Microsoft Certified: DevOps Engineer Expert practice questions
209 free questions with answers and explanations.
- 101.A DevOps team is adopting an SRE strategy. They are faced with a legacy application that frequently experiences critical failures, consuming significant on-call team time. The current mean time to recovery (MTTR) for these failures is unacceptably high. Which SRE practice should they prioritize to MOST effectively reduce the MTTR for this legacy application?Implement a Site Reliability Engineering (SRE) strategy
- 102.A global SaaS provider uses Azure Front Door to route traffic to its multi-region application. The SRE team wants to implement a disaster recovery strategy that ensures continuous availability for users even if an entire Azure region becomes unavailable. The primary goal is to minimize user-perceived downtime and latency. Which disaster recovery pattern, coupled with Azure Front Door, would be MOST effective?Implement a Site Reliability Engineering (SRE) strategy
- 103.An SRE team is designing a disaster recovery plan for an application hosted on Azure. The application's data tier uses Azure SQL Database. The business requires an RPO (Recovery Point Objective) of 5 minutes and an RTO (Recovery Time Objective) of 1 hour. Which Azure SQL Database feature is MOST appropriate for meeting these requirements?Implement a Site Reliability Engineering (SRE) strategy
- 104.A team is implementing a new microservice on Azure Functions. To ensure reliability, they want to limit the impact of failures in downstream dependencies. Specifically, if a particular external API dependency becomes slow or unresponsive, they want to prevent it from causing cascading failures in their Azure Function, while still allowing other parts of the system to function normally. Which design pattern should they apply?Implement a Site Reliability Engineering (SRE) strategy
- 105.A DevOps team is responsible for a critical e-commerce application. They notice that during peak sales events, the application experiences intermittent slowdowns and a slight increase in error rates, despite scaling resources. These issues are difficult to reproduce in lower environments. To effectively identify the root cause and improve the application's resilience, which health monitoring strategy should they prioritize implementing?Implement a Site Reliability Engineering (SRE) strategy
- 106.A team is managing an Azure-based critical payment processing system. Their Service Level Objective (SLO) for processing latency is that 99.9% of payment transactions must complete within 500 milliseconds. During a recent incident, the system experienced a sustained period where 1% of transactions took longer than 1 second, and 0.5% failed outright. To improve the system's reliability and prevent similar incidents, the SRE team decides to implement a proactive failure detection strategy. Which of the following should be their PRIMARY focus for this strategy?Implement a Site Reliability Engineering (SRE) strategy
- 107.A DevOps team is developing a new microservice and needs to define its Service Level Objectives (SLOs). The microservice will handle critical customer authentication requests. Which of the following metrics is MOST appropriate to use as a Service Level Indicator (SLI) for the availability of this authentication microservice?Implement a Site Reliability Engineering (SRE) strategy
- 108.A healthcare startup is building a new patient portal on Azure, leveraging Azure App Service for web applications and Azure SQL Database for data storage. They need to implement a secure and efficient way to store and retrieve application secrets like database connection strings and API keys without embedding them directly in code or configuration files. This solution must also integrate with Azure DevOps for automated deployments. Which Azure service should they use?Implement an instrumentation strategy
- 109.A DevOps team is managing a complex microservices application deployed on Azure Kubernetes Service (AKS). They need to ensure that all custom metrics generated by their application, such as order processing rates and inventory levels, are collected and available for monitoring and alerting. These metrics should be stored in a centralized location for long-term analysis. Which Azure service should they use to ingest and store these custom application metrics?Implement an instrumentation strategy
- 110.A company uses Azure Kubernetes Service (AKS) for its containerized applications. They need to monitor the health and performance of their AKS clusters, including node CPU/memory utilization, pod status, and container logs. The monitoring solution must also provide insights into network performance within the cluster and support custom metrics from applications. Which Azure Monitor feature should be enabled and configured?Implement an instrumentation strategy
- 111.A company is migrating an on-premises application to Azure. The application currently uses a custom logging agent that writes logs to local files. The DevOps team wants to continue using this agent in Azure VMs but needs to centralize these logs for analysis in Azure Monitor Log Analytics. The solution must be scalable and robust. Which Azure Monitor component should be deployed to the Azure VMs to collect these custom local files and send them to Log Analytics?Implement an instrumentation strategy
- 112.A DevOps team wants to visualize the aggregated health and performance of their entire microservices application, which consists of multiple Azure App Services, Azure Functions, and Azure SQL Databases. They need a single pane of glass to quickly identify service dependencies and performance bottlenecks across the whole system. They also want to include custom metrics from their application code. Which Azure Monitor visualization tool is best suited for this comprehensive, end-to-end view?Implement an instrumentation strategy
- 113.A team is using Azure Monitor Workbooks to create interactive reports for their application. They need to display data from both Azure Monitor Metrics and Azure Monitor Logs within the same workbook, allowing users to switch between different time ranges and apply filters dynamically. The workbook should also support embedding external content, such as documentation links or custom HTML. Which feature of Azure Monitor Workbooks enables combining data from different sources and external content while providing interactive controls?Implement an instrumentation strategy
- 114.A company is implementing an Azure DevOps strategy for a new microservices application. They need to collect detailed performance metrics, application logs, and distributed trace information across multiple services written in different languages. The solution must support real-time diagnostics and facilitate quick identification of issues impacting end-users. Which Azure service is best suited to meet these requirements?Implement an instrumentation strategy
- 115.A financial services company uses Azure DevOps to manage its application lifecycle. They need to ensure that all changes to their production Azure infrastructure, such as virtual network configurations or firewall rules, are tracked and auditable. Specifically, they want to be alerted if any critical security-related resource is modified or deleted. Which Azure Monitor feature should be configured to meet this requirement?Implement an instrumentation strategy
- 116.A global e-commerce company uses Azure Front Door to manage traffic to its geographically distributed web applications. They need to monitor the health and performance of their Front Door instances, including metrics like HTTP request latency, data transfer, and backend health. They also require the ability to analyze security logs related to Web Application Firewall (WAF) policies. Which Azure Monitor integration should be configured for this purpose?Implement an instrumentation strategy
- 117.A team is developing a serverless application using Azure Functions and needs to implement distributed tracing to understand the end-to-end flow of requests across multiple functions and external services. The tracing should be integrated with Azure Monitor for visualization and analysis. Which approach should they use to implement distributed tracing for their Azure Functions?Implement an instrumentation strategy
- 118.A DevOps team is managing an Azure Kubernetes Service (AKS) cluster that hosts several critical applications. They need to implement a strategy to collect and analyze logs from all pods, containers, and Kubernetes nodes. The solution must provide a centralized view of all logs, allow for complex querying across namespaces and historical data, and support long-term retention for compliance. Which Azure service combination is best suited for this comprehensive logging strategy?Implement an instrumentation strategy
- 119.A development team is using Azure DevOps to manage their CI/CD pipelines. They want to ensure that any failures within their Azure Pipelines, such as failed build tasks or deployment errors, are immediately escalated to the responsible team. The escalation process should involve sending an email, posting a message to a Microsoft Teams channel, and creating a work item in Azure Boards. Which Azure DevOps feature should they configure to automate this multi-channel notification and action process?Implement an instrumentation strategy
- 120.A DevOps team needs to implement a comprehensive monitoring solution for a distributed application running on Azure. The application consists of several microservices, Azure Functions, and an Azure SQL Database. They require a centralized dashboard that displays key performance indicators (KPIs) from all these components, allowing them to correlate events and identify root causes quickly. The dashboard should also support interactive filtering and drilling down into specific data points. Which Azure Monitor feature is best suited for creating such a dashboard?Implement an instrumentation strategy
- 121.A company is developing a new serverless application using Azure Functions. They need to implement a robust logging strategy that captures detailed information about function executions, including input payloads, output results, and any errors encountered. The logs should be searchable and queryable for troubleshooting and auditing purposes. Which logging solution is most appropriate for this scenario?Implement an instrumentation strategy
- 122.A company is implementing a new alerting strategy for their critical business applications hosted on Azure. They want to ensure that alerts are not only triggered but also routed to the correct teams based on the severity and affected service. Additionally, they need to integrate with an existing IT Service Management (ITSM) system to automatically create incident tickets. Which Azure Monitor component is responsible for defining the actions to be taken when an alert fires, including routing and ITSM integration?Implement an instrumentation strategy
- 123.A global software company is migrating its legacy monolithic application to a microservices architecture on Azure. They need to analyze the performance bottlenecks and communication patterns between their newly developed microservices. This requires visualizing the end-to-end flow of requests across different services, including calls to external dependencies like databases and other APIs. Which Application Insights feature can provide this visual representation and help identify performance issues?Implement an instrumentation strategy
- 124.A DevOps team is responsible for a critical Azure Function App. They need to create an alert that triggers when the average response time of the HTTP trigger function exceeds 500 milliseconds for a continuous period of 5 minutes. The alert should send an email to the operations team and also post a message to a Microsoft Teams channel. Which sequence of actions correctly creates this alert in Azure Monitor?Implement an instrumentation strategy
- 125.A security team needs to be notified immediately if any critical Azure resource (e.g., Virtual Network, Storage Account) is deleted or modified in a way that could impact security posture. This includes changes made by administrators or automated processes. The notifications should go to a specific security operations email alias. Which type of alert rule in Azure Monitor should they configure?Implement an instrumentation strategy
- 126.A development team is deploying a new web application to Azure App Service. They need to ensure that all application logs, including custom diagnostic messages and structured data, are collected and stored in a centralized location for long-term analysis and compliance. The solution must allow for complex queries and integration with other monitoring tools. Which logging strategy should they implement?Implement an instrumentation strategy
- 127.A company is deploying a new application to Azure App Service and needs to capture all HTTP request logs, including detailed information about client IP addresses, user agents, and response times. These logs must be retained for at least 90 days for auditing purposes and be easily queryable. They also need to ensure that the logging solution is cost-effective for high-volume traffic. Which logging destination should be configured for the App Service diagnostics settings?Implement an instrumentation strategy
- 128.A DevOps team is responsible for a critical e-commerce application. They are performing a Post-Incident Review (PIR) after a major outage caused by a misconfiguration. During the PIR, their primary goal is to identify ALL contributing factors, not just the immediate cause, and to develop actionable improvements to prevent recurrence. Which SRE principle is the team primarily applying during this PIR?Implement a Site Reliability Engineering (SRE) strategy
- 129.A DevOps team is adopting an SRE strategy for a legacy application that frequently experiences intermittent failures due to upstream dependencies. The team wants to implement a mechanism to prevent these intermittent failures from cascading and overwhelming the service, while still allowing it to recover gracefully. Which design pattern should they implement?Implement a Site Reliability Engineering (SRE) strategy
- 130.A team is designing an SRE strategy for a new critical service. They have defined a Service Level Objective (SLO) for the service's availability as 99.9%. They want to calculate the maximum allowable downtime per month to stay within this SLO. Assume a standard 30-day month.Implement a Site Reliability Engineering (SRE) strategy
- 131.A DevOps team is managing a critical microservices application on Azure. They have observed that during peak load, some backend services occasionally become unresponsive, leading to cascading failures in downstream services. The team wants to implement a mechanism that can temporarily prevent a service from making requests to an unresponsive dependency, allowing the dependency time to recover and preventing further resource exhaustion. Which design pattern should they implement?Implement a Site Reliability Engineering (SRE) strategy
- 132.A global SaaS provider uses Azure Cosmos DB for its multi-tenant application's data store. The application requires strong data consistency across all regions for critical operations, ensuring that all reads return the most recently written data, regardless of the region. They need a DR strategy that supports this requirement while maintaining high availability. Which Cosmos DB feature should they leverage?Implement a Site Reliability Engineering (SRE) strategy
- 133.A financial services company is implementing a disaster recovery (DR) strategy for its critical trading platform hosted on Azure. The platform requires extremely low RTO (Recovery Time Objective) and RPO (Recovery Point Objective), ideally measured in seconds or very few minutes. They need a strategy that maintains a fully functional, up-to-date replica of the production environment in a secondary region, ready to take over immediately with minimal data loss. Which DR strategy would best meet these requirements?Implement a Site Reliability Engineering (SRE) strategy
- 134.A DevOps team is designing an SRE strategy for a new critical IoT platform on Azure that processes millions of telemetry data points per second. They need to ensure that the data ingestion pipeline can tolerate transient failures without data loss and without overwhelming downstream services. Which architectural pattern should they incorporate into their ingestion pipeline to achieve this resilience and flow control?Implement a Site Reliability Engineering (SRE) strategy
- 135.A DevOps team is managing an Azure-based critical payment processing system. Their Service Level Objective (SLO) for transaction success rate is 99.9%. They have observed that the system typically operates at 99.95% success. The team wants to set up alerts that notify them ONLY when there is a risk of breaching the SLO, rather than when the SLO has already been breached. Which type of alerting strategy should they implement?Implement a Site Reliability Engineering (SRE) strategy
- 136.A financial services company uses Azure Kubernetes Service (AKS) for its core banking application. They need a disaster recovery strategy that provides a relatively fast recovery time (RTO of 2-4 hours) and ensures data consistency, but they want to keep costs lower than a full active-active deployment. They are willing to accept a brief period of reduced capacity during recovery. Which DR strategy is most appropriate?Implement a Site Reliability Engineering (SRE) strategy
- 137.A DevOps team is managing a critical application on Azure. They have implemented several monitoring tools, including Azure Monitor for metrics and logs, and Application Insights for application performance. They regularly review dashboards and alerts. However, they've noticed that incidents are often detected reactively, sometimes by end-users, rather than proactively by their monitoring systems. Which aspect of their health monitoring strategy needs immediate improvement to shift towards proactive detection?Implement a Site Reliability Engineering (SRE) strategy
- 138.A DevOps team is implementing a health monitoring strategy for a new critical microservice deployed on Azure Kubernetes Service (AKS). They want to ensure that the service is not only running but also capable of processing requests correctly. Which type of probe should they configure in their Kubernetes deployment to check if the application inside the container is ready to serve traffic and remove it from the service load balancer if it becomes unresponsive?Implement a Site Reliability Engineering (SRE) strategy
- 139.A DevOps team manages a critical microservices application on Azure Kubernetes Service (AKS). They want to improve the detectability of issues across their distributed services. They need to trace requests as they flow through multiple services, identify bottlenecks, and pinpoint service dependencies. Which monitoring approach is best suited for this requirement?Implement a Site Reliability Engineering (SRE) strategy
- 140.A DevOps team is adopting an SRE strategy for a critical e-commerce platform hosted on Azure. They want to define a Service Level Objective (SLO) for the platform's average response time. The business requires that 95% of all user requests complete within 500 milliseconds. Which of the following SLI definitions most accurately supports this SLO?Implement a Site Reliability Engineering (SRE) strategy
- 141.A global e-commerce company uses Azure Kubernetes Service (AKS) for its critical applications. They have defined a Service Level Objective (SLO) of 99.9% availability for their primary payment processing service over a 30-day period. Currently, the service has experienced 15 minutes of downtime within the first 10 days of the current period. What is the remaining error budget in minutes for the rest of the 30-day period?Implement a Site Reliability Engineering (SRE) strategy
- 142.A global e-commerce company uses Azure Front Door to route traffic to its multi-region application. The SRE team wants to ensure that if one Azure region experiences a major outage, user traffic is automatically and seamlessly redirected to a healthy region with minimal disruption. They also aim for near-zero RTO and RPO. Which disaster recovery strategy should they employ?Implement a Site Reliability Engineering (SRE) strategy
- 143.A company is implementing a disaster recovery strategy for its critical application hosted on Azure. The application uses Azure App Service for its front end and Azure SQL Database for its data store. The RTO (Recovery Time Objective) is 4 hours, and the RPO (Recovery Point Objective) is 1 hour. The company wants to minimize costs while meeting these objectives. Which disaster recovery strategy should they implement?Implement a Site Reliability Engineering (SRE) strategy
- 144.A DevOps team is implementing a failure detection and recovery strategy for a critical API hosted on Azure Functions. They observe that upstream dependencies occasionally become unresponsive for short periods. To prevent the API from becoming unresponsive itself while waiting for these dependencies, they want to implement a mechanism that automatically retries failed calls after a delay, with increasing delays between subsequent retries. Which resiliency pattern should they implement?Implement a Site Reliability Engineering (SRE) strategy
- 145.A global enterprise is adopting Azure DevOps for its software development lifecycle. They have a strict security policy requiring that all code changes must undergo an automatic security scan for common vulnerabilities before merging into the main branch. This scan must identify issues like SQL injection, cross-site scripting (XSS), and insecure API endpoints. Which type of security testing should be integrated into their Azure DevOps pipeline to meet this requirement?Develop a security and compliance plan
- 146.A software development company is using Azure DevOps for its CI/CD pipelines. They have implemented a security gate in their release pipeline that requires manual approval from a security team lead before deploying to production. This approval process must be auditable and clearly recorded within Azure DevOps. Which Azure DevOps feature should the team configure to implement this security gate?Develop a security and compliance plan
- 147.A DevOps team is developing a new serverless application using Azure Functions. The application needs to access sensitive data stored in an Azure Key Vault and a backend API hosted in an Azure App Service. Both the Key Vault and the App Service are configured to only allow access from specific Virtual Networks (VNets). How should the DevOps team configure the Azure Function to securely access these resources while adhering to the VNet access restrictions?Develop a security and compliance plan
- 148.A global software company maintains several Azure subscriptions for different development, test, and production environments. They need to ensure that all virtual networks (VNets) created across these subscriptions are peered with a central hub VNet in the production subscription for secure, internal network routing. Furthermore, this peering must be established automatically whenever a new VNet is created. Which Azure service combination provides the most efficient and compliant solution?Develop a security and compliance plan
- 149.A DevOps team is deploying sensitive APIs to Azure App Service. They need to restrict access to these APIs so that only other authorized Azure services (e.g., Azure Functions, Logic Apps) within their virtual network can call them. External internet access must be blocked. Which networking feature should be configured on the Azure App Service to achieve this?Develop a security and compliance plan
- 150.A company is required to implement a 'least privilege' security model for their Azure environment. They want to ensure that developers only have permissions to deploy resources within specific resource groups for their projects, and only to specific resource types (e.g., Web Apps, Azure SQL Database). They should NOT be able to create Virtual Networks or modify subscription-level settings. Which Azure service is best suited to define and enforce these granular permissions?Develop a security and compliance plan