Microsoft Certified: Azure Developer Associate (AZ-204) practice questions
228 free questions with answers and explanations.
- 101.A client is developing a serverless application that needs to perform a long-running, multi-step business process. Each step of the process might take several minutes to complete, and the overall process needs to maintain state across these steps, handling potential failures and retries. The client wants to use Azure Functions. Which Azure Functions capability is best suited for this scenario?Connect to and consume Azure services and third-party services
- 102.A development team is building a new application that needs to integrate with a legacy on-premises system. The on-premises system exposes a SOAP web service that the new cloud-based application must consume. To simplify the integration, improve security, and standardize the API interface for the cloud application, the team wants to wrap the SOAP service with a RESTful API. Which Azure service is best suited for this task?Connect to and consume Azure services and third-party services
- 103.A company is developing a new microservices application. They need to implement a solution that allows multiple independent services to asynchronously process the same event without knowledge of each other. The solution must ensure reliable delivery and support complex routing based on event content. Which Azure service should they use?Connect to and consume Azure services and third-party services
- 104.A manufacturing company uses Azure IoT Edge devices to collect sensor data from machinery. This data needs to be processed locally on the Edge device to filter out noise and aggregate readings before being sent to the cloud for long-term storage and analytics. Which component of Azure IoT Edge allows for this local data processing?Connect to and consume Azure services and third-party services
- 105.A company is developing a system where a critical business process involves several steps, and each step is implemented as a separate Azure Function. The process requires guaranteed execution order, state persistence between steps, and the ability to restart from a specific failed step without reprocessing earlier successful steps. Which Azure Functions feature should be used to implement this process?Connect to and consume Azure services and third-party services
- 106.A developer needs to create a serverless API that can be accessed by both internal and external consumers. The API must support custom authentication, request validation, and caching to improve performance and reduce load on the backend service. Which Azure service should be used to achieve these requirements efficiently?Connect to and consume Azure services and third-party services
- 107.A development team is implementing an API using Azure API Management (APIM). They need to ensure that specific sensitive information (e.g., API keys, connection strings) used within APIM policies is not hardcoded and can be securely managed and rotated. Additionally, these values should be accessible to policies without exposing them directly in the policy XML. Which APIM feature, combined with an Azure security service, should they use?Monitor, troubleshoot, and optimize Azure solutions
- 108.A company uses Azure API Management (APIM) to expose its backend APIs. They are experiencing intermittent performance issues and higher-than-expected latency for certain API calls. They need to identify the specific policies or backend service calls within APIM that contribute most to the latency. Which APIM feature or Azure Monitor integration should they leverage to diagnose this issue effectively?Monitor, troubleshoot, and optimize Azure solutions
- 109.A development team is building a new e-commerce platform that uses Azure Cosmos DB as its primary data store. They anticipate high read volumes for product catalog data, which changes infrequently. To improve performance and reduce Cosmos DB costs, they decide to implement caching. Which caching strategy is most appropriate for this scenario?Monitor, troubleshoot, and optimize Azure solutions
- 110.A manufacturing company uses an IoT solution that sends telemetry data to Azure IoT Hub. An Azure Function processes these messages, stores some data in Azure Cosmos DB, and sends alerts via Azure Event Grid. The company observes that certain IoT devices are intermittently failing to send data, but the processing functions are not reporting any errors. They need to monitor the end-to-end flow from IoT Hub ingestion to Cosmos DB storage to identify where messages might be getting lost or delayed. Which Azure Monitor feature provides the most effective way to visualize and troubleshoot this multi-service flow?Monitor, troubleshoot, and optimize Azure solutions
- 111.A development team is building a serverless application using Azure Functions and needs to monitor custom business events and metrics within their function executions. They want to track specific user actions, internal processing steps, and calculated values to gain deeper insights into application behavior. Which Application Insights SDK method should they use to send these custom events and metrics?Monitor, troubleshoot, and optimize Azure solutions
- 112.A team is developing a new serverless application that processes telemetry data from IoT devices. The data is ingested into Azure Event Hubs, processed by an Azure Function, and then stored in Azure Cosmos DB. To ensure the solution can handle high throughput and maintain data integrity, you need to monitor the end-to-end latency and identify any bottlenecks between these services. Which Azure Monitor feature provides a distributed tracing capability to track requests across multiple services?Monitor, troubleshoot, and optimize Azure solutions
- 113.A company is using Azure API Management (APIM) to secure and publish its APIs. They have a requirement to restrict API access based on the calling client's IP address. Only requests originating from a specific range of internal IP addresses should be allowed to access a particular API, while all other requests should be rejected. Which APIM policy should be implemented to achieve this?Monitor, troubleshoot, and optimize Azure solutions
- 114.A financial services company is developing a new online banking application. The application processes sensitive customer transaction data and uses Azure Functions for various microservices. For auditing and security purposes, all HTTP requests to these Azure Functions must be logged, including request headers, body, and response status. The logging solution must be able to correlate requests across different microservices and provide real-time alerting for anomalies. Which Azure Monitor feature should you use to meet these requirements?Monitor, troubleshoot, and optimize Azure solutions
- 115.A financial analytics application uses Azure Cosmos DB to store time-series data. Developers need to troubleshoot performance issues related to slow queries and high Request Unit (RU) consumption. They want to identify which specific queries are consuming the most RUs and contributing to the performance bottlenecks. Which Azure Monitor feature integrated with Cosmos DB should they use to get detailed query metrics and optimize their queries?Monitor, troubleshoot, and optimize Azure solutions
- 116.An online gaming company uses Azure API Management (APIM) to manage access to its game server APIs. They need to ensure that only authenticated and authorized users can access the game server's `/play` endpoint. The authentication is handled by an external identity provider (IdP) that issues JWTs. After successful authentication, the IdP sends the JWT to the client. The client then includes this JWT in requests to the `/play` endpoint. Which APIM policy configuration should be applied to the `/play` operation to enforce this security requirement?Monitor, troubleshoot, and optimize Azure solutions
- 117.A company is experiencing intermittent performance issues with a legacy ASP.NET application hosted on Azure App Service. The application frequently accesses a SQL Database and occasionally makes calls to an external third-party API. You need to implement monitoring to quickly identify the root cause of these performance issues. Which Azure Monitor feature should you leverage to visualize the end-to-end request flow and dependencies?Monitor, troubleshoot, and optimize Azure solutions
- 118.A developer is building a high-traffic web application that uses Azure Cosmos DB as its backend. To optimize costs and ensure consistent performance, the developer needs to monitor the Request Units per second (RU/s) consumption and provisioned throughput of the Cosmos DB account. They want to set up an alert that triggers if the consumed RU/s consistently exceeds 80% of the provisioned throughput for more than 5 minutes. Which Azure Monitor feature should be used to configure this alert?Monitor, troubleshoot, and optimize Azure solutions
- 119.A company uses Azure API Management (APIM) to expose its backend APIs. They want to ensure that only authorized client applications can consume these APIs. The client applications will authenticate using OAuth 2.0 and obtain JSON Web Tokens (JWTs) from an identity provider. You need to configure APIM to validate these JWTs before forwarding requests to the backend. Which policy should you implement in APIM?Monitor, troubleshoot, and optimize Azure solutions
- 120.A company uses Azure API Management (APIM) to expose several internal APIs to external partners. They need to implement a security measure that ensures only authorized clients can access specific API operations. This authorization should be based on claims embedded within a JSON Web Token (JWT) provided by the client. Which APIM policy should they use to enforce this requirement efficiently?Monitor, troubleshoot, and optimize Azure solutions
- 121.A retail company uses Azure API Management (APIM) to expose product catalog APIs to its mobile application. The company wants to implement a robust caching mechanism at the API Gateway level to reduce the load on backend services and improve response times for frequently requested product data. The caching solution must support invalidation when product data changes in the backend. Which APIM caching policy should be configured to meet these requirements?Monitor, troubleshoot, and optimize Azure solutions
- 122.You are developing a new microservice that relies on a backend data store. To improve response times and reduce the load on the database, you decide to implement a distributed cache. The cache needs to support high availability, scale out independently, and allow data to be shared across multiple instances of your microservice. Which Azure caching solution best meets these requirements?Monitor, troubleshoot, and optimize Azure solutions
- 123.A company is developing a new serverless application using Azure Functions. They are concerned about potential cold starts affecting the user experience, especially for HTTP-triggered functions. The application experiences unpredictable traffic patterns, with periods of inactivity followed by sudden spikes. Which Azure Functions hosting plan is designed to minimize cold starts while still offering a serverless experience and cost efficiency for variable loads?Monitor, troubleshoot, and optimize Azure solutions
- 124.A financial services company is developing a new online banking application in Azure. The application must process millions of transactions per day with extremely low latency, and data consistency is paramount. They are considering using Azure Cache for Redis to improve performance. Which caching strategy is most appropriate for their transaction processing requirements?Monitor, troubleshoot, and optimize Azure solutions
- 125.A software company is building a new microservices-based application. They are using Azure Cosmos DB as their primary data store. They anticipate extremely high read loads (millions of reads per second) for certain frequently accessed data, but updates to this data are infrequent. To offload Cosmos DB and ensure consistent low-latency reads, they decide to implement an in-memory cache. Which Azure caching solution is best suited for this scenario, considering its high throughput, low latency, and integration capabilities?Monitor, troubleshoot, and optimize Azure solutions
- 126.You are developing an Azure Function App that processes high volumes of incoming messages from an Azure Service Bus queue. The function is critical and must maintain low latency even during peak loads. You observe that during peak times, the function's execution time increases significantly, and messages start to back up in the queue. You suspect the function is being throttled or not scaling quickly enough. Which configuration change would directly address the function's ability to scale out rapidly to handle increased message processing?Monitor, troubleshoot, and optimize Azure solutions
- 127.A developer needs to configure Azure API Management (APIM) to transform the JSON response from a backend API. The backend returns a complex JSON object, but the client application only requires a subset of the fields and needs them renamed. You need to implement an inbound policy that efficiently performs this transformation. Which policy type is best suited for this task?Monitor, troubleshoot, and optimize Azure solutions
- 128.A logistics company uses Azure Functions to process incoming shipment updates. These functions occasionally encounter transient errors when connecting to a backend database or external APIs. These errors are usually resolved by retrying the operation after a short delay. The company wants to implement a robust retry mechanism within their Azure Function code to handle these transient failures gracefully without manual intervention. Which pattern should they implement?Monitor, troubleshoot, and optimize Azure solutions
- 129.You are supporting a critical Azure Web App that experiences intermittent performance degradation, especially during peak hours. Users report slow loading times and occasional timeouts. You need to identify the root cause of these issues by analyzing application performance and potential bottlenecks. Which Azure Monitor feature should you primarily use to collect detailed runtime data, dependency calls, and request performance metrics from the Web App?Monitor, troubleshoot, and optimize Azure solutions
- 130.A company is migrating an on-premises application to Azure. The application uses a custom caching layer that needs to be replaced with an Azure caching solution. The new cache must support both read-through and write-through caching patterns to simplify application code and keep the cache synchronized with the backend database. Which Azure caching service provides native support for these caching patterns?Monitor, troubleshoot, and optimize Azure solutions
- 131.A company has an Azure Function App that processes large image files uploaded to Azure Blob Storage. The function is triggered by new blob creation. Occasionally, the function fails due to memory exhaustion when processing extremely large and complex images. You need to implement a robust solution to handle these failures, ensuring that failed processing attempts are retried, but only for a limited number of times, and then moved to a dead-letter queue for manual inspection. Which combination of Azure services and practices should you use?Monitor, troubleshoot, and optimize Azure solutions
- 132.A healthcare provider is deploying a new patient portal application to Azure. The application's backend APIs are exposed through Azure API Management (APIM). Due to strict regulatory compliance, all API traffic must be routed through an Azure Application Gateway for Web Application Firewall (WAF) protection and then to APIM. APIM must then route traffic to backend services hosted in a private Azure Virtual Network (VNet). Which APIM deployment mode is required to ensure APIM can communicate with both the Application Gateway and the private VNet backend services?Monitor, troubleshoot, and optimize Azure solutions
- 133.A media company uses Azure Blob Storage to store large video files and Azure Functions to process them (e.g., transcoding, thumbnail generation). They notice that during peak upload times, the Azure Functions are sometimes delayed in processing new blobs, even when the Function App scale out is enabled. The company wants to optimize the processing speed and ensure that functions are triggered immediately upon blob creation, minimizing latency. Which type of Azure Functions trigger should be used to achieve the lowest possible latency for processing new blobs?Monitor, troubleshoot, and optimize Azure solutions
- 134.You are managing an Azure API Management (APIM) instance that exposes several critical backend APIs. To enhance security, all backend APIs require client certificates for mutual TLS authentication. You need to configure APIM to present a client certificate when making calls to the backend. What is the correct sequence of steps to upload and associate a client certificate with a backend API in APIM?Monitor, troubleshoot, and optimize Azure solutions
- 135.A global e-commerce platform uses Azure Front Door to route traffic to its backend web applications. They have configured an Azure Function App to handle user authentication requests. During peak traffic events, the Function App experiences high CPU utilization and occasional HTTP 503 errors. The team needs to ensure the Function App can scale rapidly and predictably to handle sudden spikes in authentication requests, while minimizing cold start times. Which Azure Functions hosting plan is most suitable for this requirement?Monitor, troubleshoot, and optimize Azure solutions
- 136.A global e-commerce company uses Azure Front Door to route traffic to its backend web applications, which are hosted as Azure App Services. They want to implement caching at the edge to reduce latency for static content (images, CSS, JavaScript files) and decrease the load on their backend App Services. Which Azure Front Door feature should they configure to achieve this?Monitor, troubleshoot, and optimize Azure solutions
- 137.A company is developing an Azure Function App that needs to interact with an Azure Storage Account to read and write blobs. The security team has mandated that the Function App must use a managed identity for authentication to the Storage Account and that access should be restricted to specific blob containers. Which Azure RBAC role, scoped to the specific blob container, should be assigned to the Azure Function App's managed identity to provide the necessary permissions while adhering to the principle of least privilege?Implement Azure security
- 138.A company is developing an Azure Function App that processes sensitive customer data. The function needs to store connection strings and API keys securely. Which Azure service should be used to manage these secrets?Implement Azure security
- 139.A developer is designing a system where an Azure Function App needs to publish messages to an Azure Service Bus topic. The Function App should have minimal necessary permissions. Which built-in Azure role should be assigned to the Function App's managed identity for this purpose?Implement Azure security
- 140.A company is developing a new serverless application using Azure Functions. The application will store customer data in Azure Cosmos DB. Due to strict compliance requirements, all data at rest in Cosmos DB must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. The Azure Function needs to be able to access the Cosmos DB account, which has been configured to use a system-assigned managed identity. The Cosmos DB account's Key Vault access policy has been configured to grant the Cosmos DB account's managed identity the `Get`, `Wrap Key`, and `Unwrap Key` permissions to the encryption key. Which of the following describes the most secure and appropriate method for the Azure Function to authenticate to Azure Cosmos DB to perform read/write operations?Implement Azure security
- 141.A developer is implementing role-based access control (RBAC) for an Azure Storage Account. A new custom role needs to be created that allows a specific Azure Function App to read and list blobs, but not write or delete them. Which `actions` property should be included in the custom role definition?Implement Azure security
- 142.A developer is implementing a RESTful API using Azure API Management (APIM) that exposes sensitive customer data. The API backend is hosted on an Azure App Service. To enhance security, all requests to the API must first be authenticated using OAuth 2.0 with Azure Active Directory (AAD) and then authorized based on roles assigned to the user. Which APIM policy should be used to enforce role-based authorization?Implement Azure security
- 143.A security team has mandated that all Azure Storage Accounts containing highly sensitive data must only be accessible from a specific Azure Virtual Network (VNet) and from a designated set of on-premises public IP addresses. Any access attempts from outside these approved sources must be blocked. The Storage Account will store blobs and files. Which combination of Azure networking features should be configured on the Storage Account to enforce this policy?Implement Azure security
- 144.A company is developing a new mobile application that will access an Azure API Management (APIM) instance. The mobile application needs to authenticate users and then use the resulting token to access the API. Which authentication method should the mobile application use to acquire the token from Azure AD?Implement Azure security
- 145.A developer is building a multi-tenant SaaS application on Azure. The application's backend API is secured with Azure Active Directory (AAD). When a new customer signs up, their AAD tenant needs to be able to authenticate users against the application. The application should dynamically discover the necessary AAD endpoints for each customer's tenant. Which Azure AD authentication approach is most suitable for this scenario?Implement Azure security
- 146.A developer is building a web API that exposes sensitive customer data. The API is hosted on Azure App Service. To protect against common web vulnerabilities such as SQL injection and cross-site scripting (XSS), which Azure service should be implemented in front of the App Service?Implement Azure security
- 147.A financial services company is developing a new serverless application using Azure Functions. The application will process highly sensitive customer financial data and must comply with strict regulatory requirements for data encryption at rest, including customer-managed encryption keys (CMEK). Which Azure storage encryption option should be used for the data stored by the Azure Function?Implement Azure security
- 148.A company is developing a new web API that exposes sensitive customer data. The API is hosted on an Azure App Service. To protect against common web vulnerabilities like SQL injection and cross-site scripting (XSS), and to inspect incoming traffic for malicious patterns, the security team requires a Web Application Firewall (WAF) to be deployed in front of the API. Which Azure service provides a WAF capability that can protect an Azure App Service?Implement Azure security
- 149.A company is migrating an on-premises application that uses Windows integrated authentication to Azure. The application needs to authenticate users against their existing Active Directory Domain Services (AD DS) without synchronizing user hashes to Azure AD. Which Azure AD service should be configured for this purpose?Implement Azure security
- 150.A developer is configuring Azure AD Conditional Access policies for a critical application. The goal is to enforce multi-factor authentication (MFA) for users accessing the application from outside the corporate network, but allow single sign-on (SSO) for users within the corporate network. Which combination of conditions and access controls should be used?Implement Azure security