All practice questions
1198 questions
EcoSphere Energy is designing a disaster recovery strategy for its energy consumption reporting application. The application stores monthly PDF reports in a general-purpose v2 Azure Storage account configured with Read-Access Geo-Redundant Storage (RA-GRS). During normal operations, the application writes reports to the primary region and reads them from both the primary and secondary regions.
During a prolonged outage in the primary region, the engineering team decides to initiate a customer-managed failover to the secondary region.
Which of the following describes the write capabilities and redundancy state of the storage account immediately after the customer-managed failover is completed?
An organization is designing a security and access control strategy for its Microsoft Entra ID tenant to protect cloud resources. You need to align the specific security requirements to the corresponding Microsoft Entra ID or Conditional Access features. Match each security requirement to the correct Microsoft Entra ID condition or session control.
Click a left item, then click its matching right item
Items
Matches
A logistics company is designing an access and governance strategy for its telemetry processing workloads in Azure. The workloads run within a single subscription across multiple resource groups. You need to design a solution that delegates administrative access to a team of operations engineers to manage Network Security Groups (NSGs) and route tables in a dedicated networking resource group, while also enforcing temporary, audited access for senior administrators who require the Owner role at the subscription level. The solution must adhere to the principle of least privilege.
Which two actions should you include in the design?
Select all that apply
A retail company stores transaction logs in an Azure General Purpose v2 (GPv2) storage account. The storage account is configured with Read-access geo-redundant storage (RA-GRS), with East US as the primary region and West US as the secondary region. To comply with regulatory audit requirements, the company's IT team plans to perform a disaster recovery drill by initiating a customer-managed failover of the storage account to the secondary region. Which two outcomes will occur once the failover is complete? (Select two.)
Select all that apply
Your company needs to host a serverless API endpoint that generates PDF reports. Each PDF generation request is CPU-intensive and takes up to 12 minutes to complete. The solution must scale dynamically and minimize administrative overhead. Which hosting option should you recommend?
An enterprise is designing a global disaster recovery and traffic routing solution for a hybrid system deployed across the Azure East US region and an on-premises datacenter in Paris. The system contains the following workloads:
* Workload 1: A legacy inventory database application that communicates over TCP port . This workload requires global failover based on client proximity, but does not support HTTP protocols.
* Workload 2: A public-facing e-commerce web application (HTTPS) that requires SSL termination at the edge, URL path-based routing to different backend pools, and web application firewall (WAF) protection.
You need to design a routing and failover strategy that minimizes latency and meets all technical requirements. Which two actions should you include in the design?
Select all that apply
A financial services company hosts an accounting application on an Azure Virtual Machine. The virtual machine uses Premium SSD v2 managed disks for its database and log volumes. You must design an Azure Backup solution that meets the following requirements:
* Backups must be taken multiple times per day to achieve a low recovery point objective (RPO).
* Quick recovery from local snapshots must be available for any data lost within the last 5 days.
* Backups must be kept in vault storage for 365 days to meet regulatory compliance.
Which two configurations must you include in the backup policy design? (Select two.)
Select all that apply
A medical diagnostics company is designing a container-based data processing solution on Azure. The solution will process patient telemetry records from multiple regions. The solution must satisfy the following requirements:
- The data processing tasks are short-lived, containerized workloads that run to completion and execute only when new telemetry records arrive in an Azure Service Bus queue.
- The compute infrastructure must automatically scale to zero when the queue is empty, and scale out dynamically based on the queue depth using Kubernetes Event-driven Autoscaling (KEDA).
- Administrative overhead associated with managing virtual machines, orchestrator nodes, and host patching must be minimized.
- Compliance regulations dictate that patient telemetry logs must be stored and isolated within their respective geographical regions (Europe and North America).
Which two configurations should you include in the design?
Select all that apply
An online education provider is designing a telemetry storage solution using Azure Cosmos DB for NoSQL to record real-time progress events from students globally. The solution must handle a write-heavy workload ( writes, reads) with an ingestion rate of thousands of events per second. The database must be replicated across three Azure regions to guarantee a read and write availability SLA. The primary query pattern retrieves all activity logs for a specific course to generate completion reports. You need to design a storage and security configuration that prevents hot partitions, ensures write scalability, and complies with security best practices. Which configuration should you recommend?
An administrator designs a virtual network named `vnet-corp-ops` with the address space . The virtual network contains a subnet named `snet-application` () and a security subnet named `snet-security` (). A network virtual appliance (NVA) is deployed in `snet-security` with the IP address .
To inspect internal traffic, the administrator creates a route table and associates it with `snet-application`. The route table contains a user-defined route for the prefix with a next hop type of Virtual Appliance and the next hop IP address set to .
How will Azure route traffic sent from a virtual machine in `snet-application` to a destination IP address of ?
An enterprise is designing a privileged access governance solution for its Azure environment. The solution must satisfy the following security and administrative requirements:
- Members of the operations team must only have permissions to manage virtual machines when performing scheduled maintenance tasks.
- Permissions to manage virtual machines must be assigned at scale to groups rather than to individual user accounts.
- Emergency access accounts must be protected from lockout risks associated with tenant-wide multi-factor authentication (MFA) policies.
Which two actions should you include in the design? (Choose two.)
Select all that apply
A financial services company is designing a subscription governance strategy for its transaction auditing platform. The auditing application runs across multiple resource groups within a dedicated Azure subscription. External audit administrators must be allowed to review resource configurations and database settings for a maximum of 8 hours during quarterly audit windows. To satisfy compliance, the solution must adhere to the principle of least privilege, minimize administrative overhead, and prevent permanent permission assignments. Which of the following designs best meets these requirements?
A marine logistics company is designing a storage solution for real-time cargo container tracking data. The data is stored in an Azure General Purpose v2 (GPv2) storage account. The design must satisfy the following requirements:
- The data must survive a regional disaster and remain available for read-only reporting in the secondary region without initiating a failover.
- The storage system in the primary region must tolerate the loss of an entire datacenter zone without data loss or service disruption.
- Tracking reports must be generated instantly, requiring sub-second retrieval times for all data stored in the account.
Which storage configuration should you recommend?
An organization is modernizing its application portfolio and migrating multiple databases to Azure Cosmos DB. You need to recommend the appropriate Azure Cosmos DB API for each application workload. Match each application workload description to its correct Azure Cosmos DB API.
Click a left item, then click its matching right item
Items
Matches
A financial services company is designing a storage solution to host shared configuration files for a containerized trading application. The application requires SMB file shares with sub-millisecond latency and high IOPS. The storage solution must remain available if a single availability zone in the primary region fails. Additionally, the company requires disaster recovery capabilities to recover the files in a secondary Azure region with a Recovery Point Objective (RPO) of 24 hours. You plan to use Azure File Sync to replicate files to the secondary region. Which redundancy configuration should you select for the primary Azure storage account to meet these requirements?
An enterprise designs a disaster recovery (DR) solution for a critical financial application hosted on Azure virtual machines (VMs) in the East US region, with West US as the target DR region.
The application architecture consists of:
* Two application tier VMs ( and ). Each VM has a write churn rate of .
* Two database tier VMs ( and ) running SQL Server. Each database VM has three Premium SSD disks: a data disk with write churn, a transaction log disk with write churn, and a TempDB disk with write churn.
The business requirements specify:
* The application tier requires a Recovery Point Objective (RPO) of and a Recovery Time Objective (RTO) of .
* The database tier requires an RPO of and an RTO of .
Which two actions should you include in the disaster recovery design?
Select all that apply
You are designing the hosting infrastructure for a new, simple containerized web application. The application needs to scale dynamically based on incoming HTTP traffic, and the development team wants to minimize operational overhead. Which two Azure compute options should you recommend? (Select two.)
Select all that apply
An enterprise designs a virtual network named `vnet-sea-prod` () to host a two-tier application. The virtual network contains the following subnets:
* `snet-app` () containing application servers
* `snet-data` () containing database servers
* `snet-shared` () containing a virtual firewall appliance with the IP address
The company's security policy requires that all traffic originating from the application servers in `snet-app` and destined for the database servers in `snet-data` must be inspected by the firewall. However, virtual machines within `snet-app` must be able to communicate directly with each other without routing through the firewall.
You need to design a routing solution that meets these requirements.
Which route should you add to a route table associated with `snet-app`?
An enterprise is designing a hub-and-spoke virtual network topology in Azure. The hub virtual network, `vnet-weur-hub` (address space: ), contains:
- An internal Azure Standard Load Balancer with a frontend IP address of that balances traffic across an active-active pair of network virtual appliances (NVAs).
- An Azure ExpressRoute Gateway in the `GatewaySubnet` () connected to an on-premises network that advertises the IP prefix .
The spoke virtual network, `vnet-prod-spoke` (address space: ), is peered with `vnet-weur-hub` with gateway transit enabled on the hub and remote gateway usage enabled on the spoke. The spoke virtual network contains two subnets:
- `snet-web` ()
- `snet-data` ()
You need to design a routing solution for the virtual machines in `snet-web` to satisfy the following requirements:
- All outbound traffic to the internet must pass through the NVAs for security inspection.
- Traffic to the on-premises network must bypass the NVAs and route directly through the ExpressRoute Gateway.
- Traffic between `snet-web` and `snet-data` must remain internal to the spoke virtual network and must not transit the hub or the NVAs.
- The design must minimize administrative overhead and avoid configuring redundant route entries.
Which three configuration actions should you include in the design? (Select three.)
Select all that apply
An organization uses an Azure Data Lake Storage Gen2 (ADLS Gen2) account with hierarchical namespace enabled to store transaction logs. You need to configure a lifecycle management policy to meet the following requirements:
- The logs must support high-throughput, sub-second read and write access for the first 30 days after creation.
- From day 31 through day 180, logs are queried occasionally for auditing and must be available with sub-second retrieval latency.
- From day 181 through day 1,095 (3 years), the logs are kept strictly for regulatory compliance and are rarely accessed. A retrieval latency of up to 15 hours is acceptable.
- After 1,095 days, the logs can be safely deleted.
- Storage costs must be minimized.
Which two actions should you include in the lifecycle management policy?
Select all that apply