70-532 Sample Questions

70-532 Sample Questions & Answers

Deploying and configuring ARM virtual machines carries the most weight, alongside PaaS compute such as Functions and App Service web apps, a storage and data strategy using blobs, tables and queues, and identity, messaging and communication services.

Launch the full 70-532 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Design and implement a storage and data strategy · Implement Azure storage tables and queues

    A developer is creating a custom retry policy for an application that interacts with Azure Table Storage. The policy must retry an operation only if a 'Conflict' (HTTP status code 409) is returned and the maximum number of retries has not been exceeded. All other HTTP status codes or exception types should cause the operation to fail immediately. Which condition correctly implements the logic to stop retrying if the status code is NOT a conflict?

    Show answer & explanation

    Correct answer: B

    The goal of a custom retry policy is to define the conditions under which it should retry. The method should return true to retry and false to fail. The requirement is to retry ONLY on a 409 Conflict. Therefore, if the status code is anything OTHER than Conflict, the method should return false to stop the retry loop.

  2. Question 2Intermediate

    Manage identity, application, and network services · Design and implement a messaging strategy

    You are architecting a solution that requires a messaging service for decoupling a front-end web application from a set of back-end processing services. Multiple, independent back-end services need to receive copies of the same message published by the front end. For example, when a new order is placed, one service should handle invoicing, another should update inventory, and a third should notify shipping. Each service must process the message independently. Which Azure messaging service provides this publish/subscribe functionality?

    Show answer & explanation

    Correct answer: B

    Azure Service Bus Topics and Subscriptions are designed for the publish/subscribe (pub/sub) pattern. The front-end publishes a single message to a topic. Multiple back-end services each listen on their own subscription to that topic, and each subscription receives a copy of the message. This allows for one-to-many message distribution. Service Bus Queues are for one-to-one delivery, and Event Hubs are for high-throughput event streaming, not individual message processing by distinct consumers.

  3. Question 3Intermediate

    Create and manage Azure Resource Manager Virtual Machines · Configure ARM VM networking

    You are tasked with securing an Azure VM that hosts a web server. The VM must be accessible from the internet on TCP port 443 (HTTPS), but all other inbound traffic from the internet should be denied. However, the VM must be able to communicate with other VMs in the same virtual network on all ports. Which Network Security Group (NSG) rule configuration is required to meet these requirements?

    Show answer & explanation

    Correct answer: B

    NSGs have default rules. One default rule allows all traffic from the 'VirtualNetwork' source. Another default rule with a high priority number (65500) denies all inbound traffic from the 'Internet'. To meet the requirements, you only need to add one new inbound rule with a lower priority number (e.g., 100) that allows traffic on port 443 from the 'Internet' source. This rule will be processed before the default deny rule, allowing HTTPS traffic while the default rules correctly handle VNet traffic and deny all other internet traffic.

  4. Question 4Beginner

    Design and implement a storage and data strategy · Manage access and monitor storage

    A developer needs to provide temporary, read-only access to a specific blob in an Azure Storage account for an external client application. The access should expire in 24 hours. The main storage account keys must not be shared with the client. Which security mechanism should be generated and provided to the client?

    Show answer & explanation

    Correct answer: B

    A Shared Access Signature (SAS) provides delegated access to resources in a storage account. It allows for granular control over permissions (read, write, delete), expiry time, and the specific resource (e.g., a single blob). This is the standard and secure way to grant temporary, limited access without exposing the account keys.

  5. Question 5Intermediate

    Create and manage Azure Resource Manager Virtual Machines · Manage ARM VM availability

    You are deploying a multi-tier application to Azure. The web tier consists of four VMs, and the business logic tier consists of two VMs. You need to ensure that a planned maintenance event by Microsoft does not cause an entire tier to become unavailable. How should you configure the VMs to achieve this goal?

    Show answer & explanation

    Correct answer: B

    The best practice for multi-tier applications is to place the VMs for each tier into their own separate Availability Set. An Availability Set distributes VMs across Update Domains and Fault Domains. By using separate sets, you ensure that planned maintenance (which targets one Update Domain at a time) will only affect a subset of VMs within a single tier, not across different tiers simultaneously. This maintains the availability of the entire application.

  6. Question 6Intermediate

    Manage identity, application, and network services · Design and implement a communication strategy

    An architect is designing a system where an on-premises application must securely invoke a service running in an Azure App Service Web App without exposing the service to the public internet. The solution must provide a secure, dedicated connection path from the on-premises network to the specific Azure App Service. Which Azure networking feature is designed for this purpose?

    Show answer & explanation

    Correct answer: C

    Azure App Service Hybrid Connections allow an Azure application to securely access on-premises resources. It also works in reverse, allowing an on-premises application to connect to an Azure App Service. It establishes a secure tunnel without requiring a VPN or firewall changes. VPN Gateway and ExpressRoute connect entire virtual networks to on-premises networks, which is more than is needed for this specific application-to-application scenario.

  7. Question 7Intermediate

    Design and implement a storage and data strategy · Implement Azure SQL Databases

    You are responsible for an Azure SQL Database that supports a mission-critical application. You must implement a disaster recovery solution that allows for failover to a secondary database in a different Azure region with a very low Recovery Point Objective (RPO) and Recovery Time Objective (RTO). The secondary database must be readable. Which feature of Azure SQL Database should you configure?

    Show answer & explanation

    Correct answer: C

    Active Geo-Replication is designed for disaster recovery. It creates a continuously synchronized, readable secondary database in a different region. It provides a low RPO (data loss) and RTO (time to recover) by allowing for quick, manual failover. Point-in-time restore is for recovering from accidental data deletion within the same region, and BACPAC export is a manual backup method with a much higher RPO.

  8. Question 8Intermediate

    Create and manage Azure Resource Manager Virtual Machines · Perform configuration management

    You are managing a fleet of Linux VMs in Azure. You need to automate the process of installing a specific version of the Apache web server and ensuring its configuration file has the correct settings on all VMs. The configuration should be applied automatically to new VMs and periodically checked for drift on existing VMs. Which Azure service or feature is the most appropriate tool for this declarative configuration management task?

    Show answer & explanation

    Correct answer: B

    Azure Automation State Configuration is a service built on PowerShell Desired State Configuration (DSC). It allows you to write declarative configurations that define the desired state of your VMs. The service then ensures that managed nodes (your VMs) are in that state, automatically correcting any configuration drift. Custom Script Extension is imperative (it runs a script once), not declarative, and does not handle drift.

  9. Question 9Intermediate

    Design and implement Azure PaaS compute and web and mobile services · Implement API management

    A developer needs to expose a set of existing backend REST APIs to external partners. The requirements are to enforce a rate limit of 100 calls per minute per partner, transform JSON responses to XML for a specific partner, and cache frequently requested data for 5 minutes. Which Azure service provides these capabilities as built-in policies?

    Show answer & explanation

    Correct answer: C

    Azure API Management is designed as a turnkey solution for publishing, securing, and managing APIs. It provides a rich set of out-of-the-box policies to handle common cross-cutting concerns, including rate limiting (throttling), response caching, and request/response transformations (like JSON to XML). Application Gateway is a web traffic load balancer, and Logic Apps is a workflow orchestrator; neither provides this comprehensive set of API gateway features.

  10. Question 10Intermediate

    Design and implement Azure PaaS compute and web and mobile services · Develop Azure App Service Mobile Apps

    You are developing a mobile application using Azure Mobile Apps as the backend. The app needs to support offline data synchronization, allowing users to create and modify data on their device even when disconnected from the internet. When connectivity is restored, the local changes must be synchronized with the backend database. What feature of the Azure Mobile Apps client SDK is essential for implementing this functionality?

    Show answer & explanation

    Correct answer: B

    The Azure Mobile Apps client SDKs include a specific feature called Offline Data Sync. This feature provides APIs to create a local store (typically an on-device SQLite database) and manage the synchronization of data between this local store and the remote backend. It handles queuing up local changes and pushing them to the server, as well as pulling down changes from the server.

Ready for the real thing?

The full 70-532 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 70-532 simulator →