All practice questions
1198 questions
VeloStream Telematics is designing a disaster recovery solution for its vehicle telemetry platform. The platform continuously writes unstructured metrics to a General Purpose v2 storage account in the East US region.
The architecture team defines the following disaster recovery requirements:
- During an outage in East US, the telemetry data must remain available for read-only analytical queries in a secondary region with a Recovery Time Objective (RTO) of less than minutes.
- To avoid unnecessary data loss due to replication lag, a write failover to the secondary region must only be initiated if the primary region outage is expected to exceed hours.
- The solution must minimize overall storage costs.
Which configuration and failover strategy should you recommend?
A financial services company is designing a subscription governance strategy. The security team must delegate permissions to a cloud operations team to manage network security groups (NSGs) and route tables within a production subscription. The operations team members change frequently, and their access must only be active during their scheduled shifts and automatically expire after eight hours. The design must prevent the operations team from modifying virtual networks or assigning permissions to other users. Additionally, any new resource group created within the subscription must automatically have a delete resource lock deployed to prevent accidental deletion. Which design should you recommend to meet these requirements while minimizing administrative overhead?
A company plans to migrate an on-premises database to Azure. The database workload requires SQL Server Agent jobs and cross-database queries. The disaster recovery (DR) solution must support automatic failover to a secondary Azure region with a recovery time objective (RTO) of less than 1 hour. After a failover, the application must connect to the database in the secondary region using the same connection string without requiring manual configuration changes. Which database solution and disaster recovery feature should you recommend?
A financial services corporation is architecting a real-time transaction processing platform. The core processing tier will run on Azure Virtual Machines. The platform has the following infrastructure requirements:
- A virtual machine uptime Service Level Agreement (SVA) of 99.99%.
- Under 1 millisecond network latency between the active virtual machine nodes in each cluster partition to support memory-mapped replication.
- Complete protection against a localized datacenter power or cooling failure.
Which design should you recommend to meet these requirements?
Match each Azure traffic routing and load balancing service to its appropriate architecture requirement.
Click a left item, then click its matching right item
Items
Matches
An enterprise is designing a data storage and retention strategy for a new telemetry analytics application. The application will write data to an Azure Data Lake Storage Gen2 (ADLS Gen2) account.
The data requirements are structured as follows:
| Period | Access Frequency & Latency | Retention & Immutability |
|---|---|---|
| **Days –** | Frequently written and analyzed. Requires sub-second, low-latency access. | Must be mutable for real-time updates. |
| **Days –** | Rarely accessed. Must remain online for occasional queries with a retrieval latency of less than seconds. | Must be protected against deletion and modification. |
| **Days – ( years)** | Not accessed. Only kept for compliance audits. Retrieval latency of up to hours is acceptable. | Must be protected against deletion and modification for the first years ( days) from creation. |
You need to configure a lifecycle management policy and immutability settings that satisfy these requirements while minimizing storage costs and avoiding early deletion fees.
Which of the following configuration options should you recommend? (Select TWO).
Select all that apply
A smart grid utility provider is designing an analytical data platform on Azure to monitor electricity consumption. The platform must ingest real-time telemetry from 500,000 smart meters at a velocity of 10,000 events per second, totaling 12 TB of new data monthly. The architecture must satisfy the following requirements:
- The raw telemetry data must be stored in a data lake and remain highly available and resilient to regional datacenter outages.
- Data analysts must perform ad-hoc, exploratory SQL queries on years of historical Parquet files in the data lake without provisioning or paying for idle compute resources.
- External partners must be granted read access to the historical files securely, with the ability to revoke access immediately if needed.
Which two options should you recommend in the architectural design to meet these requirements?
Select all that apply
An enterprise is designing a compute and logging architecture for a containerized order-processing application. The design must satisfy the following requirements:
- Host multiple microservices that scale dynamically based on the queue depth of an Azure Service Bus queue using Kubernetes Event-driven Autoscaling (KEDA).
- Minimize the administrative and operational overhead associated with managing cluster infrastructure and virtual machines.
- Separate log data into different geographical regions to comply with strict regional data residency regulations.
Which compute and monitoring configuration should you recommend?
You are designing a backup and recovery solution for an Azure virtual machine that runs a critical middleware application. The virtual machine uses Premium SSD managed disks.
Your solution must satisfy the following technical requirements:
- Resilience: Backups must be recoverable even in the event of a complete disaster in the primary Azure region.
- Operational RTO: Any recovery of files or full virtual machines from backups created within the last 10 days must take less than 15 minutes.
- Retention: Backups must be kept for a total of 180 days to meet compliance regulations.
- Cost: Minimize overall storage and management costs.
Which backup vault type, storage redundancy, and policy configuration should you select to meet these requirements?
An enterprise is planning the deployment of an Azure landing zone. A team of fifteen external database consultants requires temporary administrative control over the resources in a production subscription to perform database schema updates. Security policy mandates that:
* Access must be granted on a temporary, just-in-time (JIT) basis.
* The administrative privilege must not exceed four hours per activation.
* All activation requests must be approved by an internal security lead.
* To maintain clean subscription-level access controls, privileges should not be assigned directly to individual consultant user accounts.
Which two configurations should you include in the privileged access and identity governance design? (Select TWO.)
Select all that apply
Contoso, Ltd. has an on-premises Active Directory Domain Services (AD DS) domain that synchronizes with a Microsoft Entra ID tenant. You are designing the identity security and hybrid authentication strategy for the organization. The design must meet the following requirements:
- Users must be able to authenticate to cloud applications even if the on-premises data center is offline.
- The security team must enforce multi-factor authentication (MFA) via Conditional Access policies for all users, but must ensure that administrators do not get locked out of the tenant in the event of a tenant-wide Entra ID MFA service outage.
Which two actions should you include in the design? (Select two.)
Select all that apply
A company is designing a high-availability storage solution in the Azure East US region. The solution will support a critical database application and has the following requirements:
1. The application's virtual machines run on Premium SSD managed disks. The disks must survive a zone failure within the primary region with zero data loss (RPO = 0).
2. The transaction logs are backed up to a standard General Purpose v2 storage account. These backups must survive a regional outage of the primary region.
3. The backup data must be readable in the secondary region at all times to allow a secondary reporting application to run audit reports without initiating a failover.
Which two storage configurations should you recommend to meet these requirements?
Select all that apply
An organization is designing a compute and monitoring solution for a new microservices-based application. The application will run in containers and must meet the following requirements:
- Support dynamic, event-driven scaling based on CPU utilization and Azure Service Bus queue depth.
- Minimize the administrative and operational overhead of the container infrastructure.
- Isolate log and telemetry data for two distinct departments (Finance and HR) into separate regulatory boundaries to satisfy strict data sovereignty requirements.
Which two configurations should you recommend in the design?
Select all that apply
An enterprise administrator needs to run a single containerized database maintenance script once per week. The container executes for approximately three minutes and then terminates. The solution must minimize deployment complexity and administrative overhead. Which Azure service should you recommend?
An organization is establishing a new governance model for their Azure environment. They need to delegate administrative permissions for managing virtual networks to a network operations team while adhering to the principle of least privilege. You need to configure a custom RBAC role and a new Management Group structure. Arrange the steps in the correct order to configure and delegate these permissions, starting with establishing the scope boundary and ending with granting user access.
Drag items to arrange them in the correct order
You are designing the data storage solution for a global micro-mobility fleet management system that tracks active electric scooters. The scooters report status updates, including battery level and GPS coordinates, every seconds. The read-to-write ratio is (write-heavy). The system must support multi-region write replication across East US, West Europe, and Southeast Asia to guarantee write latency below globally. The solution must survive a complete regional outage without data loss or downtime. Which design configuration meets these requirements while preventing hot partitions and ensuring regional disaster resilience?
A company named OrbitCargo Systems is designing a disaster recovery strategy for its critical flight cargo tracking application. The application stores transaction logs in an Azure Block Blob storage account that is currently configured with Read-Access Geo-Redundant Storage (RA-GRS). The primary region is East US, and the secondary region is West US.
During a simulated primary region outage in East US, the operations team needs to ensure that the tracking application can continue to read existing logs and write new transaction logs with minimal downtime. The solution must ensure that once the primary region becomes healthy again, data redundancy is maintained.
Which two actions should you include in the design to meet these requirements?
Select all that apply
A financial services startup is preparing for an annual regulatory audit of its Azure production environment. A third-party compliance team consisting of five auditors needs temporary access to view configuration settings across all resources in a subscription. You must design an identity governance solution that allows the auditors to self-service their access only when needed, enforces multi-factor authentication (MFA) upon activation, and minimizes administrative overhead. Which of the following solutions should you recommend?
An enterprise is designing a global traffic routing and failover strategy for workloads deployed in the East US and West Europe regions. The solution must support two distinct workloads:
1. A public-facing web application that requires Secure Sockets Layer (SSL) termination at the edge, URL path-based routing (mapping `/static/*` to Azure Storage and `/api/*` to regional application gateways), Web Application Firewall (WAF) integration, and a failover recovery time objective (RTO) of less than 30 seconds.
2. A database replication synchronization daemon that communicates using a custom TCP protocol over port 5432.
Which routing and failover architecture should you recommend to meet these requirements?
You are designing a backup solution for a critical production workload hosted on an Azure Virtual Machine. The virtual machine has the following configuration:
* Operating System: Windows Server 2025
* Disks: Multiple Premium SSD v2 managed disks
* Location: East US region
The backup solution must meet the following requirements:
* Backups must run daily.
* All backup data must be stored in a Recovery Services vault configured with Zone-Redundant Storage (ZRS).
* To meet a strict Recovery Time Objective (RTO) for operational recoveries, administrators must be able to perform instant file-level restores from local snapshots for any backup taken within the last 7 days.
* Backups must be retained in the vault for a minimum of 365 days.
You need to design the Azure Backup policy.
Which backup policy configuration should you recommend?