AZ-305 Sample Questions

AZ-305 Sample Questions & Answers

Expect questions on designing compute architecture and an application's overall design, migrations, backup and high-availability planning, storage for relational and unstructured data plus integration, and identity, governance and monitoring solutions.

Launch the full AZ-305 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Design identity, governance, and monitoring solutions · Recommend a solution that securely stores passwords and secrets

    A development team is building a new serverless application using Azure Functions. The application needs to store connection strings, API keys, and other secrets securely. The team wants to follow the principle of least privilege and avoid storing secrets in application settings or source code. The Azure Functions must be able to retrieve these secrets at runtime automatically using their identity.

    What is the most secure and recommended approach for managing these secrets?

    Show answer & explanation

    Correct answer: A

    This is the definitive best practice for secrets management in Azure. Storing secrets in Azure Key Vault provides a secure, centralized, and auditable secrets store. By enabling a system-assigned managed identity for the Function App and granting it 'Get' permissions on the secrets in Key Vault, the function can securely access the secrets at runtime without any credentials being stored in its code or configuration. This leverages Azure AD for authentication and adheres to the principle of least privilege.

  2. Question 2Advanced

    Design identity, governance, and monitoring solutions · Recommend an organizational and hierarchical structure for Azure resources

    An enterprise is planning to deploy a large number of applications in Azure, organized into multiple subscriptions for different business units. The CIO wants to ensure that all deployed resources comply with corporate standards from the moment they are created. The standards include a mandatory cost center tag, deployment only in specific Azure regions, and the automatic deployment of the Log Analytics agent on all VMs. The solution must be repeatable and version-controlled.

    Which Azure service is best suited for defining and assigning this comprehensive package of governance artifacts?

    Show answer & explanation

    Correct answer: A

    Azure Blueprints are designed for this exact purpose. A blueprint is a package that bundles related artifacts like Azure Policy assignments, Role-Based Access Control (RBAC) assignments, and Azure Resource Manager (ARM) templates. This allows the organization to define a repeatable set of standards and configurations that can be assigned to multiple subscriptions. Blueprints can be versioned, enabling tracking and auditing of changes to the governance standards over time.

  3. Question 3Intermediate

    Design data storage solutions · Recommend a solution for storing non-relational data

    You are designing the storage for a new cloud-native application that will process large volumes of unstructured data, including images and videos. The application requires a hierarchical namespace to manage files in a directory-like structure for big data analytics workloads (e.g., Spark, Databricks). It also needs to be cost-effective and support fine-grained, POSIX-like access control lists (ACLs).

    Which Azure Storage solution should you recommend?

    Show answer & explanation

    Correct answer: A

    Azure Data Lake Storage (ADLS) Gen2 is the ideal solution. It is built on top of Azure Blob Storage but adds a hierarchical namespace, which allows for organizing data into directories and subdirectories, providing significant performance benefits for analytics workloads. It also supports Azure AD integration and POSIX-like ACLs for fine-grained security at the file and folder level, meeting all the specified requirements.

  4. Question 4Advanced

    Design infrastructure solutions · Recommend a load balancing and routing solution

    A company is designing a global web application with users in North America, Europe, and Asia. The application consists of a web front-end and a set of backend APIs. The company has the following requirements:

    • Provide a single, global endpoint for users (e.g., www.contoso.com).
    • Route users to the closest Azure region hosting the application to minimize latency.
    • Implement a Web Application Firewall (WAF) to protect against common web vulnerabilities.
    • Terminate SSL at the edge and manage certificates centrally.

    Which Azure service should be used to meet all these requirements?

    Show answer & explanation

    Correct answer: A

    Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It provides a single global endpoint, uses anycast to route users to the nearest point of presence (POP), includes a built-in WAF, and handles SSL termination. It is specifically designed to meet all the listed requirements for a modern global web application.

  5. Question 5Intermediate

    Design business continuity solutions · Design for high availability

    A company has an Azure SQL Database with a service level objective of General Purpose, Gen5, 8 vCores. The database supports a critical business application. The company's business continuity plan requires a Recovery Point Objective (RPO) of less than 5 seconds and a Recovery Time Objective (RTO) of less than 30 seconds for regional outages. The plan also requires that the failover process be manageable through a single endpoint for both the primary and secondary databases.

    Which feature should you configure to meet these requirements?

    Show answer & explanation

    Correct answer: A

    Auto-failover groups are designed for this exact scenario. They manage the replication and failover of a group of databases to a secondary region. They provide a listener endpoint (one for read-write and one for read-only traffic) that remains constant, automatically redirecting traffic to the new primary after a failover. This meets the single endpoint requirement. Failover groups use active geo-replication underneath, which offers a low RPO (typically under 5 seconds) and a low RTO (under 30 seconds for automatic failover), satisfying the business continuity requirements.

  6. Question 6Intermediate

    Design infrastructure solutions · Recommend a solution to optimize network security

    A company is deploying a multi-tier application to Azure. The architecture consists of web servers, application servers, and a database. The security team wants to segment the network and control traffic flow between the tiers. They have the following rules:

    • Web servers should only be able to communicate with application servers on port 443.
    • Application servers should only be able to communicate with the database server on port 1433.
    • The database server should not be able to initiate connections to the web or application servers.

    You want to implement these rules using the simplest possible mechanism. Which combination of Azure networking components should you use?

    Show answer & explanation

    Correct answer: A

    This is the standard and most straightforward design for network segmentation within Azure. Creating a subnet for each tier provides logical isolation. Applying Network Security Groups (NSGs) with specific inbound and outbound rules to each subnet allows for fine-grained control of traffic flow between the tiers, directly implementing the required security rules at the network layer.

  7. Question 7IntermediateSelect 2

    Design identity, governance, and monitoring solutions · Design a log routing solution

    You are designing a solution to collect and analyze logs from hundreds of Azure resources, including VMs, App Services, and Storage Accounts. The solution must meet the following requirements:

    • Provide a centralized repository for all logs.
    • Enable complex log queries using a rich query language.
    • Create alerts based on log data patterns.
    • Retain logs for 90 days for active analysis and up to 2 years for compliance.

    Which two Azure services should you design the solution around? Each correct answer presents part of the solution.

    Show answer & explanation

    Correct answers: A, B

    An Azure Monitor Logs (Log Analytics) workspace is the primary service for aggregating and analyzing log and performance data from Azure resources. It provides the centralized repository, uses the powerful Kusto Query Language (KQL) for complex queries, and has a robust alerting engine. It perfectly fits the core requirements for analysis and alerting.

    While Log Analytics can retain data, it's more cost-effective to use an Azure Storage account for long-term archival. Diagnostic settings on Azure resources can be configured to send logs to both a Log Analytics workspace for active analysis (90 days) and to a Storage Account for inexpensive, long-term retention (2 years) to meet compliance requirements.

  8. Question 8Advanced

    Design identity, governance, and monitoring solutions · Design identities and access for applications

    A company is migrating a legacy application to Azure. The application was designed to use Windows Integrated Authentication to authenticate users from an on-premises Active Directory. The company wants to publish this application to remote users over the internet without using a VPN. The remote users should be able to sign in using their Azure AD credentials and experience single sign-on (SSO). The solution must be able to translate the Azure AD-based authentication to the Kerberos-based authentication required by the application.

    Which Azure service should be used to meet these requirements?

    Show answer & explanation

    Correct answer: A

    Azure AD Application Proxy is designed to securely publish on-premises web applications to external users. For applications that use Windows Integrated Authentication, Application Proxy can be configured with Kerberos Constrained Delegation (KCD). This allows the Application Proxy connector to impersonate users and acquire Kerberos tickets on their behalf to access the application, effectively bridging the gap between modern cloud authentication (Azure AD) and legacy on-premises authentication (Kerberos).

  9. Question 9Intermediate

    Design business continuity solutions · Recommend a backup and recovery solution for compute

    You are designing a backup strategy for an Azure VM that runs a business-critical database server. The business requires the ability to restore the VM to a specific point in time with minimal data loss. Backups must be application-consistent to ensure the database can be recovered without corruption. The backups should be stored in a separate region for disaster recovery purposes.

    Which backup solution should you design?

    Show answer & explanation

    Correct answer: A

    Azure Backup is the native solution for backing up Azure VMs. It supports application-consistent backups using Volume Shadow Copy Service (VSS) on Windows, ensuring the database is in a consistent state. By configuring the Recovery Services vault to use geo-redundant storage (GRS), the backups are automatically replicated to a paired secondary region, providing protection against regional disasters. This combination meets all the stated requirements.

  10. Question 10Beginner

    Design infrastructure solutions · Recommend an appropriately sized compute solution based on workload requirements

    An organization is building a new application that will be deployed using containers on Azure Kubernetes Service (AKS). The application will consist of numerous microservices. They need to choose a compute node (VM) size for their AKS cluster. The primary goal is to minimize costs while ensuring that if a single node fails, the impact on the overall cluster capacity is minimized. The workloads are not memory or CPU intensive.

    Which strategy for selecting VM sizes for the AKS node pools should be recommended?

    Show answer & explanation

    Correct answer: A

    Using a larger number of smaller VMs (scaling out) provides better resilience and minimizes the impact of a single node failure. If one small node fails, only a small fraction of the total cluster capacity is lost, and the running pods can be rescheduled onto the many remaining nodes. This approach often provides a better cost-to-performance ratio for general-purpose container workloads compared to using a few large, expensive VMs.

Ready for the real thing?

The full AZ-305 simulator has every exam-style question, timed mode, and instant scoring.

Go to the AZ-305 simulator →