networking solution that ensures the VM retains its IP address even after a reboot and that the application can be reached by on-premises users using its hostname. Which TWO actions should you take? (Choose two.)

Select 2 answers
A.Assign a static private IP address to the VM's NIC
B.Assign a static public IP address to the VM
C.Configure Azure Firewall to forward DNS requests
D.Create an Azure DNS private zone and add an A record for the VM
E.Connect to the VM using Azure Bastion for name resolution
AnswersA, D

In Azure, a VM's private IP can be dynamic by default, meaning it may change when the VM is deallocated/restarted, breaking configuration that references the IP. Assigning a static private IP to the NIC guarantees a consistent address within the virtual network, which is critical for on-premises applications that connect via VPN/ExpressRoute and rely on a fixed endpoint. Additionally, static private IPs are managed at the NIC level and remain assigned until explicitly removed, supporting reliable name-to-IP mapping and firewall rules.

Why this answer

A is correct because assigning a static private IP address to the VM's NIC ensures the IP address persists across reboots, which is required for Windows authentication and legacy application dependencies that rely on a fixed IP. This is done by setting the private IP allocation method to 'Static' in the NIC's IP configuration, preventing DHCP from assigning a new address after a restart.

Exam trap

The trap here is that candidates often confuse a static public IP with a static private IP, assuming external reachability requires a public IP, when in fact the question specifies on-premises users (likely over a VPN or ExpressRoute) and hostname resolution via a private DNS zone.

120
MCQhard

Refer to the exhibit. You are reviewing the properties of an Azure Storage account. The encryption section shows keySource as Microsoft.Keyvault and infrastructureEncryption enabled. What does infrastructureEncryption mean in this context?

A.It enforces HTTPS for all data in transit
B.It automatically rotates the encryption key daily
C.It encrypts the encryption key stored in Key Vault
D.It enables double encryption of data at rest
AnswerD

When infrastructure encryption is enabled on an Azure Storage account, data is encrypted at rest twice: first by the standard Azure Storage service-side encryption, then by a second layer using platform-managed keys at the storage infrastructure level. This double-encryption model means a compromise of one key layer still leaves the data protected by the other. It is specifically an at-rest capability; it does not apply to network traffic, and it cannot be turned off after the account is created.

Why this answer

Infrastructure encryption in Azure Storage provides double encryption of data at rest. When enabled, data is encrypted twice: once at the service level using a Microsoft-managed key or a customer-managed key from Azure Key Vault (as indicated by keySource: Microsoft.Keyvault), and a second layer at the infrastructure level using a separate platform-managed key. This ensures that even if one encryption layer is compromised, the second layer protects the data, meeting compliance requirements for highly sensitive workloads.

Exam trap

The trap here is that candidates confuse infrastructure encryption with enforcing HTTPS (data in transit) or with key rotation, but the question specifically tests the understanding that 'infrastructureEncryption' means double encryption of data at rest, not a transport or key management feature.

How to eliminate wrong answers

Option A is wrong because enforcing HTTPS for data in transit is controlled by the 'Secure transfer required' setting in the storage account's firewall and virtual networks blade, not by infrastructure encryption, which applies only to data at rest. Option B is wrong because automatic daily key rotation is a feature of customer-managed keys in Azure Key Vault when configured with an update to the key version, not a property of infrastructure encryption itself. Option C is wrong because encrypting the encryption key stored in Key Vault is a separate concept known as 'key encryption key' (KEK) wrapping, which is part of the key hierarchy in Azure Key Vault, not the double encryption provided by infrastructure encryption.

121
MCQhard

A manufacturing company is designing an IoT solution to monitor equipment in real-time. Thousands of sensors send telemetry data every second. The data must be ingested, processed, and stored for analysis. The solution must handle high throughput and provide low-latency analytics. Additionally, the company wants to use Azure Machine Learning to predict equipment failures based on historical data. You need to design a data pipeline that meets these requirements. What should you include in the design?

A.Use Azure IoT Hub to ingest data, Azure Stream Analytics for real-time processing, and Azure Blob Storage for long-term storage.
B.Use Azure IoT Hub to ingest data, Azure Cosmos DB for storage, and Azure Functions for processing.
C.Use Azure IoT Hub to ingest data, Azure Data Lake Storage for storage, and Azure Stream Analytics for processing.
D.Use Azure Event Hubs to ingest data, Azure Databricks for processing, and Azure Blob Storage for storage.
AnswerA

Azure IoT Hub is the ideal cloud gateway for IoT because it provides per-device identity, secure authentication, and built-in message routing to downstream services. Stream Analytics then handles real-time, SQL-like queries over high-throughput telemetry without requiring custom code, while Blob Storage offers inexpensive, tiered long-term retention. Together they form a scalable hot/warm/cold pipeline that is standard for IoT telemetry workloads.

Why this answer

Azure IoT Hub is designed for secure, high-throughput ingestion from millions of IoT devices, Azure Stream Analytics provides low-latency, real-time processing using SQL-like queries, and Azure Blob Storage offers cost-effective, durable long-term storage for historical data. This combination directly meets the requirements for real-time monitoring and supports downstream Azure Machine Learning workloads by storing historical telemetry in a format easily accessible for model training.

Exam trap

The trap here is that candidates often confuse Azure IoT Hub with Azure Event Hubs, overlooking IoT Hub's superior device management and security features for sensor fleets, or they mistakenly pair Azure Databricks with Event Hubs assuming it provides lower latency than Stream Analytics, when in fact Stream Analytics is purpose-built for sub-second stream processing.

How to eliminate wrong answers

Option B is wrong because Azure Cosmos DB is a NoSQL database optimized for low-latency transactional workloads, not for high-throughput telemetry storage or long-term analytics; using Azure Functions for processing lacks the native windowing and temporal aggregation capabilities needed for real-time analytics on streaming sensor data. Option C is wrong because while Azure Data Lake Storage is excellent for analytics, it is not optimized for real-time, low-latency processing; Azure Stream Analytics should be used for processing, but the pairing with Data Lake Storage for immediate storage introduces latency that contradicts the low-latency requirement. Option D is wrong because Azure Event Hubs is a valid ingestion service, but Azure Databricks is a batch and interactive analytics platform, not a low-latency stream processing engine; using it for real-time processing adds unnecessary complexity and latency compared to Azure Stream Analytics.

122
MCQmedium

Your organization uses Microsoft Purview to govern data assets across Azure SQL Database, Azure Data Lake Storage, and on-premises SQL Server. You need to ensure that sensitive data such as credit card numbers are automatically detected and classified. What should you configure in Microsoft Purview?

A.Data share
B.Data catalog
C.Data lineage mapping
D.Data classification rules
AnswerD

Microsoft Purview's data classification rules are explicitly designed to automatically scan data assets for sensitive information by applying pattern matching (e.g., regex for credit card numbers, social security numbers, or custom patterns) and then assigning classifications such as 'Credit Card Number' or 'PII.' These rules are executed during the data scanning process, allowing organizations to identify and manage sensitive data across their landscape. This is the correct mechanism for automatically detecting and classifying sensitive data, aligning with the requirement.

Why this answer

Microsoft Purview's data classification rules are specifically designed to automatically detect and classify sensitive data like credit card numbers across data sources. By configuring classification rules, you define patterns (e.g., regex for credit card numbers) that Purview scans against assets in Azure SQL Database, Azure Data Lake Storage, and on-premises SQL Server, applying sensitivity labels accordingly.

Exam trap

The trap here is that candidates often confuse the Data Catalog's metadata discovery with automatic content classification, not realizing that classification requires explicit rules to scan and identify sensitive data patterns.

How to eliminate wrong answers

Option A is wrong because Data Share is a service for securely sharing data with external organizations, not for detecting or classifying sensitive data. Option B is wrong because Data Catalog is a metadata repository that registers and discovers data assets but does not perform automatic scanning or classification of sensitive content. Option C is wrong because Data Lineage Mapping tracks how data moves and transforms across pipelines, which is unrelated to detecting sensitive data patterns like credit card numbers.

123
MCQmedium

Your company is deploying a web application on Azure App Service. The application must be able to read secrets from Azure Key Vault without storing credentials in application code. Which feature should you enable?

A.Key Vault access policies
B.Azure AD Application Registration with client secret
C.Managed Identity
D.App Service Authentication / Authorization
AnswerC

Managed Identity is correct because it gives the App Service an Azure AD-backed service principal that is automatically created and managed by Azure. The application retrieves a token from the Azure Instance Metadata Service (IMDS) endpoint without any secrets in code or configuration. After enabling the identity, you simply grant it read (`list` and `get`) permissions on the Key Vault via an access policy or RBAC, and the runtime calls Key Vault with that identity. This is the recommended Azure pattern for passwordless, secure access between Azure resources.

Why this answer

Managed Identity (C) is correct because it allows the App Service to authenticate to Azure Key Vault without storing any credentials in code or configuration. Azure automatically manages the identity lifecycle, and the app uses the Azure Identity SDK to obtain tokens for Key Vault access via the IMDS endpoint (169.254.169.254). This eliminates the need for secrets or certificates in the application.

Exam trap

The trap here is that candidates often confuse App Service Authentication/Authorization (EasyAuth) with Managed Identity, but EasyAuth is for user authentication, not for the app's own identity to access Azure resources like Key Vault.

How to eliminate wrong answers

Option A is wrong because Key Vault access policies control authorization (who can read secrets) but do not provide authentication credentials for the app; the app still needs a way to prove its identity. Option B is wrong because an Azure AD Application Registration with a client secret requires storing that secret in the application code or configuration, which violates the requirement of not storing credentials. Option D is wrong because App Service Authentication / Authorization (EasyAuth) is designed to authenticate users (not the app itself) and does not provide the app with an identity to access Key Vault.

124
MCQmedium

You are designing a solution to provide high availability for a critical application running on Azure Virtual Machines. The virtual machines must be placed on physically separate hardware and have guaranteed availability during Azure maintenance events. Which option meets these requirements?

A.Deploy VMs in an Availability Set
B.Deploy VMs in a Proximity Placement Group
C.Deploy VMs in different Availability Zones
D.Deploy VMs in a Virtual Machine Scale Set
AnswerC

Availability Zones are physically separate datacentres within a region, each with independent power, cooling and networking. Distributing VMs across zones satisfies the stem's physically separate hardware constraint and maintains availability during Azure maintenance affecting a single zone.

Why this answer

Availability Zones provide physically separate locations within an Azure region, protecting against datacenter failures and maintenance events. Option A (Availability Set) spreads VMs across fault and update domains within a single datacenter, not across separate physical facilities. Option B (Proximity Placement Group) is for low latency, not high availability.

Option D (Virtual Machine Scale Set) is for auto-scaling and can be combined with Availability Zones, but alone it does not guarantee placement on separate hardware.

125
Multi-Selectmedium

You are designing a solution to monitor a hybrid environment consisting of Azure VMs and on-premises servers. The solution must provide centralized log analytics, security threat detection, and the ability to run custom queries across all logs. Which TWO Azure services should you include? (Choose two.)

Select 2 answers
A.Azure Monitor Agent
B.Azure Log Analytics workspace
C.Microsoft Sentinel
D.Azure Arc
E.Azure Update Manager
AnswersB, C

Azure Log Analytics workspace is the central data repository in Azure Monitor that receives logs and metrics from Azure and non-Azure sources, including hybrid machines via the Azure Monitor Agent. It provides the KQL query language to analyze, correlate, and visualize data, and serves as the foundation for alerts, workbooks, and dashboards. This makes it the correct choice when the requirement is to monitor and analyze a hybrid environment.

Why this answer

A Log Analytics workspace is the central repository in Azure that ingests and stores log data from various sources, including Azure VMs and on-premises servers. It enables you to run custom Kusto Query Language (KQL) queries across all collected logs, which directly satisfies the requirement for centralized log analytics and custom querying.

Exam trap

The trap here is that candidates often confuse Azure Monitor Agent (a data collector) with Azure Monitor itself, mistakenly thinking the agent alone provides analytics and querying, when in fact it only forwards data to a Log Analytics workspace.

126
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID (formerly Azure AD) and on-premises Active Directory. You need to design a solution that allows users to access cloud applications using their on-premises credentials, and also enables single sign-on (SSO) for legacy on-premises applications that do not support modern authentication protocols. What should you recommend?

A.Deploy Azure Active Directory Domain Services and domain-join the legacy application servers.
B.Use Azure Active Directory B2B collaboration for internal users.
C.Implement Azure AD Connect with password hash synchronization and Azure AD Application Proxy.
D.Configure Azure AD Seamless SSO and use Azure AD Connect with pass-through authentication.
AnswerC

Azure AD Connect with password hash synchronization synchronizes a cryptographic hash of each user's on-premises AD password to Azure AD, enabling the user to sign in to cloud services using the same credentials. Azure AD Application Proxy then publishes legacy on-premises applications that use non-modern protocols (for example, Kerberos or LDAP) and enforces Azure AD pre-authentication, so after the initial Azure AD sign-in, users are seamlessly authenticated to the legacy app. Together these components deliver the needed SSO experience without requiring additional on-premises infrastructure. This is the correct combination for extending SSO to legacy apps in a hybrid identity environment.

Why this answer

Azure AD Connect with password hash synchronization enables users to authenticate to cloud applications using their on-premises credentials, while Azure AD Application Proxy provides secure remote access and SSO for legacy on-premises applications that do not support modern authentication protocols (such as Kerberos, SAML, or OAuth). The Application Proxy can pass Kerberos constrained delegation tickets to legacy apps, enabling SSO without requiring those apps to be domain-joined or modified.

Exam trap

The trap here is that candidates often confuse pass-through authentication (which validates passwords on-premises) with the need for a reverse proxy solution like Application Proxy to handle legacy app publishing and SSO, mistakenly thinking Seamless SSO alone suffices for on-premises legacy applications.

How to eliminate wrong answers

Option A is wrong because Azure AD Domain Services provides managed domain services (e.g., LDAP, Kerberos) for Azure VMs but does not enable SSO for legacy on-premises applications accessed from the internet; it also requires domain-joining servers, which is not a scalable or secure approach for publishing legacy apps. Option B is wrong because Azure AD B2B collaboration is designed for external guest users (partners, vendors), not for internal users who need to use their on-premises credentials for cloud apps and legacy app SSO. Option D is wrong because Azure AD Seamless SSO with pass-through authentication provides SSO for cloud apps and validates passwords against on-premises AD, but it does not include a reverse proxy component to publish legacy on-premises applications that lack modern authentication support.

127
MCQhard

A global e-commerce company deploys its web application on Azure Kubernetes Service (AKS) clusters in multiple Azure regions. They need a single global endpoint for users, with SSL offloading, web application firewall (WAF) protection, and URL path-based routing to the nearest healthy AKS cluster. Which Azure service should they use?

A.Azure Front Door
B.Azure Traffic Manager
C.Azure Application Gateway
AnswerA

Azure Front Door is correct because it operates at Layer 7 as a global entry point using Microsoft's edge network. It supports SSL offloading, web application firewall (WAF), and URL path-based routing, and it uses anycast to route users to the nearest healthy backend based on global health probes. This uniquely combines global distribution with HTTP-layer intelligence and security, making it ideal for a globally distributed e-commerce web application.

Why this answer

Azure Front Door is the correct choice because it provides a single global endpoint with SSL offloading, WAF protection, and URL path-based routing. It uses Anycast-based routing to direct traffic to the nearest healthy AKS cluster, ensuring low latency and high availability across multiple regions.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager (DNS-level) with Azure Front Door (application-layer), overlooking the need for SSL offloading, WAF, and path-based routing that only Front Door provides.

How to eliminate wrong answers

Option B (Azure Traffic Manager) is wrong because it operates at the DNS level and does not support SSL offloading, WAF, or URL path-based routing; it only provides DNS-based traffic distribution. Option C (Azure Application Gateway) is wrong because it is a regional load balancer that cannot provide a single global endpoint across multiple Azure regions; it lacks global Anycast routing. Option D (Azure Load Balancer) is wrong because it operates at Layer 4 (TCP/UDP) and does not support SSL offloading, WAF, or URL path-based routing; it is designed for regional traffic distribution within a single region.

128
MCQhard

A company is deploying a multi-tier web application on Azure. The web tier must be accessible from the internet. The application tier and database tier must be isolated within the virtual network and not directly accessible from the internet. The solution must provide SSL termination, URL-based routing, and Web Application Firewall (WAF) capabilities. Which Azure service should they use to expose the web tier?

A.Azure Application Gateway
C.Azure Traffic Manager
D.Azure Front Door
AnswerA

Azure Application Gateway is the correct choice because it operates at Layer 7, enabling SSL termination, URL path-based routing, and integrated WAF to filter malicious traffic. It can be deployed in a dedicated subnet within the same VNet as the web and database tiers, allowing it to forward requests to a backend pool via private IP addresses while the database tier remains isolated behind NSGs. This combination of HTTP-level routing, security, and VNet integration satisfies the multi-tier isolation requirement.

Why this answer

Azure Application Gateway is a layer-7 load balancer that provides SSL termination, URL-based routing, and a built-in Web Application Firewall (WAF). It can expose the web tier to the internet while keeping the application and database tiers isolated within the virtual network, as it routes traffic to backend pools using HTTP/HTTPS rules without exposing those backends directly.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway because both offer layer-7 features, but Front Door is a global load balancer that does not provide VNet-level isolation for backends, whereas Application Gateway is regionally scoped and integrates directly with virtual networks for internal tier isolation.

How to eliminate wrong answers

Option B (Azure Load Balancer) is wrong because it operates at layer 4 (TCP/UDP) and cannot perform SSL termination, URL-based routing, or WAF capabilities. Option C (Azure Traffic Manager) is wrong because it is a DNS-based traffic router that directs traffic at the domain level, not a proxy or gateway; it does not terminate SSL, route based on URL paths, or provide WAF. Option D (Azure Front Door) is wrong because, although it offers SSL termination, URL-based routing, and WAF, it is a global, multi-region service designed for internet-facing applications at the edge; it does not isolate backends within a single virtual network and is not the correct choice for a single-region deployment requiring VNet integration for the application and database tiers.

129
MCQeasy

You need to design a virtual network architecture for a three-tier application in Azure. The web tier must be accessible from the internet, the application tier must only be accessible from the web tier, and the database tier must only be accessible from the application tier. Which combination of Azure services should you use?

A.Use Azure Front Door, service endpoints, and Azure SQL Database with firewall rules.
B.Use Azure Application Gateway with WAF, network security groups (NSGs) on subnets, and Azure Private Endpoints for the database.
C.Use Azure Load Balancer, Azure Firewall, and Azure SQL Database with public endpoint.
D.Use a single virtual network with three subnets, no NSGs, and Azure SQL Database with VNet injection.
AnswerB

Azure Application Gateway with WAF provides the required Layer 7 internet-facing ingress, offering TLS offload, path-based routing, and OWASP Top 10 protection, which is superior to a simple load balancer for a three-tier app. Network security groups (NSGs) applied to each subnet establish explicit allow/deny rules between the web, application, and data tiers, enabling least-privilege communication and preventing lateral movement if one tier is compromised. Azure Private Endpoints for the database place the Azure SQL Database into the VNet with a private IP address, ensuring traffic never traverses the public internet and can be further secured with NSGs on the subnet or with Network Security Perimeter controls. This combination of L7 WAF protection, subnet segmentation, and private connectivity is the industry best practice for a secure three-tier architecture on Azure.

Why this answer

It uses Azure Application Gateway with WAF to provide internet-facing, layer-7 web traffic management and protection, network security groups (NSGs) on subnets to enforce east-west traffic isolation (web-to-app, app-to-database), and Azure Private Endpoints for the database to ensure the database is accessible only via a private IP within the virtual network, eliminating exposure to the internet. This combination meets the three-tier isolation requirements precisely.

Exam trap

The trap here is that candidates often confuse Azure Front Door with Application Gateway, or assume that service endpoints alone provide the same level of isolation as Private Endpoints, but service endpoints do not remove public endpoint exposure and cannot enforce subnet-to-subnet access control without additional NSG rules.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global load balancer and CDN that does not provide subnet-level traffic filtering; service endpoints only secure Azure SQL Database to a subnet but do not prevent the database from being accessed from other services in that subnet, and firewall rules alone cannot enforce the app-tier-only access requirement. Option C is wrong because Azure Load Balancer operates at layer 4 and cannot inspect application-layer traffic or provide WAF protection; Azure Firewall is a stateful firewall but does not replace the need for NSGs to isolate subnets, and using a public endpoint for Azure SQL Database violates the requirement that the database must only be accessible from the application tier. Option D is wrong because a single virtual network with three subnets and no NSGs provides no traffic filtering between tiers, allowing any resource in any subnet to communicate with any other; Azure SQL Database with VNet injection (delegated subnet) still requires NSGs or other controls to restrict access, and without them, the database is exposed to the application and web tiers directly.

130
MCQmedium

Refer to the exhibit. You run the Azure Resource Graph query shown. A colleague asks why the query returns no results even though there are VMs in the subscription. The VMs use managed disks with Premium_LRS. What is the most likely reason for the empty result set?

A.The storage account type is incorrectly specified; it should be 'Premium_ZRS'
B.The resource type string is case-sensitive; it should be 'Microsoft.Compute/virtualMachines'
C.The 'limit 10' clause restricts too many results; remove the limit
D.The 'name' property does not exist; use 'properties.name' instead
AnswerB

Azure Resource Graph queries enforce strict case-sensitivity for the `resourceType` property. To accurately retrieve virtual machine resources, the precise string `Microsoft.Compute/virtualMachines` must be utilised. If the query shown in the exhibit employs an incorrect casing, such as `microsoft.compute/virtualmachines` or `Microsoft.Compute/VirtualMachines`, it will fail to match any existing virtual machines within the subscription. This adherence to exact casing is the most likely reason for the empty result set, despite the presence of VMs.

Why this answer

The query specifies 'microsoft.compute/virtualmachines' (all lowercase), but the correct casing includes capital letters: 'Microsoft.Compute/virtualMachines'. Option A is wrong because Premium_LRS is a valid storage account type. Option C is wrong because the query limits to 10 results, which is fine.

Option D is wrong because the query does not filter by name.

131
MCQmedium

Your organization has a containerized application running on Azure Kubernetes Service (AKS). You need to design a solution to securely store and manage secrets (e.g., database passwords, API keys) that the application consumes. The solution must integrate with AKS and support automatic rotation of secrets. What should you use?

A.Azure Key Vault with the Secrets Store CSI driver
B.Azure App Configuration
C.Azure Managed Identity
D.Azure Container Registry
AnswerA

Azure Key Vault is Azure's dedicated secret-management service, providing HSM-backed encryption, Azure RBAC/access policies, and audit logging. The Secrets Store CSI driver mounts Key Vault secrets as a volume into AKS pods, so applications can read them as files without hardcoding credentials in images or environment variables. Because the driver supports periodic polling and can update mounted secrets in place, it enables secret rotation without redeploying or restarting the pod, which is precisely what the scenario requires.

Why this answer

Azure Key Vault with the Secrets Store CSI driver is the correct choice because it provides a dedicated, secure vault for storing secrets and mounts them directly into AKS pods as volumes or environment variables without exposing them in application code. The CSI driver integrates natively with AKS and supports automatic rotation by periodically polling Key Vault for updated secret versions, ensuring pods consume the latest values without requiring a restart.

Exam trap

The trap here is that candidates often confuse Azure App Configuration with Key Vault because both can store configuration data, but App Configuration lacks secret-specific features like automatic rotation, access policies, and hardware security module (HSM) support that Key Vault provides.

How to eliminate wrong answers

Option B is wrong because Azure App Configuration is designed for managing application configuration settings (e.g., feature flags, connection strings) and does not natively support secret rotation or secure secret storage with access policies like Key Vault. Option C is wrong because Azure Managed Identity provides an identity for AKS to authenticate to Azure services but does not store or manage secrets; it must be combined with Key Vault to access secrets. Option D is wrong because Azure Container Registry is a container image registry and has no capability to store or manage secrets consumed by applications; it only stores container images and Helm charts.

132
MCQeasy

A company deploys a stateless web application on Azure VMs in a single region. They need to distribute incoming HTTP traffic across multiple VMs and perform health checks. The solution should be highly available within the region. Which Azure load balancing solution should they use?

A.Azure Load Balancer (Standard) with HTTP health probe.
B.Azure Application Gateway v2.
C.Azure Traffic Manager.
D.Azure Front Door.
AnswerA

The Standard Load Balancer is a regional Layer 4 load balancer that distributes TCP/UDP traffic across backend VM instances. Its HTTP health probe periodically sends HTTP GET requests to the configured path and removes any VM that does not return a 2xx status, enabling automatic failover. Being zone-redundant, it provides high availability within a region, and because the app is stateless, no session persistence or Layer 7 routing is needed. This makes it the simplest, most cost-effective choice.

Why this answer

Azure Load Balancer (Standard) operates at Layer 4 (TCP/UDP) and can distribute HTTP traffic across VMs in a single region while performing health checks via HTTP health probes. It provides high availability within a region by distributing traffic across availability zones or availability sets, meeting the requirement for a stateless web application without needing Layer 7 features.

Exam trap

The trap here is that candidates often choose Azure Application Gateway v2 because they assume HTTP traffic requires a Layer 7 load balancer, but Azure Load Balancer can handle HTTP traffic at Layer 4 with HTTP health probes, making it the simpler and more cost-effective choice for a stateless web application within a single region.

How to eliminate wrong answers

Option B is wrong because Azure Application Gateway v2 is a Layer 7 load balancer with features like SSL termination, URL-based routing, and WAF, which are unnecessary for a stateless web application that only needs basic HTTP traffic distribution and health checks, adding cost and complexity. Option C is wrong because Azure Traffic Manager is a DNS-based global traffic routing solution that operates across regions, not within a single region, and does not perform health checks on individual VMs or distribute incoming HTTP traffic directly. Option D is wrong because Azure Front Door is a global Layer 7 load balancer and CDN that routes traffic across regions, not within a single region, and includes features like SSL offload and WAF that are not required for this scenario.

133
MCQmedium

Your company has an Azure subscription that contains several virtual machines (VMs) running Windows Server. You need to ensure that all VMs are compliant with a baseline security policy that includes specific registry key settings. The solution must automatically remediate non-compliant settings without manual intervention. What should you use?

A.Azure Automation State Configuration (DSC)
B.Azure Policy with Guest Configuration
C.Microsoft Defender for Cloud with custom recommendations
D.Microsoft Intune
AnswerB

Azure Policy with Guest Configuration audits and remediates settings inside VMs via the Guest Configuration extension, applying the DeployIfNotExists effect to install and configure the agent. This satisfies the stem's requirement for automatic remediation of registry key settings without manual intervention, which subscription-level policy alone cannot achieve.

Why this answer

Azure Policy with Guest Configuration is designed to audit and enforce settings inside VMs, including registry keys, and supports automatic remediation via DeployIfNotExists and Modify effects. It uses a guest configuration extension to evaluate the VM's configuration and can remediate non-compliant settings without manual intervention. This meets the requirement of ensuring compliance with a baseline security policy and automatic remediation.

Exam trap

AZ-305 often tests the confusion between Azure Policy with Guest Configuration and Azure Automation State Configuration (DSC). Both can enforce and remediate VM settings and report on compliance, but Azure Policy with Guest Configuration is the Azure-native governance solution that audits and automatically remediates in-guest settings (including registry keys) at scale, with compliance reporting integrated into Azure Policy.

How to eliminate wrong answers

Option A is wrong because Azure Automation State Configuration (DSC) can enforce configurations but does not provide the same level of compliance auditing and automatic remediation at scale as Azure Policy; it requires manual setup of DSC configurations and does not integrate with Azure Policy's compliance dashboard. Option C is wrong because Microsoft Defender for Cloud with custom recommendations provides security assessments but does not automatically remediate non-compliant settings; it only alerts. Option D is wrong because Microsoft Intune is for managing devices (including Windows PCs) but is not used for managing Azure VMs' guest OS settings; it lacks the deep integration with Azure Policy for VM compliance.

134
Multi-Selecthard

Your company plans to migrate a large number of on-premises virtual machines to Azure. You need to assess the current environment and migrate the workloads with minimal downtime. Which THREE Azure services or tools should you use? (Choose three.)

Select 3 answers
A.Azure App Service
B.Azure Import/Export Service
C.Azure Data Box
D.Azure Site Recovery
E.Azure Migrate
AnswersC, D, E

Azure Data Box is a physical appliance that Microsoft ships to your site, enabling secure, offline bulk transfer of up to 80 TB of data over a high-speed local copy path when network bandwidth is limited or non-existent. After you copy data onto the device, you return it, and Microsoft uploads the data to an Azure storage account. This makes Data Box ideal for large initial data loads, but it is not itself a continuous replication or live migration tool; it facilitates lifting and shifting data, which can then be attached to newly deployed VMs. For a migration involving a huge volume of on-premises data with constrained connectivity, Data Box provides the fastest and most cost-effective way to move the raw data into Azure.

Why this answer

Azure Data Box is correct because it enables large-scale offline data transfer for environments with limited network bandwidth, allowing you to migrate terabytes of VM data to Azure without relying on slow or unstable connections. This service is ideal for the initial bulk copy of on-premises VM disks, which can then be used with Azure Migrate for assessment and Azure Site Recovery for ongoing replication with minimal downtime.

Exam trap

The trap here is that candidates often confuse Azure Data Box with Azure Import/Export Service, but Data Box is the modern, recommended service for large-scale offline migration, while Import/Export is outdated and less integrated with Azure Migrate and Site Recovery.

135
MCQeasy

A government agency is designing a solution to store sensitive citizen data. The data must be encrypted at rest and in transit. The agency requires that the encryption keys be managed by the agency and stored in a hardware security module (HSM). Additionally, the solution must comply with regulatory requirements that mandate customer-managed keys. You need to recommend a key management solution. What should you recommend?

A.Use Azure Key Vault Standard with software-protected keys.
B.Use Microsoft Purview to manage keys and compliance.
C.Use Azure Information Protection with a custom protection template.
D.Use Azure Key Vault Managed HSM with FIPS 140-2 Level 3 validated HSMs.
AnswerD

Azure Key Vault Managed HSM is a fully managed, single-tenant HSM service validated to FIPS 140-2 Level 3, meaning the cryptographic boundary is tamper-resistant and hardware-protected. It gives the agency customer-managed keys (CMK) stored in a dedicated HSM partition, preventing Microsoft from accessing key material and providing the auditability required by government mandates such as FedRAMP High and NIST controls. This makes it the correct choice for sensitive workloads requiring hardware-bound key protection.

Why this answer

Azure Key Vault Managed HSM provides a fully managed, FIPS 140-2 Level 3 validated HSM that allows the agency to retain sole control of the encryption keys, meeting the requirement for customer-managed keys. It ensures data is encrypted at rest and in transit while keeping keys within the agency's own HSM boundary, which is essential for regulatory compliance.

Exam trap

The trap here is that candidates often confuse Azure Key Vault Standard (which offers software-protected keys) with Azure Key Vault Managed HSM (which offers dedicated HSM-backed keys), failing to recognize that only Managed HSM provides FIPS 140-2 Level 3 validation and full customer-managed key sovereignty.

How to eliminate wrong answers

Option A is wrong because Azure Key Vault Standard uses software-protected keys that are not FIPS 140-2 Level 3 validated and do not meet the requirement for keys stored in a dedicated HSM. Option B is wrong because Microsoft Purview is a data governance and compliance solution, not a key management service; it cannot store or manage encryption keys in an HSM. Option C is wrong because Azure Information Protection is a classification and labeling service that uses Azure Rights Management for encryption, but it does not provide customer-managed keys stored in a dedicated HSM, nor does it meet the FIPS 140-2 Level 3 requirement.

136
MCQeasy

Your company is migrating on-premises virtual machines to Azure. You need to assess the current environment and get a cost estimate for Azure. Which tool should you use?

A.Azure Cost Management
B.Azure Migrate
C.Azure Monitor
D.Azure Advisor
AnswerB

Azure Migrate discovers and assesses on-premises VMs, producing readiness findings and Azure cost estimates through its assessment tooling. This directly satisfies the stem's dual requirement to assess the current environment and obtain a cost estimate before migration.

Why this answer

Azure Migrate provides assessment and migration capabilities for on-premises workloads to Azure. It can discover on-premises VMs and provide a cost estimate for running them in Azure. Option A (Azure Cost Management) is for cost analysis after migration, not for initial assessment.

Option C (Azure Monitor) is for monitoring, not assessment. Option D (Azure Advisor) gives optimization recommendations after deployment.

137
MCQmedium

A company has an Azure SQL Database that they need to access from an on-premises data center over ExpressRoute. They want to use a private IP address to connect to the database, ensuring traffic never traverses the public internet. Which Azure service should they use?

A.Azure Private Link
B.Azure Service Endpoints
C.Azure VPN Gateway
D.Azure Front Door
AnswerA

Azure Private Link provisions a private endpoint inside your virtual network, assigning Azure SQL Database an interface with a private IP address. Traffic from on-premises to this endpoint flows over ExpressRoute or a site-to-site VPN and then through the Microsoft backbone, never touching the public internet. This also lets you disable public access to the database, so only clients reaching the private endpoint can connect.

Why this answer

Azure Private Link allows you to access Azure SQL Database over a private endpoint within your virtual network, using a private IP address. When combined with ExpressRoute, traffic from your on-premises data center to the database traverses the Microsoft backbone network and never touches the public internet, meeting the requirement for a private, secure connection.

Exam trap

The trap here is confusing Azure Service Endpoints with Private Link: both keep traffic on the Azure backbone, but only Private Link provides a private IP address and removes exposure to the public endpoint, which is the key requirement in this scenario.

How to eliminate wrong answers

Option B (Azure Service Endpoints) is wrong because service endpoints expose the Azure SQL Database to the internet via its public endpoint, even though traffic is routed over the Azure backbone; the connection still resolves to a public IP and is not a private IP address. Option C (Azure VPN Gateway) is wrong because it creates an encrypted tunnel over the public internet, which does not guarantee that traffic never traverses the public internet—it still uses internet routing between the VPN gateway and the on-premises device. Option D (Azure Front Door) is wrong because it is a global load balancer and application delivery service that operates over the public internet, using public endpoints and not providing private IP connectivity to Azure SQL Database.

138
MCQhard

You are designing a network architecture for a three-tier application hosted in Azure. The front-end tier must be accessible from the internet, the business tier must only communicate with the front-end tier, and the data tier must only communicate with the business tier. You need to minimize exposure and use Azure-native services. Which combination of services should you use?

A.Azure Load Balancer for front-end, NSGs on subnets, and VNet peering
B.VPN Gateway for front-end, NSGs on subnets, and private endpoints
C.Azure Application Gateway with WAF for front-end, NSGs on subnets, and service endpoints
D.Azure Firewall for all inbound traffic, NSGs on subnets, and VNet peering
AnswerC

Azure Application Gateway is a Layer-7 load balancer with an integrated web application firewall (WAF), delivering TLS termination, cookie-based session affinity, URL path-based routing, and OWASP Top-10 attack protection for the front-end HTTP/HTTPS tier. NSGs placed on each subnet enforce east-west traffic rules so the web tier can only communicate with the app tier, which can only reach the data tier. Service endpoints restrict Azure PaaS services like SQL Database and Storage to traffic from a specific VNet subnet, adding a hardened network boundary for the backend. This combination fully aligns with a secured, tiered web architecture.

Why this answer

Azure Application Gateway with WAF provides Layer 7 HTTP/HTTPS load balancing and web application firewall protection for internet-facing front-end traffic. Network Security Groups (NSGs) on subnets enforce east-west traffic isolation, allowing the business tier to only receive traffic from the front-end subnet and the data tier to only receive traffic from the business subnet. Service endpoints secure access to PaaS data services (e.g., Azure SQL Database) from the data tier subnet without exposing public endpoints, meeting the requirement to minimize exposure using Azure-native services.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7) and overlook the need for WAF to protect internet-facing web applications, or they incorrectly assume VPN Gateway or Azure Firewall can serve as a front-end load balancer for HTTP traffic.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and lacks web application firewall (WAF) capabilities, leaving the front-end vulnerable to application-layer attacks; VNet peering is used for connecting separate VNets, not for tier-to-tier isolation within the same VNet. Option B is wrong because VPN Gateway is designed for site-to-site or point-to-site encrypted tunnels from on-premises networks, not for direct internet-facing front-end access; private endpoints are used for privately accessing PaaS services from a VNet, but they do not replace the need for a Layer 7 load balancer or WAF for internet traffic. Option D is wrong because Azure Firewall is a stateful firewall for centralized inbound/outbound traffic inspection, but it is not optimized for HTTP/HTTPS load balancing or WAF functionality; VNet peering is irrelevant for intra-VNet subnet isolation and does not address the need for a dedicated front-end load balancer.

139
Multi-Selecteasy

A company is planning to migrate on-premises SQL Server databases to Azure. They want to minimize administrative overhead and ensure high availability with automatic failover. Which TWO Azure SQL deployment options should they consider?

Select 2 answers
A.Azure SQL Database (single database)
B.SQL Server on Azure VMs
C.SQL Server Stretch Database
D.Azure SQL Database Managed Instance
E.Azure Synapse Analytics
AnswersA, D

Azure SQL Database (single database) is the correct PaaS target for a straightforward migration. It provides a fully managed SQL Server engine with a 99.99% availability SLA, automatic built-in high availability via Always On replicas, transparent backup and patching, and built-in automated failover. Its isolated database model requires zero infrastructure maintenance, making it the fastest, lowest-overhead option for migrating a single on-premises transactional database.

Why this answer

Azure SQL Database (single database) is correct because it is a fully managed PaaS offering where Microsoft handles patching, backups, and infrastructure, and it supports built-in high availability with automatic failover via the underlying service tier architecture. Azure SQL Database Managed Instance is also correct because it provides near-100% SQL Server compatibility as a PaaS service, reducing administrative overhead while including built-in high availability and automatic failover through Always On availability groups managed by the platform. SQL Server on Azure VMs is not appropriate here because it is IaaS, requiring the customer to manage OS patching, SQL updates, and configure their own Always On availability groups for failover.

SQL Server Stretch Database is a deprecated feature for archiving cold data to Azure, not a migration target for high availability. Azure Synapse Analytics is an analytics/data warehousing service, not a transactional SQL Server database migration option.

Exam trap

The trap here is that candidates often choose SQL Server on Azure VMs (Option B) thinking it offers more control for high availability, but they overlook that it requires manual configuration of Always On Availability Groups or clustering, which increases administrative overhead, whereas Azure SQL Database and Managed Instance provide automatic failover as a built-in PaaS feature.

140
MCQhard

Your organization is designing a solution to capture and analyze IoT data from millions of devices. The solution must ingest data at high velocity, store the data for long-term analytics, and provide real-time dashboards. Which combination of Azure services should you recommend?

A.Azure Event Hubs, Azure Data Lake Storage, and Azure Stream Analytics
B.Azure Service Bus, Azure SQL Database, and Power BI
C.Azure Cosmos DB, Azure Data Explorer, and Azure Logic Apps
D.Azure IoT Hub, Azure Blob Storage, and Azure Functions
AnswerA

Azure Event Hubs is a massively scalable event streaming platform that ingests millions of events per second with low latency, making it the correct high-velocity ingestion layer. Azure Data Lake Storage Gen2 stores both structured and unstructured data in a hierarchical namespace with POSIX access control and ACID transactions, ideally suited for long-term analytics. Azure Stream Analytics runs serverless, SQL-like queries on live and historical streams, providing the low-latency, stateful processing needed to deliver real-time dashboards.

Why this answer

Azure Event Hubs is designed for high-velocity data ingestion from millions of devices, Azure Data Lake Storage provides scalable and cost-effective long-term storage for analytics, and Azure Stream Analytics enables real-time processing and dashboarding. This combination directly addresses the requirements of high-throughput ingestion, durable storage, and real-time analytics without unnecessary complexity.

Exam trap

The trap here is confusing Azure IoT Hub with Azure Event Hubs, as both can ingest device data, but IoT Hub is designed for device management and bidirectional communication, not for the massive-scale, high-velocity event streaming required for millions of devices.

How to eliminate wrong answers

Option B is wrong because Azure Service Bus is a message broker for enterprise messaging with lower throughput and higher latency than Event Hubs, making it unsuitable for high-velocity IoT ingestion; Azure SQL Database is a relational store not optimized for massive-scale time-series or unstructured data; and Power BI alone cannot perform real-time stream processing without a real-time analytics engine. Option C is wrong because Azure Cosmos DB is a NoSQL database with limited throughput for high-velocity ingestion and is not designed for long-term cold storage; Azure Data Explorer is a fast analytics service but lacks native high-velocity ingestion capabilities; and Azure Logic Apps is an orchestration tool, not a real-time stream processor. Option D is wrong because Azure IoT Hub is a device management and ingestion service but is not optimized for high-velocity event streaming at the scale of millions of devices; Azure Blob Storage is a general-purpose object store but lacks the hierarchical namespace and analytics integration of Data Lake Storage; and Azure Functions is a serverless compute service that cannot sustain real-time stream processing at high throughput without complex scaling.

141
MCQhard

You are designing a landing zone in Azure for a regulated financial services company. They require that all storage accounts be restricted to specific virtual networks and have encryption using customer-managed keys (CMK). Additionally, they want to ensure that any storage account creation outside of the approved network boundaries is prevented. Which combination of Azure Policy and Network Security controls should you recommend?

A.Use Azure Policy to enforce service endpoints on storage accounts and deny creation if not present, along with a policy requiring CMK encryption.
B.Use Azure Policy to require storage account encryption with CMK, and use network security groups (NSGs) to restrict storage account access to specific subnets.
C.Deploy Azure Firewall in the hub virtual network and configure application rules to allow only approved storage accounts.
D.Use Azure Policy to require storage accounts to use private endpoints, and use Azure Private Link to restrict access from specific virtual networks.
AnswerA

By combining a Deny policy that requires the Microsoft.Storage service endpoint on storage accounts with a policy mandating customer-managed keys (CMK), the landing zone ensures all storage resources are both network-isolated to approved virtual networks and encrypted with keys held by the organization. The Deny effect blocks any storage account creation that lacks the service endpoint, while the CMK policy enforces encryption at rest with a key the customer controls, addressing regulated-industry requirements for both network segmentation and cryptographic key sovereignty. This approach is declarative and prevents configuration drift, as any non-compliant creation is rejected at deployment time.

Why this answer

It combines Azure Policy to enforce service endpoints on storage accounts (denying creation if not present) with a policy requiring customer-managed keys (CMK) for encryption. Service endpoints restrict storage account access to specific virtual networks at the network layer, while the CMK policy ensures compliance with encryption requirements. This directly addresses the company's need to prevent storage account creation outside approved network boundaries and enforce encryption.

Exam trap

The trap here is that candidates often confuse network security groups (NSGs) or Azure Firewall with service endpoints or private endpoints, not realizing that NSGs cannot restrict PaaS service access and that private endpoints alone do not prevent resource creation outside approved networks.

How to eliminate wrong answers

Option B is wrong because network security groups (NSGs) operate at the subnet or NIC level and cannot restrict access to a storage account's public endpoint; NSGs filter traffic to/from VMs, not PaaS services like Azure Storage. Option C is wrong because Azure Firewall application rules control outbound traffic from virtual networks to FQDNs, but they do not enforce restrictions on storage account creation or encryption; they also cannot prevent a user from creating a storage account outside approved network boundaries. Option D is wrong because while private endpoints and Azure Private Link restrict access from specific virtual networks, they do not prevent storage account creation outside those networks; a user could still create a storage account with a public endpoint, and the policy would not deny it.

142
MCQeasy

Your company has Azure virtual machines running a critical application. You need to back up these VMs daily and retain backups for 7 years. The solution must be cost-effective and support application-consistent backups. What should you use?

A.Azure Backup
B.Azure Files backup
C.Azure Site Recovery
D.Azure VM snapshots stored in Azure Storage
AnswerA

Azure Backup is the native managed backup service for Azure VMs. It installs a backup extension on each VM and coordinates VSS (Volume Shadow Copy) on Windows or file-system-consistent snapshots on Linux, then transfers the VM's disks to a Recovery Services vault. It provides a configurable backup policy (daily or weekly) with long-term retention, and allows application-consistent, crash-consistent point-in-time restores of entire VMs or individual disks. Because it is fully managed and integrated with Azure Policy and monitoring, it is the correct choice for a critical application that needs reliable recoverability.

Why this answer

Azure Backup is the correct choice because it provides a native, cost-effective backup solution for Azure VMs that supports application-consistent backups via the Volume Shadow Copy Service (VSS) for Windows and file-system-consistent backups for Linux. It allows you to configure a backup policy with daily backups and a retention duration of up to 99 years, easily meeting the 7-year requirement. Azure Backup also integrates with Azure Recovery Services vault, offering centralized management and long-term retention at a lower cost than other disaster recovery or snapshot-based approaches.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with Azure Backup (backup), or assume that VM snapshots are sufficient for long-term retention, overlooking the need for application consistency and cost-effective lifecycle management.

How to eliminate wrong answers

Option B is wrong because Azure Files backup is designed to back up Azure file shares, not Azure VMs, and does not provide application-consistent backups for VM workloads. Option C is wrong because Azure Site Recovery is a disaster recovery solution focused on replication and failover for business continuity, not a backup service; it does not support long-term retention policies like 7 years and is more expensive for daily backup needs. Option D is wrong because Azure VM snapshots stored in Azure Storage are crash-consistent by default, not application-consistent, and managing snapshots for daily backups over 7 years would be complex and costly due to manual lifecycle management and lack of native backup policy integration.

143
MCQmedium

A company plans to deploy multiple virtual machines (VMs) across two Azure regions for high availability. The VMs will host a stateless web application that must be accessible via a single DNS endpoint. The solution must automatically route traffic to the nearest region with available capacity and provide failover if a region becomes unhealthy. Which Azure service should they use to meet these requirements?

A.Azure Traffic Manager
B.Azure Front Door
D.Azure Application Gateway
AnswerA

Azure Traffic Manager is a DNS-based global load balancer that routes incoming DNS requests to the most appropriate regional endpoint based on routing methods such as performance, geographic, weighted, or priority. It continuously monitors endpoint health and can automatically redirect traffic away from failed or overloaded regions, ensuring high availability and capacity-aware distribution across multiple VMs in different regions.

Why this answer

Azure Traffic Manager is a DNS-based traffic load balancer that distributes traffic to the nearest region with available capacity using the Performance traffic-routing method, and it automatically fails over to the next healthy endpoint when a region becomes unhealthy. It operates at the DNS level, returning the appropriate endpoint IP based on the client's DNS resolver location and endpoint health probes, making it ideal for stateless web applications requiring a single DNS endpoint across regions.

Exam trap

The trap here is that candidates often confuse Azure Front Door (Layer 7, HTTP/HTTPS) with Traffic Manager (DNS-based, any protocol), but the requirement for a single DNS endpoint and region-level failover without specifying HTTP makes Traffic Manager the correct choice.

How to eliminate wrong answers

Option B (Azure Front Door) is wrong because it is an HTTP/HTTPS application delivery controller that provides global load balancing with SSL offload and path-based routing, but it operates at Layer 7 and requires HTTP traffic, whereas the question does not specify HTTP-only traffic and Traffic Manager works at DNS level for any protocol. Option C (Azure Load Balancer) is wrong because it operates at Layer 4 and distributes traffic only within a single region, not across multiple Azure regions. Option D (Azure Application Gateway) is wrong because it is a regional Layer 7 load balancer with HTTP/HTTPS features and cannot route traffic across multiple regions or provide global failover.

144
MCQeasy

A company is deploying a multi-tier web application on Azure VMs. The web tier must be accessible from the internet, while the application and database tiers must be isolated within the virtual network. The solution must provide SSL termination, web application firewall (WAF) capabilities, and URL-based routing. Which Azure service should they use to expose the web tier?

A.Use an Azure Load Balancer and configure NSGs on each subnet.
B.Use Azure Firewall to inspect all traffic and allow internet traffic to the web tier.
C.Use Azure Application Gateway with WAF, and configure NSGs to restrict traffic between tiers.
D.Use Azure Front Door to expose the web tier and NSGs for internal isolation.
AnswerC

Azure Application Gateway is a Layer 7 regional load balancer that provides SSL termination, WAF, URL-based routing, and cookie-based session affinity, making it the appropriate entry point for the web tier. By enabling WAF, it actively blocks common web vulnerabilities such as SQL injection and cross-site scripting before they reach the backend. Complementing this with NSGs on each subnet enforces network-level isolation, ensuring that only the web tier can communicate with the app tier on specific ports (e.g., 8080/tcp) and that the app tier cannot initiate outbound connections to the internet. This combination of application-layer protection and subnet-level access control exactly matches the requirement to restrict traffic between tiers while securely exposing the web tier.

Why this answer

Azure Application Gateway is a Layer 7 load balancer that provides SSL termination, a web application firewall (WAF), and URL-based routing, making it ideal for exposing a web tier to the internet. By placing the gateway in front of the web tier and configuring network security groups (NSGs) on the application and database subnets, you can isolate internal tiers while meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming a basic load balancer can handle SSL termination and WAF, when in fact those features require Layer 7 capabilities.

How to eliminate wrong answers

Option A is wrong because Azure Load Balancer operates at Layer 4 and cannot perform SSL termination, WAF inspection, or URL-based routing; it only distributes traffic based on IP and port. Option B is wrong because Azure Firewall is a stateful Layer 3/4 firewall that does not provide SSL termination or URL-based routing, and it is not designed to act as a reverse proxy for web tiers. Option D is wrong because Azure Front Door is a global Layer 7 service that excels at CDN and cross-region routing but does not natively support URL-based routing within a single virtual network; it is typically used for global load balancing, not for internal tier isolation with NSGs.

145
MCQmedium

Your company has an Azure subscription that contains a hub virtual network and multiple spoke virtual networks connected via VNet peering. You need to ensure that all traffic between spokes is routed through a network virtual appliance (NVA) in the hub. The NVA is configured with IP forwarding enabled. What should you configure in the spoke virtual networks?

A.Deploy a VPN gateway in each spoke and configure site-to-site VPNs.
B.Configure NSG rules to block direct spoke-to-spoke traffic.
C.Add route tables to the spoke subnets with a default route (0.0.0.0/0) pointing to the NVA's private IP.
D.Enable BGP on the VNet peerings.
AnswerC

Adding route tables to the spoke subnets with a default route (0.0.0.0/0) pointing to the NVA's private IP is correct because it creates a user-defined route (UDR) that overrides the system route for peered VNets. When the next hop type is set to 'Virtual appliance' and the NVA's private IP is specified, all outbound traffic from that subnet—including traffic destined for other spoke VNets—is forced through the NVA in the hub. This works because UDRs take precedence over the automatically propagated routes from VNet peering. To ensure spoke-to-spoke traffic flows correctly, the NVA must have IP forwarding enabled, and the hub subnet containing the NVA must allow the traffic.

Why this answer

Adding a route table to the spoke subnets with a default route (0.0.0.0/0) pointing to the NVA's private IP forces all outbound traffic from the spoke, including traffic destined for other spokes, to be forwarded to the NVA. The NVA, with IP forwarding enabled, can then inspect and route the traffic to the target spoke. This ensures the desired traffic flow through the hub without requiring any changes to the VNet peering configuration.

Exam trap

The trap here is that candidates often confuse NSG rules (which filter traffic) with route tables (which direct traffic), leading them to choose Option B, but NSGs cannot force traffic through an NVA—they only allow or deny traffic at the subnet or NIC level.

How to eliminate wrong answers

Option A is wrong because deploying a VPN gateway in each spoke and configuring site-to-site VPNs would create a mesh of encrypted tunnels between spokes, bypassing the NVA entirely and adding unnecessary complexity and cost. Option B is wrong because NSG rules block traffic at the network layer but do not redirect traffic; they would drop spoke-to-spoke traffic rather than route it through the NVA, which does not meet the requirement. Option D is wrong because enabling BGP on VNet peerings is not supported in Azure; BGP is used with VPN gateways or ExpressRoute, not with VNet peering, and it cannot force traffic through an NVA.

146
MCQeasy

A company has multiple Azure virtual networks (VNets) in different regions. They want to connect all VNets to each other securely over the Microsoft backbone network, and also connect to their on-premises data center via ExpressRoute. What is the simplest Azure solution to enable connectivity between all VNets and on-premises?

A.Azure Virtual WAN
B.VNet peering
C.ExpressRoute
AnswerA

Azure Virtual WAN is a managed hub-and-spoke service built on the Microsoft global backbone. Each regional Virtual Hub automatically routes traffic between all connected VNets and branch sites (VPN or ExpressRoute) with transitive any-to-any connectivity, so a spoke VNet only needs to connect to its regional hub rather than peer directly with every other VNet. This design makes it the preferred solution when multiple VNets in different regions must communicate while also integrating on-premises connectivity without manual route management.

Why this answer

Azure Virtual WAN is the simplest solution because it provides a hub-and-spoke architecture that automatically connects all VNets and on-premises sites over the Microsoft backbone network. It natively integrates ExpressRoute and VPN gateways into a single managed service, eliminating the need to manually configure multiple peering or gateway connections.

Exam trap

The trap here is that candidates often assume VNet peering or a single ExpressRoute circuit can provide transitive connectivity between all VNets and on-premises, but they forget that VNet peering is non-transitive and ExpressRoute alone does not route between VNets without additional gateways or a hub.

How to eliminate wrong answers

Option B (VNet peering) is wrong because it only connects two VNets directly and does not provide transitive routing; to connect multiple VNets and on-premises, you would need a mesh of peerings and a gateway in each VNet, which is complex and not scalable. Option C (ExpressRoute) is wrong because it only connects on-premises to Azure, not VNets to each other; it requires additional gateways or peering to enable inter-VNet connectivity. Option D (VPN Gateway) is wrong because it only provides site-to-site VPN connectivity to on-premises, not transitive routing between VNets; you would need multiple VPN gateways and complex routing to connect all VNets.

147
MCQmedium

A company has Azure virtual networks (VNets) in three different Azure regions and an on-premises data center connected via ExpressRoute. They need to connect all VNets to each other and to on-premises over the Microsoft global backbone. They also require centralized management of routing and the ability to enforce security policies such as forced tunneling for internet-bound traffic. Which Azure service should they use?

A.Azure Virtual Network Manager
B.Azure Virtual WAN
C.Azure Firewall
D.Azure Route Server
AnswerB

Azure Virtual WAN is Microsoft's global transit networking service that builds a hub-and-spoke architecture with virtual hubs deployed in each region. Each virtual hub contains integrated VPN, ExpressRoute, and (optionally) Azure Firewall components, and the hubs are interconnected via Microsoft's high-speed backbone, enabling VNet-to-VNet, branch-to-VNet, and remote-user-to-VNet connectivity. It automatically manages routing tables, supports forced tunneling, and provides centralized policy management, making it the correct choice when you need reliable global transit between VNets in three different regions and on-premises connectivity.

Why this answer

Azure Virtual WAN is the correct choice because it provides a hub-and-spoke architecture that connects VNets across regions and on-premises via the Microsoft global backbone, with built-in centralized routing management and the ability to enforce security policies like forced tunneling through integrated Azure Firewall or third-party NVAs. It meets all requirements: multi-region VNet connectivity, ExpressRoute integration, and centralized policy control.

Exam trap

The trap here is that candidates often confuse Azure Virtual Network Manager (a connectivity configuration tool) with Azure Virtual WAN (a full SD-WAN solution), overlooking that Virtual WAN provides the actual routing, global transit, and integrated security enforcement required for multi-region and hybrid connectivity.

How to eliminate wrong answers

Option A is wrong because Azure Virtual Network Manager manages network group membership and connectivity configurations (like mesh or hub-and-spoke) but does not provide built-in routing management, forced tunneling, or direct integration with ExpressRoute for global backbone connectivity. Option C is wrong because Azure Firewall is a stateful firewall service that enforces security policies and forced tunneling, but it does not provide the underlying connectivity between VNets and on-premises or centralized routing management across regions. Option D is wrong because Azure Route Server enables dynamic route exchange between NVAs and Azure VNets but does not provide the global connectivity fabric, centralized routing management, or forced tunneling enforcement required for multi-region and on-premises integration.

148
MCQmedium

A company deploys a web application on Azure VMs across multiple availability zones in the East US region. They need to distribute incoming HTTPS traffic across the VMs, offload SSL termination, and ensure that client requests from the same user session are sent to the same backend VM (session persistence). Which Azure load balancing solution should they choose?

A.Azure Application Gateway v2 with cookie-based affinity
B.Azure Load Balancer Standard with source IP affinity
C.Azure Traffic Manager with performance routing
D.Azure Front Door with session affinity
AnswerA

Azure Application Gateway v2 is the correct choice because it operates at Layer 7, allowing it to terminate SSL/TLS and inspect HTTP headers and cookies. With cookie-based affinity, the gateway sets a session cookie to bind a client to the same backend VM for the duration of the session, which is essential for stateful web applications. Additionally, v2 supports zone-redundant deployment, enabling automatic distribution of traffic across VMs placed in different availability zones.

Why this answer

Azure Application Gateway v2 is the correct choice because it is a Layer 7 load balancer that can offload SSL termination, distribute HTTPS traffic, and support cookie-based session affinity (also known as sticky sessions). Cookie-based affinity ensures that all requests from the same user session are routed to the same backend VM by injecting an Application Gateway-managed cookie into the client's response. This meets all three requirements: HTTPS traffic distribution, SSL offloading, and session persistence.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer (Layer 4) with Application Gateway (Layer 7), assuming that 'session persistence' alone is enough, but they overlook the explicit requirement for SSL termination, which only a Layer 7 solution like Application Gateway can provide.

How to eliminate wrong answers

Option B is wrong because Azure Load Balancer Standard operates at Layer 4 (TCP/UDP) and cannot offload SSL termination; it also supports source IP affinity for session persistence, but that is not cookie-based and does not handle HTTPS termination. Option C is wrong because Azure Traffic Manager is a DNS-level traffic router that does not perform SSL termination or session persistence; it only directs traffic based on routing methods like performance, priority, or geographic, and does not inspect HTTP/HTTPS payloads. Option D is wrong because Azure Front Door does support session affinity and SSL offloading, but it is a global load balancer and CDN service designed for multi-region distribution, not for distributing traffic across VMs within a single Azure region (East US) across availability zones; it adds unnecessary latency and complexity for a regional-only deployment.

149
MCQhard

You are designing a governance strategy for multiple Azure subscriptions. You need to ensure that all resources in a specific subscription are deployed only in the West US region. Additionally, any new resource group must contain a tag named 'Environment' with a value of 'Production'. What combination of Azure Policy initiatives should you assign?

A.Assign the 'Allowed Locations' policy to the management group and the 'Require a tag on resource groups' policy to the subscription
B.Assign the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy to the subscription
C.Assign the 'Allowed Locations' policy to the subscription and the 'Inherit a tag from the resource group' policy to the management group
D.Assign a single Azure Policy definition that includes both the allowed location and require tag effects
AnswerB

This is correct because both policies are assigned at the subscription scope, directly targeting the specific subscription that needs governance. 'Allowed Locations' restricts where resources can be deployed, and 'Require a tag on resource groups' mandates that each resource group carry a required tag, satisfying the dual constraints of location and tagging without affecting other subscriptions.

Why this answer

It assigns both the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy directly to the subscription. The 'Allowed Locations' policy restricts resource deployment to the West US region, while the 'Require a tag on resource groups' policy ensures that every new resource group includes the 'Environment' tag with a value of 'Production'. Assigning both policies at the subscription scope meets both requirements without unnecessary inheritance or scope issues.

Exam trap

The trap here is that candidates often confuse the 'Require a tag on resource groups' policy with the 'Inherit a tag from the resource group' policy, mistakenly thinking inheritance will enforce the tag on the resource group itself, when in fact inheritance applies tags to resources within the group, not to the group itself.

How to eliminate wrong answers

Option A is wrong because assigning the 'Allowed Locations' policy to the management group would apply the restriction to all subscriptions under that management group, not just the specific subscription, and the 'Require a tag on resource groups' policy at the subscription level is correct but the location policy scope is too broad. Option C is wrong because the 'Inherit a tag from the resource group' policy applies tags from the resource group to its resources, not to the resource group itself, so it does not enforce the required tag on the resource group. Option D is wrong because there is no single Azure Policy definition that combines both the 'Allowed Locations' and 'Require a tag on resource groups' effects; these are separate policy definitions that must be assigned individually.

150
Multi-Selectmedium

Which TWO Azure services can be used to provide a fully managed DNS solution that supports custom domains and DNSSEC?

Select 1 answer
A.Azure Front Door
B.Azure DNS
C.Azure Traffic Manager
D.Azure App Service
E.Azure Public IP address
AnswersB

Correct. Azure DNS is a fully managed DNS service that supports custom domains (via DNS zone delegation) and DNSSEC, providing secure and authoritative name resolution.

Why this answer

Azure DNS is a fully managed DNS hosting service that provides name resolution using Microsoft Azure infrastructure and supports custom domains via DNS zone delegation. Azure DNS DNSSEC support is currently limited (preview/not generally available for all scenarios). However, the stem asks for TWO services, and only Azure DNS among the listed options is a full DNS hosting solution.

Azure Front Door and Traffic Manager provide DNS-based traffic routing but are not DNS hosting services and do not support DNSSEC zone management. Azure App Service and Azure Public IP addresses do not provide DNS hosting. Because only one option satisfies the criteria, the question as written is invalid and should be reworded to ask for a single service.

Exam trap

Candidates often mistake Azure Front Door or Traffic Manager for DNS hosting services because they use DNS-based routing, but neither provides full DNS zone management or DNSSEC support. The real trap is recognizing that only Azure DNS is a managed DNS hosting service among these options.

← PreviousPage 2 of 4 · 241 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure Solutions questions.