WorksheetsAZ305 - Sept 2025
Total questions: 46
Worksheet time: 26mins
You have an Azure solution that uses the Azure Cosmos DB for MongoDB API.
You need to ensure that you can restore data in the solution to any point in time from the last 30 days by using a self-service solution.
Which backup solution should you use?
Azure Backup
Microsoft Azure Recovery Services (MARS)
Azure Cosmos DB Periodic backup
Azure Cosmos DB Continuous backup
You have an on-premises datacenter that connects to Azure by using ExpressRoute.
The on-premises datacenter uses Microsoft System Center Data Protection Manager (DPM) for backup and restore of on-premises Windows virtual machines.
You need to ensure that backups from the on-premises virtual machines are copied to Azure. The solution must use the minimum amount of administrative effort.
What should you recommend?
Deploy a DPM server in Azure.
Deploy Microsoft Azure Backup Server (MABS) to the on-premises network.
Install the Microsoft Azure Backup Server (MABS) agent on the DPM server.
Replace DPM with Microsoft Azure Backup Server (MABS).
You have an Azure subscription that contains Azure SQL databases.
You need to recommend a backup solution for the databases. The solution must ensure that the backups are configurable for at least 90 days.
What should you recommend?
Geo-zone-redundant storage (GZRS)
Locally-redundant storage (LRS)
Long-term retention (LTR)
Transaction log backups
You have five Azure SQL databases in a resource group named RG1. You have a Log Analytics Workspace named WS1. WS1 is configured to use resource-context access mode.
Databases in RG1 are configured to use WS1 for diagnostic logs.
A user named user1 needs to be able to review the logs for the databases in RG1.
Which role will you assign user1? The solution must follow the principle of least privilege.
Contributor role for RG1
Contributor role for WS1
Reader role for RG1
Reader role for WS1
You have an Azure subscription.
You plan to implement an Azure Key Vault. The solution must meet the following requirements:
Prevent the accidental deletion of keys, secrets, and certificates.
Prevent the deletion of the key vault, keys, secrets, and certificates in a configurable retention period.
Which two Key Vault features should you use to meet the requirements? Each correct answer presents part of the solution.
access policies
Key Vault firewall
Key Vault Premium tier
purge protection
soft delete
You use Microsoft Entra ID to manage users and their access to Azure-based resources.
After a security review, your organization wants to conditionally restrict access to resources based on a list of attributes.
You plan to use Conditional Access in Microsoft Entra ID.
To which three attributes can you apply conditions? Each correct answer presents a complete solution.
client process ID
device state
regional language
sign-in risk
IP Address
You have an application that runs on load-balanced Azure virtual machines. The application must access an Azure storage account and an Azure Key Vault.
You need to recommend an identity strategy for accessing Azure resources. The solution must meet the following requirements:
Secure access to the resources based on permissions.
Minimize the number of identities to create.
Which type of identity should you include in the recommendation?
Microsoft Entra ID groups
Microsoft Entra ID users
system-assigned managed identities
user-assigned managed identities
You need to design an identity solution for Azure virtual machines. The solution must meet with the following requirements:
Identities must be removed when virtual machines are deleted.
Identities cannot be shared among multiple virtual machines.
Which type of identity should you use?
Microsoft Entra groups
Microsoft Entra users
system-assigned managed identities
user-assigned managed identities
You need to design a solution to store keys used by an application hosted in Azure. The solution must meet the following requirements:
Be compliant with FIPS 140-2 Level 2
Be optimized for costs
Be fully managed
Which key management solution should you use?
Azure Key Vault Premium
Azure Key Vault Standard
Managed HSM
Self-hosted HSM
An application named App1 must access a stored password when connecting to a service named Service1.
You plan to use Azure Key Vault to store the password for Service1.
You need to recommend a solution to ensure that the password for Service1 is stored securely.
Which type of object should you create in Key Vault?
Certificate
Key
Secret
You are designing an Azure solution that contains the following resources:
A virtual network with an Azure firewall
A virtual machine scale set running an application
Two virtual machines that run Microsoft SQL Server
You need to provide management rights to different teams for the virtual network, scale set, and database servers. The solution must minimize administrative effort.
How should you organize the solution components?
Create a different management group for each solution component.
Create a different resource group for each solution component.
Create a different subscription for each solution component.
Create a different value on a tag for each resource in each solution component.
You need to recommend a solution that allows you to verify which Azure resources do not have tags. The solution must not block users from creating new resources.
What should you include in the recommendation?
Azure Policy with a disabled effect
Azure Policy with an audit effect
resource groups with a delete lock
resource groups with a read-only lock
Your organization has multiple Azure subscriptions and resource groups. You need to ensure that all resources are tagged with the 'Environment' tag to identify whether they are in development, testing, or production environments.
You implement a solution that automatically applies the 'Environment' tag to all new resources as they are created.
What do you do?
Use ARM templates to apply tags.
Use Azure Automation Runbooks to apply tags.
Use Azure CLI to apply tags.
Use Azure Policy for tagging rules.
Your organization migrates on-premises infrastructure to Microsoft Azure, requiring compliance with corporate governance policies.
You need to design a strategy to automate compliance checks and enforce policies across Azure resources.
Each correct answer presents part of the solution. Which three actions should you take?
Assign policies at a management group level.
Deploy Microsoft Azure Security Center.
Implement Microsoft Azure Policy.
Use Azure Logic Apps for compliance automation.
Use Microsoft Azure Cost Management.
Your organization has multiple Microsoft Azure subscriptions and needs to ensure compliance with specific security policies.
You need to design a governance strategy that enforces these security policies automatically across all subscriptions.
Each correct answer presents part of the solution. Which two actions should you perform? (Choose 2)
Apply security policies to each subscription individually.
Create a management group and apply security policies at this level.
Use Azure Blueprints to define and apply security policies across all subscriptions.
Use Azure Policy to define and assign security policies to the management group.
You are designing a solution that uses Azure SQL databases.
You need to ensure that the database solution meets the following requirements:
Has three IOPS per DTU
Uses columnstore indexing
Is optimized for costs
Which service tier should you use?
Basic
Premium
Standard S2
Standard S3
You have a Microsoft SQL Server application that uses SQL common language runtime (CLR) integration.
You need to migrate the application to Azure. The solution must minimize ongoing administration costs.
What should you use?
Azure Cosmos DB for NoSQL
Azure SQL Database
Azure SQL Managed Instance
SQL Server on Azure Virtual Machines
You are developing a new Microsoft SQL Server application that will run in Azure.
The application will use the spatial capabilities of SQL Server.
You need to recommend a SQL Server deployment option for the application. The solution must minimize ongoing administration costs.
What should you recommend?
Azure SQL Database
Azure SQL Managed Instance
SQL Server on Azure Virtual Machines
You are designing a data storage solution in Azure. The solution must meet the following requirements:
Provide read and write region replicas with eventual consistency.
Store non-relational data.
What should you include in the design?
Azure Cosmos DB
Azure SQL Database
Azure SQL Managed Instance
-
Azure Synapse Analytics
Your organization operates from locations in the United States, the United Kingdom, Australia, and Germany. Each location has employees that work with files stored in a File Share on Azure Storage.
You are designing the structure of the storage accounts. The accounts must meet the following requirements:
A single policy will enforce regulatory requirements.
Low IO latency is critical.
Costs must be minimized.
How many storage accounts should you create?
1
2
3
4
You need to design a file storage solution in Azure. The solution must meet the following requirements:
Provide the highest possible durability.
Remain available during a zone or Azure region failure.
Which type of redundancy should you use?
geo-redundant storage (GRS)
geo-zone-redundant storage (GZRS)
locally-redundant storage (LRS)
zone-redundant storage (ZRS)
You are designing the access control strategy for an Azure Data Lake Storage solution.
You need to ensure that users can only access folders and files based on access ACLs.
What should you include in the design?
Ensure that users are assigned the Contributor role only
Ensure that users are assigned the Owner role only
Ensure that users are assigned the Reader role only
Ensure that users are not assigned to the Reader, Contributor, or Owner roles.
You are designing the redundancy requirements for files stored in Azure Storage accounts.
You plan to store files that can be easily recreated.
You need to minimize storage cost.
Which type of redundancy should you include in the design?
geo-redundant storage (GRS)
geo-zone-redundant storage (GZRS)
locally-redundant storage (LRS)
read-access geo-zone-redundant storage (RA-GZRS)
You need to recommend a protection strategy for files stored in an Azure Storage account. The solution must meet the following requirements:
Protection must last for five years.
During the retention period, new objects can be created.
During the retention period, files must not be deleted or modified.
After the retention period, files can be deleted, but they cannot be modified.
What should you recommend using to apply the protection?
a legal hold policy
a delete lock
a time-based retention policy
A read-only lock
During the retention period of a time-based retention policy, files can be created and read, but they cannot be modified or deleted. When the retention period expires, files can be deleted but not modified. This meets the requirements.
Create a new Azure Synapse pipeline.
Create a new Azure Synapse SQL pool.
Enable Azure Synapse Link.
Install Azure Synapse Studio.
You have several on-premises Microsoft SQL servers installed on servers in your organization's factory.
You have an Azure Synapse Analytics pipeline that uses a self-hosted integration runtime to access the servers.
There is only a single on-premises virtual machine that can host the self-hosted integration runtime.
You need to create a new Azure Synapse Analytics workspace that has access to the data from the on-premises SQL servers. The workspace will be used by a different team and will have different administrators.
What should you do?
Add a SQL Server Integration Services (SSIS) integration runtime to Azure Data Factory.
Create all the required pipelines in the single Azure Synapse Analytics workspace.
Install a second self-hosted integration runtime on the on-premises server.
Migrate the pipelines to Azure Data Factory.
You need to design a data analysis solution in Azure that meets the following requirements:
Allows for data transformation
Links data to Microsoft Power BI
Performs near real-time log analysis
What should you use?
Azure Cosmos DB
Azure Data Factory
Azure SQL Manage Instance
Azure Synapse Analytics
You are designing an Azure virtual machines solution that has a frontend and a backend, each hosted in its own virtual machine scale set.
You need to ensure that the virtual machines from the frontend and backend communicate by using the lowest latency possible.
What should you include in the design?
application security groups
availability sets
availability zones
proximity placement groups
You are designing an Azure virtual machines solution to host a stateless application.
You need to ensure that the number of virtual machines used is increased and decreased automatically based on CPU usage.
What should you include in the design?
Azure API Management
Azure App Service
a load balancer with a virtual machine scale set
a load balancer with virtual machines
You have an on-premises Microsoft SQL Server deployment that you plan to migrate to Azure.
The SQL Server code regularly executes operating system commands by using the xp_cmdshell statement.
Performance metrics for the existing system show the following:
Average CPU is 45 percent.
Average disk I/O is 98 percent.
Which deployment option should you recommend for the migrated system?
Azure SQL Database
Azure SQL Managed Instance
Azure Storage-optimized virtual machine
Azure Memory-optimized virtual machine
You have an Azure subscription.
You plan to deploy a new application. The application design will include the use of messages between each application component.
You need to recommend a Message queue solution that meets the following requirements:
Supports a message size of 256 KB.
Groups messages into transactions.
Support automatic dead lettering.
What should you recommend?
Azure Event Grid
Azure Event Hubs
Azure Service Bus queue
Azure Storage Queue
You are designing a large-scale microservices-based application.
A message queue will be used to hold unprocessed messages. Each message will be processed once, and then deleted from the queue. Each message will be approximately 32 KB in size. At peak periods, up to 10 million messages might be unprocessed.
Which messaging service should you recommend for the application?
Azure Event Hubs
Azure IoT Hub
Azure Queue Storage
Azure Service Bus
Your organization manufactures breathing machines to assist patients with asthma.
You are creating a Microsoft Power BI dashboard to monitor the overall effectiveness of the machines across all users.
Each machine has built-in wireless internet connectivity and can send monitoring data to an online service. Azure Stream Analytics will be used to populate a streaming dataset in Power BI.
To which service should the breathing machines send data?
Azure Cosmos DB
Azure Event Hubs
Azure SQL Database
Azure Stream Analytics
You are designing a web app named WebApp1.
The headers and footers of the web pages delivered by WebApp1 will contain large amounts of static HTML.
You need to recommend a solution to provide the greatest responsiveness for WebApp1.
What should you include in the recommendation?
Azure Cache for Redis
Azure Load Balancer
Azure Traffic Manager
Azure WebApp Deployment Slots
You are planning to migrate your organization to Azure.
You are considering the migration effort for each workload based on the Microsoft Cloud Adoption Framework for Azure.
Which three phases should you design as part of the migration plan? Each correct answer presents part of the solution.
assess
deploy
govern
release
Test
You are planning a migration to Azure by using the Microsoft Cloud Adoption Framework for Azure.
You consider the implementation of innovative new solutions as critical to the outcome of the migration.
Which Microsoft Cloud Adoption Framework for Azure phase covers the implementation of innovative solutions?
adopt
govern
plan
ready
Your organization is migrating to Azure.
A web app named WebApp1 is critical to business operations, has limited functionality, and is based on technologies that are nearing end of support.
Creating new functionality in WebApp1 is slow and error prone. The existing code base for WebApp1 is complex, difficult to understand, and difficult to support.
Which Cloud Adoption Framework migration strategy should you consider for WebApp1?
rearchitect
rebuild
refactor
rehost
You need to design a networking solution to optimize connectivity from the internet to an Azure App Service web app. The solution must meet the following requirements:
Cache static objects.
Terminate SSL connections as close to the end user as possible.
Route traffic to the lowest latency Azure region hosting the web app.
What should you include in the design?
Azure Application Gateway
Azure Front Door
Azure Load Balancer
Azure Traffic Manager
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains two subnets named Subnet1 and Subnet2.
You plan to analyze all the outbound traffic from the subscription by using a third-party solution on a Network Virtual Appliance (NVA).
You need to recommend a connectivity solution to route all the outbound traffic.
What should you recommend?
Private endpoint
Service endpoint
User-defined route (UDR)
VPN gateway
You are designing a networking solution to optimize connectivity from the internet to a web app hosted in Azure. The solution must meet the following requirements:
Be available if an Azure region fails.
Route users to the closest region hosting the app.
What should you include in the recommendation?
Azure API Management
Azure Application Gateway
Azure Load Balancer
Azure Traffic Manager
You are planning a security solution for resources in Azure.
You need to recommend a solution to filter traffic between the resources in a single virtual network.
Which two services should you include in the recommendation? Each correct answer presents a complete solution.
a network security group (NSG)
a network virtual appliance (NVA)
Azure Front Door
Azure Traffic Manager
You are designing a hybrid network for an organizational migration to Azure. Some resources will be deployed to Azure. Other resources will remain on premises.
You need to recommend a solution to connect the on-premises network to Azure.
Which two services should you use to connect the networks? Each correct answer presents a complete solution.
Azure Firewall
Azure Load Balancer
Azure VPN Gateway
ExpressRoute
You have two subscriptions named Sub1 and Sub2 in an Azure tenant.
You need to connect a virtual network in Sub1 to a virtual network in Sub2.
Which two networking features should you recommend? Each correct answer presents a complete solution.
Azure Private Link
Virtual network peering
ExpressRoute
VPN gateways
You are designing the migration plan for an Amazon RDS database named DB1.
You plan to migrate DB1 to an Azure SQL managed instance.
You need to recommend a solution to automate the migration by using PowerShell. The solution must meet the following requirements:
Minimize the number of tools to be installed.
Minimize downtime.
Which migration tool should you recommend?
Azure Database Migration Service
Bulk Copy
Import/Export Wizard
the Azure SQL migration extension for Azure Data Studio
You plan to use a Log Analytics workspace to hold logs for Azure Monitor. The logs will be used for analytics and alerts. A single query must be able to correlate data from all the logs.
You estimate that the workspace will ingest around 8 TB of logs per day.
What should you do first?
Configure Log Analytics to use only Basic Logs.
Create a dedicated cluster.
You have five Azure SQL databases in a resource group named RG1. You have a Log Analytics Workspace named WS1. WS1 is configured to use resource-context access mode.
Databases in RG1 are configured to use WS1 for diagnostic logs.
A user named user1 needs to be able to review the logs for the databases in RG1.
Which role will you assign user1? The solution must follow the principle of least privilege.
Reader role for RG1
Reader role for RG1
