Designing Microsoft Azure Infrastructure Solutions Free Sample Questions

20 free sample questions205 in the full practice test Other version: AZ-303(158)

Try simulator

AZ-305 Sample Questions

  1. Question 1

    A financial services company is designing a new three-tier application on Azure. The company has a strict security policy that requires all network traffic between the web, application, and data tiers to be inspected by a Network Virtual Appliance (NVA). The company also wants to centralize the management of this NVA and other shared services like DNS and Active Directory domain controllers. You need to design a network topology that meets these requirements.

    Which network design should you recommend?

    Answer and explanation

    Correct answer: A

    A hub-and-spoke topology is the recommended design for centralizing shared services and enforcing security policies. Placing the NVA and other shared services in the hub VNet allows for centralized management and inspection of all traffic. Each application tier can be isolated in its own spoke VNet, and user-defined routes (UDRs) can force all inter-spoke traffic through the NVA in the hub, meeting the inspection requirement. This design is scalable, cost-effective, and aligns with Azure best practices.

  2. Question 2

    A retail company is migrating its e-commerce platform to Azure. The platform experiences massive, unpredictable traffic spikes during flash sales. The product catalog is stored in an Azure SQL Database. During sales, the database becomes a bottleneck due to an extremely high volume of read operations. The company needs a solution that can handle the read traffic without requiring a permanent, expensive scale-up of the primary database. The solution must minimize changes to the application's data access layer.

    What is the most suitable solution to recommend?

    Answer and explanation

    Correct answer: A

    Read scale-out replicas are designed for read-heavy workloads. This feature allows you to provision one or more read-only replicas of the primary database. The application can then be configured to direct read-only queries (like browsing the product catalog) to these replicas, offloading the primary database to handle write transactions. This directly addresses the read bottleneck during traffic spikes without over-provisioning the primary database year-round. It is a built-in feature of Azure SQL Database Premium and Business Critical service tiers.

  3. Question 3

    An organization has deployed a critical application on a set of Azure Virtual Machines. The security team wants to ensure that administrative access (RDP and SSH) to these VMs is only possible from a secure, managed jump box and not directly from the internet. They also want to audit all administrative sessions. The solution should avoid exposing any public IP addresses on the VMs themselves.

    Which Azure service should be recommended to meet these requirements?

    Answer and explanation

    Correct answer: A

    Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP and SSH connectivity to your virtual machines directly through the Azure portal. It is deployed within a virtual network and allows access without exposing public IP addresses on the target VMs. All sessions are conducted over SSL, and it provides a centralized point of access that can be easily integrated with network security groups and Azure AD for enhanced security and auditing.

  4. Question 4

    A company has a hybrid cloud environment with resources both on-premises and in Azure. The governance team needs to enforce a consistent set of policies, such as requiring specific tags on resources and restricting deployments to certain regions, across both Azure and their on-premises servers. They want a single control plane to manage and audit compliance for all resources, regardless of their location.

    What Azure service should be the cornerstone of this governance design?

    Answer and explanation

    Correct answer: A

    Azure Arc extends the Azure control plane (Azure Resource Manager) to manage resources outside of Azure, including on-premises servers (Windows and Linux) and Kubernetes clusters. By onboarding on-premises servers to Azure Arc, they become Azure resources with a Resource ID. This allows you to apply Azure Policy, tagging, and other Azure management services to them, providing a unified governance and compliance solution across a hybrid environment from a single pane of glass.

  5. Question 5

    You are designing a disaster recovery strategy for a stateful application running in Azure Kubernetes Service (AKS). The application uses Azure Disks for persistent storage via Persistent Volumes (PVs). The business requires a Recovery Point Objective (RPO) of 4 hours and a Recovery Time Objective (RTO) of 8 hours. The disaster recovery site will be in a paired Azure region.

    You need to recommend a solution for backing up and restoring the application's state, including its Kubernetes objects and persistent data.

    Which solution should you recommend?

    Answer and explanation

    Correct answer: A

    Azure Backup for AKS is a native, enterprise-grade solution designed specifically for this scenario. It can back up and restore both the Kubernetes objects (deployments, services, etc.) and the persistent data stored in Persistent Volumes (backed by Azure Disks). It supports scheduled backups to meet the RPO and cross-region restore to meet the RTO, integrating directly with the Backup Vault and providing a centralized management experience.

  6. Question 6

    A development team is building a new serverless application using Azure Functions. The application needs to store connection strings, API keys, and other secrets securely. The team wants to follow the principle of least privilege and avoid storing secrets in application settings or source code. The Azure Functions must be able to retrieve these secrets at runtime automatically using their identity.

    What is the most secure and recommended approach for managing these secrets?

    Answer and explanation

    Correct answer: A

    This is the definitive best practice for secrets management in Azure. Storing secrets in Azure Key Vault provides a secure, centralized, and auditable secrets store. By enabling a system-assigned managed identity for the Function App and granting it 'Get' permissions on the secrets in Key Vault, the function can securely access the secrets at runtime without any credentials being stored in its code or configuration. This leverages Azure AD for authentication and adheres to the principle of least privilege.

  7. Question 7

    An enterprise is planning to deploy a large number of applications in Azure, organized into multiple subscriptions for different business units. The CIO wants to ensure that all deployed resources comply with corporate standards from the moment they are created. The standards include a mandatory cost center tag, deployment only in specific Azure regions, and the automatic deployment of the Log Analytics agent on all VMs. The solution must be repeatable and version-controlled.

    Which Azure service is best suited for defining and assigning this comprehensive package of governance artifacts?

    Answer and explanation

    Correct answer: A

    Azure Blueprints are designed for this exact purpose. A blueprint is a package that bundles related artifacts like Azure Policy assignments, Role-Based Access Control (RBAC) assignments, and Azure Resource Manager (ARM) templates. This allows the organization to define a repeatable set of standards and configurations that can be assigned to multiple subscriptions. Blueprints can be versioned, enabling tracking and auditing of changes to the governance standards over time.

  8. Question 8

    You are designing the storage for a new cloud-native application that will process large volumes of unstructured data, including images and videos. The application requires a hierarchical namespace to manage files in a directory-like structure for big data analytics workloads (e.g., Spark, Databricks). It also needs to be cost-effective and support fine-grained, POSIX-like access control lists (ACLs).

    Which Azure Storage solution should you recommend?

    Answer and explanation

    Correct answer: A

    Azure Data Lake Storage (ADLS) Gen2 is the ideal solution. It is built on top of Azure Blob Storage but adds a hierarchical namespace, which allows for organizing data into directories and subdirectories, providing significant performance benefits for analytics workloads. It also supports Azure AD integration and POSIX-like ACLs for fine-grained security at the file and folder level, meeting all the specified requirements.

  9. Question 9

    A company is designing a global web application with users in North America, Europe, and Asia. The application consists of a web front-end and a set of backend APIs. The company has the following requirements:

    • Provide a single, global endpoint for users (e.g., www.contoso.com).
    • Route users to the closest Azure region hosting the application to minimize latency.
    • Implement a Web Application Firewall (WAF) to protect against common web vulnerabilities.
    • Terminate SSL at the edge and manage certificates centrally.

    Which Azure service should be used to meet all these requirements?

    Answer and explanation

    Correct answer: A

    Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It provides a single global endpoint, uses anycast to route users to the nearest point of presence (POP), includes a built-in WAF, and handles SSL termination. It is specifically designed to meet all the listed requirements for a modern global web application.

  10. Question 10

    A company has an Azure SQL Database with a service level objective of General Purpose, Gen5, 8 vCores. The database supports a critical business application. The company's business continuity plan requires a Recovery Point Objective (RPO) of less than 5 seconds and a Recovery Time Objective (RTO) of less than 30 seconds for regional outages. The plan also requires that the failover process be manageable through a single endpoint for both the primary and secondary databases.

    Which feature should you configure to meet these requirements?

    Answer and explanation

    Correct answer: A

    Auto-failover groups are designed for this exact scenario. They manage the replication and failover of a group of databases to a secondary region. They provide a listener endpoint (one for read-write and one for read-only traffic) that remains constant, automatically redirecting traffic to the new primary after a failover. This meets the single endpoint requirement. Failover groups use active geo-replication underneath, which offers a low RPO (typically under 5 seconds) and a low RTO (under 30 seconds for automatic failover), satisfying the business continuity requirements.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 363 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon