Microsoft Azure Fundamentals (AZ-900) practice questions
243 free questions with answers and explanations.
- 101.A company requires a secure, private, and high-bandwidth connection between its on-premises data center and its Azure Virtual Network. This connection must bypass the public internet to ensure predictable performance and enhanced security. Which Azure networking service should they use?Describe Azure identity, security, and networking
- 102.A company is deploying a new web application in Azure. They need to ensure that the application is resilient to regional outages and provides low-latency access to users located across different geographic locations. Which Azure service should they use?Describe Azure identity, security, and networking
- 103.An organization is deploying several web applications to Azure and needs to ensure that these applications are protected from common web-based attacks, such as SQL injection and cross-site scripting. They also require load balancing capabilities for their web traffic. Which Azure networking service combines these features?Describe Azure identity, security, and networking
- 104.A company is planning to migrate its on-premises data center to Azure. They need to ensure that user identities and authentication processes remain consistent across both environments. The solution must allow users to use their existing on-premises Active Directory credentials to access Azure resources. Which Azure identity service should they implement?Describe Azure identity, security, and networking
- 105.A company is implementing a zero-trust security model. They need to ensure that users accessing sensitive applications in Azure must re-authenticate and provide a second factor of authentication if they are connecting from an untrusted network location or a non-compliant device. Which Azure AD feature provides this capability?Describe Azure identity, security, and networking
- 106.A company wants to establish a secure, private connection between their on-premises network and their Azure Virtual Network. They require high bandwidth and consistent low latency, and the connection must not traverse the public internet. Which Azure networking service should they use?Describe Azure identity, security, and networking
- 107.A financial institution is deploying a new application in Azure that will process highly sensitive customer data. They need to ensure that the data remains encrypted not only at rest and in transit, but also while actively being processed by the CPU and memory. Which Azure security concept addresses this requirement?Describe Azure identity, security, and networking
- 108.A global company has deployed its web application in multiple Azure regions (e.g., East US, West Europe, Southeast Asia) to ensure high availability and low latency for its users worldwide. They need a service that can intelligently route user traffic to the closest and healthiest endpoint. Which Azure service should they use?Describe Azure identity, security, and networking
- 109.A company is implementing a new application in Azure that requires highly available and scalable storage for large amounts of unstructured data, such as images and videos. The data needs to be accessible via standard HTTP/HTTPS. Which Azure storage solution would best meet these requirements?Describe Azure identity, security, and networking
- 110.A development team is building a new application that requires storing sensitive configuration data, such as API keys, database connection strings, and certificates. They need a centralized and secure service in Azure to manage these secrets, ensuring they are protected against unauthorized access and are easily retrievable by authorized applications. Which Azure service should they use?Describe Azure identity, security, and networking
- 111.An administrator needs to implement a policy in Azure that requires all newly created virtual machines to have a specific tag (e.g., 'CostCenter: IT'). This policy should automatically audit compliance and prevent non-compliant resources from being created. Which Azure security feature can enforce this requirement?Describe Azure identity, security, and networking
- 112.A company is using Azure Active Directory (Azure AD) for identity and access management. They want to ensure that users accessing sensitive applications from untrusted locations or non-compliant devices are prompted for multi-factor authentication (MFA) or blocked entirely. Which Azure AD feature can enforce these types of access policies?Describe Azure identity, security, and networking
- 113.A security administrator needs to restrict inbound network traffic to a specific Azure Virtual Machine. The VM should only accept RDP (Remote Desktop Protocol) connections on port 3389 from a predefined set of IP addresses. Which Azure networking component should be configured to achieve this?Describe Azure identity, security, and networking
- 114.A company is designing its network infrastructure in Azure. They have multiple virtual machines (VMs) that need to communicate with each other securely within a private network segment. Additionally, these VMs need to be able to resolve DNS names for both internal resources and external public websites. Which two Azure networking services are fundamental for achieving this connectivity and name resolution?Describe Azure identity, security, and networking
- 115.A company is implementing a new security policy that requires all Azure resources to be tagged with specific department and cost center information. They need an automated way to enforce this policy and ensure compliance across all subscriptions and resource groups. Which Azure service should they use?Describe Azure identity, security, and networking
- 116.A developer is creating an application in Azure that needs to securely store connection strings, API keys, and cryptographic keys. These secrets must be accessible by the application but not directly exposed in code or configuration files. Which Azure service should be used?Describe Azure identity, security, and networking
- 117.A company is designing an application that will host customer data. They need to ensure that data at rest is encrypted and that only authorized services and users can access it. Which security principle is primarily addressed by implementing these measures?Describe Azure identity, security, and networking
- 118.A security administrator needs to implement a policy that automatically encrypts all newly created virtual machine disks in an Azure subscription. This policy must be enforced consistently across all resource groups. Which Azure service can be used to achieve this compliance requirement?Describe Azure identity, security, and networking
- 119.A company is implementing a zero-trust security model in Azure. They need to ensure that access to resources is granted only after explicit verification of the user, device, and environment. Which Azure security feature directly supports this principle by evaluating conditions before granting access?Describe Azure identity, security, and networking
- 120.A company requires a solution to centralize the collection of security logs and events from various Azure resources, on-premises servers, and other cloud environments. They need to be able to analyze these logs to detect threats and respond to security incidents. Which Azure service is best suited for this requirement?Describe Azure identity, security, and networking
- 121.A company is implementing a new security strategy for its Azure environment. They want to ensure that all administrative actions performed on Azure resources are logged, auditable, and traceable to the individual who performed them. Which Azure service helps achieve this requirement?Describe Azure identity, security, and networking
- 122.A company is concerned about unauthorized access to its Azure resources, particularly from users with administrative privileges. They want to implement a solution that provides just-in-time (JIT) access and just-enough-access (JEA) for administrative roles, requiring approval and auditing for elevated permissions. Which Azure AD feature should they use?Describe Azure identity, security, and networking
- 123.A developer needs to integrate an Azure Function App with an Azure SQL Database. The Function App will retrieve sensitive connection strings and API keys to access the database and other external services. To protect these secrets, which Azure service should the developer use?Describe Azure identity, security, and networking
- 124.A company is designing an Azure environment and needs to restrict network traffic between different subnets within a Virtual Network. They want to define granular rules based on IP addresses, ports, and protocols to control inbound and outbound access for virtual machines. Which Azure security component should they use?Describe Azure identity, security, and networking
- 125.A company is migrating its on-premises applications to Azure. They require a dedicated, private, and high-bandwidth connection from their datacenter to their Azure Virtual Networks, bypassing the public internet for enhanced security and reliability. Which Azure networking service should they choose?Describe Azure identity, security, and networking
- 126.A company is deploying a new application to Azure that requires secure communication between several virtual machines (VMs) located in different virtual networks (VNets). The company needs to ensure that traffic between these VNets can flow securely without transiting the public internet. Which Azure networking service should they use?Describe Azure identity, security, and networking
- 127.A company is migrating its on-premises virtual machines to Azure. They need to ensure that the virtual machines can communicate with each other securely within the same logical network, and that they can be segmented into different subnets for organizational purposes. Which Azure networking component is fundamental for achieving this?Describe Azure identity, security, and networking
- 128.A company requires a centralized security information and event management (SIEM) solution in Azure to collect security data from various sources, perform threat detection, and enable rapid response to security incidents. Which Azure service is designed for this purpose?Describe Azure identity, security, and networking
- 129.A company is migrating its on-premises virtual machines to Azure. They need to ensure that the virtual machines in Azure can communicate with their on-premises network securely over the internet, using an encrypted tunnel. Which Azure service should they use?Describe Azure identity, security, and networking
- 130.A security administrator needs to implement a system that automatically blocks network traffic from IP addresses that are known to be malicious. This system should continuously update its threat intelligence to protect Azure Virtual Networks from emerging threats. Which Azure security feature provides this capability?Describe Azure identity, security, and networking
- 131.A global company has multiple Azure regions deployed and needs to ensure that users access the closest available endpoint for their applications to minimize latency. If an endpoint becomes unavailable, traffic should automatically be redirected to the next available healthy endpoint. Which Azure networking service provides this global traffic distribution and failover capability?Describe Azure identity, security, and networking
- 132.A security auditor is reviewing the access control strategy for an Azure subscription. They need to ensure that users only have the minimum necessary permissions to perform their job functions, and these permissions are granted directly to their user accounts or groups. Which Azure identity and access management concept does this describe?Describe Azure identity, security, and networking
- 133.A company is concerned about Distributed Denial of Service (DDoS) attacks targeting its public-facing Azure applications. They need a service that provides enhanced DDoS protection capabilities beyond the basic protection offered by Azure's platform, including attack analytics and telemetry. Which Azure security service should they implement?Describe Azure identity, security, and networking
- 134.An organization is evaluating Azure for its compliance needs. They need to ensure that all data stored in Azure Blob Storage is encrypted at rest by default, without requiring any additional configuration by developers or administrators. Which Azure feature ensures this baseline level of encryption for Blob Storage?Describe Azure architecture and services
- 135.A small startup is developing a new online collaboration tool. They want to minimize upfront costs for hardware and software licenses while still having access to a robust development environment. Which cloud benefit best addresses their primary concern?Describe cloud concepts
- 136.A consulting firm needs to provision a new network environment in Azure for a client. This environment must be isolated from other client networks and contain several subnets for different application tiers (web, application, database). Which Azure service is the fundamental building block for creating this isolated and segmented network in Azure?Describe Azure architecture and services
- 137.A company requires a service to manage and distribute container images for their Azure Kubernetes Service (AKS) clusters. They need a private, secure, and geographically replicated repository for their Docker images and other OCI artifacts. Which Azure service should they use?Describe Azure architecture and services
- 138.A technology startup is developing a new online gaming platform that is expected to experience massive and unpredictable spikes in user traffic, especially during new game releases or seasonal events. They need a cloud solution that can automatically and instantaneously adjust its computing resources up or down to match these fluctuations without manual intervention, while optimizing costs. Which cloud capability is central to meeting this specific requirement?Describe cloud concepts
- 139.A company is developing a new application that will be deployed across multiple Azure regions. They need a service to manage and automate the deployment, scaling, and management of containerized applications. The solution should provide a highly available and resilient environment for microservices. Which Azure service is the best fit?Describe Azure architecture and services
- 140.A development team is building a new application that processes large quantities of streaming data from IoT devices. They need a service that can ingest millions of events per second, apply real-time analytics, and integrate with other Azure services for storage and visualization. Which Azure service is best suited for this scenario?Describe Azure architecture and services
- 141.A financial institution is developing a new online banking application. They require a database solution that offers high availability, global distribution with multi-master capabilities, and low-latency access for users worldwide. Which Azure database service is best suited for these requirements?Describe Azure architecture and services
- 142.A small startup is planning to deploy its first application to Azure. They need a service that provides a dedicated, single-tenant physical server to host their virtual machines, ensuring complete isolation and meeting specific compliance requirements. Which Azure service should they choose?Describe Azure architecture and services
- 143.A startup is building a new machine learning platform. They need to provision virtual machines, storage, and networking components quickly and programmatically. Their developers require root access to the operating system to install custom libraries and configure specialized software. However, they want to avoid the capital expenditure of purchasing and maintaining physical hardware. Which cloud service model is most suitable for this scenario?Describe cloud concepts
- 144.A multinational corporation needs to deploy a new customer relationship management (CRM) application that must be accessible to users and customers across North America, Europe, and Asia, with minimal latency. The application also needs to comply with regional data residency requirements. Which cloud benefit is most crucial for meeting both the global accessibility and data residency needs?Describe cloud concepts
- 145.A global e-commerce company needs to deploy its applications in a cloud environment that offers the highest possible level of control over the operating system, virtual network configuration, and installed software, while still leveraging virtualization. They are willing to manage these components themselves. Which cloud service type provides this level of control?Describe cloud concepts
- 146.A global enterprise needs to ensure that their Azure resources are consistently configured across multiple subscriptions and resource groups, adhering to corporate standards for security, compliance, and naming conventions. They want to define a set of rules that can be automatically enforced and audited. Which Azure service is best suited for this requirement?Describe Azure architecture and services
- 147.A company wants to extend its on-premises Active Directory to Azure to provide single sign-on (SSO) for cloud-based applications while maintaining a synchronized user identity experience. They need a tool that synchronizes user accounts, passwords, and groups from their on-premises Active Directory to Azure Active Directory. Which Azure service is designed for this hybrid identity scenario?Describe Azure architecture and services
- 148.A development team is building a new application that needs to store large amounts of unstructured data, such as images and videos. The data must be highly available and accessible from anywhere in the world. Which Azure storage solution is most appropriate for this scenario?Describe Azure architecture and services
- 149.A cybersecurity firm needs to analyze massive volumes of security logs and telemetry data generated from various sources, including Azure resources, on-premises systems, and other cloud providers. They require a service that can ingest, store, and perform complex queries and analytics on this data in real-time, enabling rapid threat detection and response. Which Azure service is best suited for this task?Describe Azure architecture and services
- 150.A company is planning to migrate its on-premises virtual machines to Azure. They need a solution that provides network isolation between their Azure resources and their on-premises network, while also allowing secure communication. Which Azure networking component is essential for establishing this private and secure connection?Describe Azure architecture and services