Step2Study
IT & TechnologyAZ-305100% Free

Microsoft Certified: Azure Solutions Architect Expert

Practice bank
230 Qs
Real exam
40 Qs
Time limit
120 min
Passing
A passing score of 700 or greater is required.

Exam blueprint

Design identity, governance, and monitoring solutions
25%
Design data storage solutions
25%
Design business continuity solutions
15%
Design infrastructure solutions
35%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 270 min · pass 70% · 230 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Microsoft Certified: Azure Solutions Architect Expert practice test questions

Sample questions from the 230-question bank, with answers and explanations.

All questions
  1. 1. A small business uses an Azure Virtual Machine to host its internal CRM application. The company requires daily backups of the VM, with a retention period of 30 days. The backup solution must be cost-effective and easy to manage. Which Azure backup solution should be implemented?

    Design business continuity solutions

    • A. Managed Disks snapshots
    • B. Azure Blob Storage with AzCopy
    • C. Azure Backup for Azure VMs
    • D. Azure Site Recovery
    Show answer

    C. Azure Backup for Azure VMs

    Azure Backup for Azure VMs is a native, cost-effective, and easy-to-manage solution that provides daily backups with configurable retention policies, directly addressing the requirements.

  2. 2. A software development company uses Azure DevOps for its source code management and CI/CD pipelines. They host a self-hosted Azure DevOps agent on an Azure Virtual Machine. The company needs to ensure that the agent VM can be recovered quickly in case of an outage or corruption, with a minimal loss of work. The agent VM stores configuration files and temporary build artifacts. The RPO must be less than 1 hour and RTO less than 4 hours. Which backup solution should be implemented for the Azure DevOps agent VM?

    Design business continuity solutions

    • A. Azure Site Recovery to replicate the VM to another region.
    • B. Snapshot the VM's OS disk hourly and store in Blob Storage.
    • C. Use Azure DevTest Labs for automatic VM shutdown and recreation.
    • D. Azure Backup for Azure VMs with a daily backup policy.
    Show answer

    D. Azure Backup for Azure VMs with a daily backup policy.

    Azure Backup for Azure VMs provides automated, scheduled backups with customizable retention policies, allowing for point-in-time recovery of the entire VM. With hourly or more frequent backups, it can easily meet the RPO of less than 1 hour and RTO of less than 4 hours for VM recovery.

  3. 3. A global e-commerce platform relies on Azure Kubernetes Service (AKS) clusters deployed in multiple regions to serve its customers. The platform needs to ensure that if an entire Azure region becomes unavailable, traffic is automatically redirected to the nearest healthy region. Which Azure service should be used to achieve this global traffic redirection and high availability for the AKS clusters?

    Design business continuity solutions

    • A. Azure DNS
    • B. Azure Load Balancer
    • C. Azure Application Gateway
    • D. Azure Front Door
    Show answer

    D. Azure Front Door

    Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It provides global load balancing, automatic failover across regions, and path-based routing.

  4. 4. A healthcare organization is migrating its on-premises SQL Server databases to Azure. These databases contain highly sensitive patient data and require a backup solution that ensures data immutability for 7 years to meet regulatory compliance, preventing any modification or deletion of backups during this period. Which Azure service should be used?

    Design business continuity solutions

    • A. Azure Site Recovery with backup integration
    • B. Azure Backup for SQL Server in Azure VMs with immutable vaults
    • C. Azure SQL Database automated backups with long-term retention
    • D. Azure Blob Storage with immutable policies
    Show answer

    B. Azure Backup for SQL Server in Azure VMs with immutable vaults

    Azure Backup for SQL Server in Azure VMs, when combined with Recovery Services vaults configured for immutable storage, allows backups of SQL databases hosted on IaaS VMs to be stored immutably for a specified period, meeting the 7-year retention and immutability requirements for regulatory compliance.

  5. 5. A multinational corporation uses Azure Virtual Machines to host its critical ERP system. The company requires a robust disaster recovery solution that can recover the entire application environment, including VMs, networks, and storage, to a secondary Azure region with an RTO of less than 2 hours and an RPO of less than 15 minutes. The solution must be automated and orchestrated. Which Azure service should be implemented?

    Design business continuity solutions

    • A. Manual VM snapshot and deployment in a secondary region.
    • B. Azure Resource Mover.
    • C. Azure Site Recovery (ASR).
    • D. Azure Backup for Azure VMs.
    Show answer

    C. Azure Site Recovery (ASR).

    Azure Site Recovery (ASR) is designed for comprehensive disaster recovery, enabling replication of Azure VMs to a secondary region. It provides orchestration for automated failover and failback, along with a low RTO (minutes to hours) and RPO (seconds to minutes) for entire application environments, meeting the specified requirements.

  6. 6. A global media company uses Azure for its content delivery network (CDN) and streaming services. They need to monitor the performance and availability of their CDN endpoints, track user-perceived performance, and analyze logs for potential security threats. The solution must provide real-time alerts and integrate with their existing incident management system. Which Azure monitoring service should be primarily used to meet these requirements?

    Design identity, governance, and monitoring solutions

    • A. Azure Network Watcher
    • B. Azure Service Health
    • C. Azure Monitor with Log Analytics and Application Insights
    • D. Azure Security Center (Defender for Cloud)
    Show answer

    C. Azure Monitor with Log Analytics and Application Insights

    Azure Monitor, combined with Log Analytics for log aggregation and querying, and Application Insights for application performance monitoring (including user-perceived performance and CDN integration), provides a comprehensive solution for performance, availability, and log analysis with alerting capabilities.

  7. 7. A company is migrating its file shares to Azure. The files are critical business documents and require a highly available solution that can be accessed from on-premises servers and Azure VMs. Data must be resilient to zone-level failures within the Azure region. Which Azure service and redundancy option should be chosen?

    Design business continuity solutions

    • A. Azure Files with Locally-redundant storage (LRS)
    • B. Azure NetApp Files with Standard tier
    • C. Azure Blob Storage with Geo-redundant storage (GRS)
    • D. Azure Files with Zone-redundant storage (ZRS)
    Show answer

    D. Azure Files with Zone-redundant storage (ZRS)

    Azure Files with Zone-redundant storage (ZRS) provides a highly available file share that is replicated synchronously across three Azure availability zones in the primary region, protecting against zone-level failures while being accessible from both on-premises (via Azure File Sync or VPN) and Azure VMs.

  8. 8. A global manufacturing company is deploying a new IoT solution on Azure to monitor factory equipment. They need to collect telemetry data from thousands of devices, process it in real-time, and store it for long-term analysis. The solution must be highly scalable, handle intermittent connectivity from devices, and allow for bi-directional communication (device-to-cloud and cloud-to-device). Which Azure service should be used as the central hub for device connectivity and management?

    Design identity, governance, and monitoring solutions

    • A. Azure Data Lake Storage
    • B. Azure Event Hubs
    • C. Azure IoT Hub
    • D. Azure Stream Analytics
    Show answer

    C. Azure IoT Hub

    Azure IoT Hub is specifically designed for bi-directional communication between IoT devices and the cloud. It provides features like device-to-cloud telemetry, cloud-to-device messaging, device management, and secure authentication for large numbers of devices, perfectly matching the requirements.

  9. 9. A global manufacturing company is deploying a new IoT solution on Azure to monitor factory equipment. They need to collect telemetry data from thousands of devices, process it in real-time, and store it for historical analysis. The solution must also provide insights into equipment health and predict potential failures. Which combination of Azure services should be used for monitoring and data ingestion?

    Design identity, governance, and monitoring solutions

    • A. Azure Logic Apps, Azure Functions, Azure SQL Database
    • B. Azure Event Hubs, Azure Stream Analytics, Azure Synapse Analytics
    • C. Azure IoT Hub, Azure Stream Analytics, Azure Data Lake Storage
    • D. Azure Service Bus, Azure Data Factory, Azure Cosmos DB
    Show answer

    C. Azure IoT Hub, Azure Stream Analytics, Azure Data Lake Storage

    Azure IoT Hub is specifically designed for secure, bi-directional communication with millions of IoT devices, handling telemetry ingestion. Azure Stream Analytics can process this real-time data for immediate insights, and Azure Data Lake Storage is suitable for cost-effective, large-scale storage of raw and processed data for historical analysis and machine learning.

  10. 10. A financial services company is developing a new serverless application on Azure that uses Azure Functions to process transactions. The application needs to store sensitive audit logs in a dedicated Azure Storage Account. To meet compliance requirements, all data written to the storage account must be encrypted at rest, and access to the storage account must be restricted to only the Azure Functions application, using a highly secure and auditable method that avoids managing connection strings. Which combination of features ensures this security posture?

    Design identity, governance, and monitoring solutions

    • A. Azure AD Application Registration with Microsoft-Managed Keys (MMK) for Storage Account Encryption
    • B. Shared Access Signatures (SAS) with Azure Policy
    • C. Storage Account Access Keys with Service Endpoints
    • D. Managed Identity for Azure Functions with Customer-Managed Keys (CMK) for Storage Account Encryption
    Show answer

    D. Managed Identity for Azure Functions with Customer-Managed Keys (CMK) for Storage Account Encryption

    Managed Identities for Azure Functions provide a secure, credential-free way for the function app to authenticate to the storage account. Customer-Managed Keys (CMK) ensure that data at rest is encrypted with keys controlled by the customer, meeting the compliance requirement for encryption beyond Microsoft's default. This combination fully addresses the security and compliance needs.

  11. 11. A company is designing a highly available solution for a stateless web application running on Azure Virtual Machine Scale Sets. The application must remain available even if an entire Azure Availability Zone fails. Which high availability strategy should be implemented?

    Design business continuity solutions

    • A. Deploy the Virtual Machine Scale Set across multiple Azure regions using Azure Traffic Manager.
    • B. Deploy the Virtual Machine Scale Set within a single Availability Set.
    • C. Deploy the Virtual Machine Scale Set in a single region without any redundancy.
    • D. Deploy the Virtual Machine Scale Set across multiple Availability Zones.
    Show answer

    D. Deploy the Virtual Machine Scale Set across multiple Availability Zones.

    Deploying a Virtual Machine Scale Set across multiple Availability Zones ensures that instances are distributed across physically separate data centers within a region, providing resilience against a single Availability Zone failure.

  12. 12. A global e-commerce company operates its primary web application from a single Azure region. Due to recent growth, the company wants to ensure that its application remains available even if an entire Azure region experiences a major outage. The application uses Azure App Service for its front end, Azure SQL Database for its primary data store, and Azure Storage for static content. The company requires a recovery time objective (RTO) of less than 4 hours and a recovery point objective (RPO) of less than 15 minutes. Which disaster recovery strategy should the company implement for its Azure SQL Database to meet these requirements?

    Design business continuity solutions

    • A. Configure active geo-replication for the Azure SQL Database to a secondary region.
    • B. Use Azure SQL Database standard backups with geo-restore to a secondary region.
    • C. Implement a failover group for the Azure SQL Database across two regions.
    • D. Deploy an Azure SQL Database Hyperscale tier with zone redundancy in the primary region.
    Show answer

    C. Implement a failover group for the Azure SQL Database across two regions.

    Failover groups provide automatic asynchronous replication of databases to a secondary region, enabling RPO of minutes and RTO of hours. This setup allows for manual or automatic failover, meeting the specified RTO and RPO requirements. Active geo-replication requires manual intervention for failover, which may not meet the RTO.

  13. 13. A financial institution is migrating its applications to Azure. They require a highly secure authentication solution for their critical applications that mandates multi-factor authentication (MFA) and provides conditional access based on user location, device compliance, and sign-in risk. The solution must integrate seamlessly with Azure AD. Which Azure AD feature should be designed to achieve these requirements?

    Design identity, governance, and monitoring solutions

    • A. Azure AD Identity Protection
    • B. Azure AD Privileged Identity Management (PIM)
    • C. Azure AD External Identities
    • D. Azure AD Conditional Access
    Show answer

    D. Azure AD Conditional Access

    Azure AD Conditional Access is the policy-based engine that allows administrators to enforce specific access requirements based on conditions such as user location, device state, and sign-in risk. It is the primary tool for implementing granular access controls and mandating MFA for specific scenarios.

  14. 14. A research laboratory is using Azure to host a high-performance computing (HPC) cluster. They need to collect detailed performance metrics (CPU, memory, disk I/O) and logs from both Windows and Linux virtual machines within the cluster. This data must be sent to a central Log Analytics workspace for analysis. Which agent should be installed on the virtual machines to achieve this?

    Design identity, governance, and monitoring solutions

    • A. Azure Network Watcher agent
    • B. Azure Diagnostics extension (WAD/LAD)
    • C. Azure Monitor Agent (AMA)
    • D. Log Analytics agent (MMA/OMS)
    Show answer

    C. Azure Monitor Agent (AMA)

    The Azure Monitor Agent (AMA) is the new, unified agent for Azure Monitor that collects monitoring data from guest operating systems of Azure VMs and hybrid machines, and delivers it to Azure Monitor Logs or Azure Monitor Metrics. It is designed to replace the legacy Log Analytics agent and Azure Diagnostics extensions, offering a more flexible and efficient data collection strategy.

  15. 15. A global media company uses Azure Blob Storage to store large video files that are accessed frequently by users worldwide. The company requires maximum data durability, immediate accessibility, and protection against regional outages. Data must be replicated to a secondary region and across multiple availability zones within both the primary and secondary regions. Which Azure Storage redundancy option should be selected?

    Design business continuity solutions

    • A. Geo-zone-redundant storage (GZRS)
    • B. Locally-redundant storage (LRS)
    • C. Geo-redundant storage (GRS)
    • D. Zone-redundant storage (ZRS)
    Show answer

    A. Geo-zone-redundant storage (GZRS)

    Geo-zone-redundant storage (GZRS) provides maximum durability by synchronously replicating data across three Azure availability zones in the primary region and then asynchronously replicating it to a single physical location in a secondary region. This combination ensures high availability within the primary region and disaster recovery to a secondary region, meeting all specified requirements for durability, accessibility, and protection against regional outages.

  16. 16. A global manufacturing company uses Azure Virtual Machines to host its critical ERP system. The company requires a recovery point objective (RPO) of 4 hours and a recovery time objective (RTO) of 8 hours. The solution must provide disaster recovery capabilities to a secondary Azure region. Which Azure service should be used to meet these requirements?

    Design business continuity solutions

    • A. Azure Backup for daily snapshots
    • B. Azure Site Recovery with replication policies
    • C. Azure Files with geo-redundant storage
    • D. Azure Traffic Manager with active-passive setup
    Show answer

    B. Azure Site Recovery with replication policies

    Azure Site Recovery (ASR) is specifically designed for disaster recovery of virtual machines, supporting replication to another region and enabling RPO/RTO configuration to meet business continuity requirements.

  17. 17. A financial institution is deploying a new web application in Azure that will process highly sensitive customer data. They need to ensure that the application can securely access other Azure services, such as Azure Key Vault and Azure SQL Database, without storing credentials directly in the application's code. The application runs on Azure App Service. How should the application be authenticated to Azure services?

    Design identity, governance, and monitoring solutions

    • A. Store connection strings with credentials in Azure Key Vault.
    • B. Configure network access policies to restrict access to Azure services.
    • C. Implement Managed Identities for Azure Resources.
    • D. Use service principals with client secrets stored in the application settings.
    Show answer

    C. Implement Managed Identities for Azure Resources.

    Managed Identities for Azure Resources provide an Azure AD identity for Azure services like App Service. This identity can then be used to authenticate to other Azure services that support Azure AD authentication, eliminating the need to store credentials in code or configuration files, which is a best practice for security.

  18. 18. A global manufacturing company with existing on-premises Active Directory (AD) requires a hybrid identity solution for its Azure environment. Users must be able to log in to Azure resources using their existing on-premises credentials. The solution must support single sign-on (SSO) and synchronize user accounts and password hashes to Azure AD, without requiring any dedicated servers in the perimeter network (DMZ) for authentication. Which authentication solution should be implemented?

    Design identity, governance, and monitoring solutions

    • A. Azure AD Connect with Password Hash Synchronization (PHS)
    • B. Azure AD Domain Services
    • C. Azure AD Connect with Federation (AD FS)
    • D. Azure AD Connect with Pass-through Authentication (PTA)
    Show answer

    A. Azure AD Connect with Password Hash Synchronization (PHS)

    Azure AD Connect with Password Hash Synchronization (PHS) synchronizes a hash of the user's on-premises AD password hash to Azure AD. This allows users to sign in with the same credentials and supports SSO, while not requiring dedicated servers in the DMZ for authentication, as Azure AD handles the authentication directly.

  19. 19. A global e-commerce platform relies on Azure Kubernetes Service (AKS) clusters deployed in multiple Azure regions to serve its customers. To optimize user experience, the company wants to ensure that user requests are routed to the closest healthy AKS cluster. Additionally, in case of a regional outage, traffic should automatically fail over to the next available region. Which Azure service should be used to achieve this global traffic routing and failover?

    Design business continuity solutions

    • A. Azure Front Door.
    • B. Azure Traffic Manager.
    • C. Azure Application Gateway.
    • D. Azure Load Balancer.
    Show answer

    A. Azure Front Door.

    Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It provides dynamic site acceleration (DSA), global HTTP/S load balancing, and application-layer security, making it ideal for routing traffic to the closest healthy backend (AKS cluster) and providing automatic failover across regions.

  20. 20. A software development company is building a new microservices application in Azure. Each microservice needs to securely communicate with other services and Azure resources (e.g., Azure Key Vault, Azure SQL Database) without managing credentials in code. The security team mandates that the identity for each service should be managed by Azure AD and automatically rotated. Which Azure AD feature should be used to assign identities to these microservices?

    Design identity, governance, and monitoring solutions

    • A. Service Principals
    • B. Managed Identities
    • C. User-assigned Identities
    • D. Application Registrations
    Show answer

    B. Managed Identities

    Managed Identities for Azure resources provide an automatically managed identity in Azure AD for Azure services. This eliminates the need for developers to manage credentials, as Azure handles the identity lifecycle and credential rotation, making it ideal for secure service-to-service communication.

  21. 21. A company is designing a new Azure solution that requires a highly available database. The database must support read and write operations across multiple Azure regions with automatic failover and minimal data loss in the event of a regional outage. Which Azure database service best meets these requirements?

    Design business continuity solutions

    • A. Azure Cosmos DB with multi-region writes
    • B. Azure Database for PostgreSQL Single Server
    • C. Azure SQL Database Standard tier
    • D. Azure SQL Managed Instance with a geo-redundant backup
    Show answer

    A. Azure Cosmos DB with multi-region writes

    Azure Cosmos DB with multi-region writes provides active-active distribution across multiple regions, enabling automatic failover and RPO of zero for regional outages, which aligns with the requirement for minimal data loss.

  22. 22. A financial services company is migrating its on-premises data center to Azure. They have several critical applications running on Windows Server VMs that require highly available file shares for user profiles and application data. The company needs to ensure that these file shares are accessible even if a single data center in an Azure region becomes unavailable. The solution must provide strong consistency and be easily manageable. Which Azure storage solution should the company choose for these file shares?

    Design business continuity solutions

    • A. Premium SSD managed disks attached to multiple VMs in an availability set.
    • B. Azure NetApp Files with cross-region replication.
    • C. Azure Files with zone-redundant storage (ZRS).
    • D. Azure Blob Storage with geo-redundant storage (GRS).
    Show answer

    C. Azure Files with zone-redundant storage (ZRS).

    Azure Files with Zone-Redundant Storage (ZRS) provides high availability for file shares by synchronously replicating data across three Azure availability zones in the primary region, protecting against single data center outages while maintaining strong consistency and ease of management.

  23. 23. A software company is developing a multi-tenant SaaS application on Azure. Each customer (tenant) has its own set of users and requires isolation of identity data. The application needs to authenticate users from various organizations, potentially using their existing corporate identities (e.g., Azure AD, Google, Facebook). Which Azure AD feature is best suited for this multi-tenant identity requirement?

    Design identity, governance, and monitoring solutions

    • A. Azure AD Domain Services (AAD DS)
    • B. Azure Active Directory (multi-tenant app registration)
    • C. Azure AD B2B collaboration
    • D. Azure AD B2C (Business to Consumer)
    Show answer

    B. Azure Active Directory (multi-tenant app registration)

    For a multi-tenant SaaS application that needs to authenticate users from various organizations using their corporate identities (e.g., their own Azure AD), registering the application as multi-tenant in Azure Active Directory is the appropriate solution. This allows users from any Azure AD tenant to sign in without requiring B2B invitations or B2C user flows.

  24. 24. A company is designing a high availability solution for its critical API backend hosted on Azure Kubernetes Service (AKS). The solution must ensure that the API remains available even if a single Azure region experiences a complete outage. Which approach should be taken?

    Design business continuity solutions

    • A. Deploy the AKS cluster across multiple Availability Zones within a single region.
    • B. Deploy multiple AKS clusters in different Azure regions and use a global load balancer.
    • C. Deploy the AKS cluster in a single Availability Zone.
    • D. Implement a self-healing deployment within a single AKS cluster.
    Show answer

    B. Deploy multiple AKS clusters in different Azure regions and use a global load balancer.

    To protect against a complete Azure region outage, the solution must involve deploying resources across multiple regions. Deploying multiple AKS clusters in different regions with a global load balancer (like Azure Front Door or Traffic Manager) provides regional disaster recovery and high availability.

  25. 25. A global e-commerce company uses Azure to host its customer-facing web application. They need to ensure that only traffic from their corporate network and specific trusted partner networks can access the application's backend APIs hosted on Azure App Service. Additionally, they must prevent direct public internet access to these backend APIs. Which Azure networking and security features should be combined to achieve this?

    Design identity, governance, and monitoring solutions

    • A. Azure DDoS Protection Standard with Traffic Manager
    • B. Azure Virtual Network (VNet) Integration with Network Security Groups (NSGs)
    • C. Azure Front Door with Web Application Firewall (WAF)
    • D. Azure Private Link with Service Endpoints
    Show answer

    B. Azure Virtual Network (VNet) Integration with Network Security Groups (NSGs)

    VNet Integration allows the App Service to reside within a virtual network, preventing direct public internet access. NSGs can then be applied to the VNet subnet to filter inbound traffic based on source IP ranges (corporate and partner networks), effectively restricting access to the backend APIs.

Microsoft Certified: Azure Solutions Architect Expert flashcards

Tap a card to flip it. 123 flashcards in the full deck.

  • Azure Backup for Azure VMs

    Flip card

    A native Azure service that provides automated, policy-based backup and recovery for Azure Virtual Machines.

    • Offers application-consistent backups.
    • Supports various retention policies (daily, weekly, monthly, yearly).
    • Integrated with Azure Recovery Services vaults for centralized management.
    Study this card →
  • Azure Backup for VMs

    Flip card

    Azure Backup for Azure VMs provides a managed, scalable, and automated backup solution for Azure Virtual Machines, enabling point-in-time recovery of entire VMs or individual files.

    • Automated, policy-driven backups.
    • Supports full VM or file-level recovery.
    • Integrated with Azure Recovery Services vaults.
    Study this card →
  • Azure Front Door

    Flip card

    A global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, providing global load balancing and site acceleration.

    • Offers global HTTP/HTTPS load balancing.
    • Provides application acceleration and SSL offloading.
    • Enables automatic failover across regions for high availability.
    Study this card →
  • Immutable Backups with Azure Backup

    Flip card

    Configuring Azure Backup (specifically Recovery Services vaults) with immutable storage ensures that once backup data is written, it cannot be modified or deleted for a specified retention period, crucial for compliance and ransomware protection.

    • Applies to Recovery Services vaults
    • Protects backup data from accidental or malicious deletion/modification
    • Supports various backup workloads (VMs, SQL, File shares)
    Study this card →
  • Azure Site Recovery (ASR)

    Flip card

    Azure Site Recovery (ASR) is a disaster recovery service that replicates workloads running on physical servers, Azure VMs, or VMware VMs to a secondary location, enabling orchestrated failover and failback for business continuity.

    • Replicates VMs (Azure, VMware, physical) to Azure or secondary site.
    • Provides orchestrated failover and failback.
    • Low RTO and RPO for disaster recovery.
    Study this card →
  • Azure Monitor Suite

    Flip card

    Azure Monitor is a comprehensive solution for collecting, analyzing, and acting on telemetry from Azure and on-premises environments, encompassing logs, metrics, application performance, and network monitoring.

    • Collects metrics and logs from various sources.
    • Provides visualization, analysis, and alerting capabilities.
    • Includes Log Analytics for log management and Application Insights for APM.
    Study this card →
  • Azure Files with ZRS

    Flip card

    Azure Files provides managed file shares in the cloud, and when configured with Zone-redundant storage (ZRS), it ensures high availability and resilience against zone-level failures.

    • Provides fully managed file shares (SMB/NFS).
    • ZRS replicates data synchronously across three availability zones.
    • Accessible from on-premises (via VPN/ExpressRoute) and Azure VMs.
    Study this card →
  • Azure IoT Hub

    Flip card

    Azure IoT Hub is a managed service that acts as a central message hub for bi-directional communication between your IoT application and the devices it manages. It supports millions of devices and ensures secure and reliable communication.

    • Bi-directional communication (device-to-cloud, cloud-to-device)
    • Device management capabilities (device twin, direct methods)
    • Secure per-device authentication
    Study this card →
  • Azure IoT Data Pipeline

    Flip card

    A typical Azure IoT data pipeline involves IoT Hub for device ingestion, Stream Analytics for real-time processing, and Data Lake Storage for historical data storage and analysis.

    • IoT Hub handles device communication and telemetry.
    • Stream Analytics processes data in motion.
    • Data Lake Storage provides scalable, cost-effective storage for big data.
    Study this card →
  • Managed Identity + CMK

    Flip card

    Managed Identity provides an automatically managed, Azure AD-based identity for Azure services, eliminating credential management. Customer-Managed Keys (CMK) allow customers to use their own encryption keys for data at rest in Azure services, providing greater control over encryption.

    • Managed Identity: Credential-free authentication for Azure services
    • Managed Identity: Azure handles identity lifecycle
    • CMK: Customer controls encryption keys in Azure Key Vault
    Study this card →
  • Azure Availability Zones

    Flip card

    Azure Availability Zones are physically separate locations within an Azure region, each with independent power, cooling, and networking, providing resilience against data center failures.

    • Protects against data center failures within a region.
    • Distributes resources across independent physical locations.
    • Requires services to be zone-aware to function across zones.
    Study this card →
  • Azure SQL Database Failover Groups

    Flip card

    Azure SQL Database Failover Groups automate the replication and failover of a group of databases to a secondary region, providing business continuity for regional disasters.

    • Automates failover for a group of databases.
    • Supports both manual and automatic failover policies.
    • Provides a read-write listener and an optional read-only listener.
    Study this card →
  • Azure AD Conditional Access

    Flip card

    A feature of Azure Active Directory that enables administrators to enforce automated access control decisions for accessing cloud apps based on various conditions such as user location, device state, application, and sign-in risk.

    • Uses 'if-then' statements to enforce policies
    • Integrates with MFA, device compliance, and Identity Protection
    • Crucial for Zero Trust security models
    Study this card →
  • Azure Monitor Agent (AMA)

    Flip card

    The Azure Monitor Agent (AMA) is a single, unified agent for Azure Monitor that collects monitoring data from guest operating systems of Azure virtual machines, Azure Arc-enabled servers, and Azure Virtual Machine Scale Sets and delivers it to Azure Monitor Logs and Azure Monitor Metrics.

    • Replaces the legacy Log Analytics agent (MMA/OMS) and Azure Diagnostics extensions.
    • Uses Data Collection Rules (DCRs) for granular control over collected data.
    • Supports both Windows and Linux operating systems.
    Study this card →
  • Azure Geo-zone-redundant storage (GZRS)

    Flip card

    The highest level of Azure Storage redundancy, combining zone-redundant storage (ZRS) in the primary region with geo-redundant storage (GRS) to a secondary region.

    • Synchronous replication across 3 AZs in primary region.
    • Asynchronous replication to secondary region.
    • Offers 12 nines (99.9999999999%) durability.
    Study this card →
  • Managed Identities for Azure Resources

    Flip card

    Managed Identities for Azure Resources provide an automatically managed identity in Azure Active Directory (Azure AD) for applications to use when connecting to resources that support Azure AD authentication.

    • Eliminates the need for developers to manage credentials.
    • Identities are managed by Azure, enhancing security.
    • Can be assigned to many Azure services, like VMs, App Services, Functions.
    Study this card →
  • Password Hash Synchronization (PHS)

    Flip card

    A hybrid identity method where a hash of the user's on-premises Active Directory password hash is synchronized to Azure Active Directory. This allows users to sign in to Azure AD with the same credentials they use on-premises.

    • Simplest to implement for hybrid identity
    • Provides cloud authentication if on-premises AD is unavailable
    • Supports seamless SSO
    Study this card →
  • Azure Cosmos DB Multi-Region Writes

    Flip card

    Azure Cosmos DB's multi-region write capability allows applications to perform writes to any configured region, ensuring high availability and low latency globally.

    • Active-active distribution across multiple Azure regions.
    • Automatic failover with zero RPO (Recovery Point Objective) for regional outages.
    • Provides global low-latency access for both reads and writes.
    Study this card →
  • Azure Files Zone-Redundant Storage (ZRS)

    Flip card

    Azure Files ZRS synchronously replicates data across three Azure availability zones within a region, providing high availability and strong consistency for file shares against single data center failures.

    • Synchronous replication across 3 AZs.
    • Protects against data center-level failures.
    • Offers strong consistency.
    Study this card →
  • Azure AD Multi-tenant Apps

    Flip card

    An Azure AD multi-tenant application allows users from any Azure AD tenant to sign in to the application after granting consent, enabling SaaS solutions to serve multiple organizations.

    • Application is registered in one Azure AD tenant.
    • Users from other tenants can sign in using their own Azure AD accounts.
    • Requires user or admin consent for first-time use in a new tenant.
    Study this card →
  • Multi-Region AKS Deployment

    Flip card

    Deploying Azure Kubernetes Service (AKS) clusters across multiple Azure regions with a global load balancer provides disaster recovery and high availability against regional outages.

    • Protects against complete Azure region failures.
    • Requires a global load balancer (e.g., Azure Front Door, Traffic Manager).
    • Ensures continuous API availability across regions.
    Study this card →
  • VNet Integration + NSG

    Flip card

    Azure Virtual Network (VNet) Integration for App Service allows an app to access resources in or through a VNet, effectively placing the app within a private network. Network Security Groups (NSGs) then filter network traffic to and from resources in an Azure VNet.

    • VNet Integration prevents public internet access to App Service
    • NSGs enable granular IP-based traffic filtering
    • Used together for private and controlled access to backend services
    Study this card →
  • Azure Front Door for Global AKS

    Flip card

    Azure Front Door is a scalable, secure, and globally distributed entry point that uses the Microsoft global edge network to create fast, secure, and highly scalable web applications, often used for routing traffic to multi-region AKS deployments.

    • Global HTTP/S load balancing
    • Latency-based routing to closest backend
    • Integrated Web Application Firewall (WAF)
    Study this card →
  • Azure Backup Server (MABS)

    Flip card

    Azure Backup Server (MABS) is an enterprise-class backup solution for on-premises workloads, including SQL Server, that integrates with Azure Backup for cloud storage and recovery.

    • Extends System Center Data Protection Manager (DPM) to Azure.
    • Supports application-consistent backups for SQL Server.
    • Enables point-in-time recovery and encryption of backups at rest.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.