CertKeen
Microsoft AzureBeta · expanding bank

Azure Solutions Architect Expert (AZ-305) Practice Exam

Original practice questions for Microsoft Exam AZ-305: Designing Microsoft Azure Infrastructure Solutions, following the skills measured as of April 17, 2026. Scenario-based design questions cover logging and monitoring, authentication and authorization with Microsoft Entra ID, identity governance, managed identities and Key Vault, management groups, Azure Policy and compliance; relational, semi-structured and unstructured data storage with Azure SQL, Cosmos DB and Azure Storage, plus data integration; backup, disaster recovery and high availability; and compute, messaging and event-driven architecture, API Management, caching, configuration, migrations, and network connectivity, security and load balancing. Every question includes a written explanation.

100 questions · 12 free preview

$19 · lifetime access
Try free sample

Studying more than one? All Microsoft Azure exams for $29 · every exam for $79

Free sample questions

  1. Sample · question 1 · Pass-through authentication for on-premises policy

    Ambleside Credit syncs its AD DS accounts into its Entra tenant. Its security policy forbids storing any form of password hash in the cloud, and on-premises sign-in hour restrictions and account disablement must take effect immediately for cloud sign-ins. Federation servers are not wanted. What should you recommend?

    • A.Federation with an AD FS farm and Web Application Proxy servers
    • B.Pass-through authentication with agents installed on several on-premises serverscorrect
    • C.Microsoft Entra Cloud Sync with password hash synchronization
    • D.Password hash synchronization with Seamless SSO

    Why: Pass-through authentication validates each password against on-premises Active Directory through lightweight agents, so no hash is stored in the cloud and on-premises policies such as logon hours apply at sign-in. Password hash synchronization, whether through Connect Sync or Cloud Sync, stores a hash of the password hash in Microsoft Entra ID. AD FS would meet the policy but adds the federation servers the company does not want.

    Open this question on its own page →
  2. Sample · question 2 · Key Vault key rotation policy

    Burnside Logistics uses customer-managed keys in Azure Key Vault to encrypt several storage accounts. Compliance requires a new key version every 180 days and a notification 30 days before a key expires, with no manual steps. What should you recommend?

    • A.Set a 180-day expiration date on each key and rely on Azure Advisor alerts
    • B.Create an Azure Automation runbook that generates a new key every 180 days and updates each storage account
    • C.Rotate the storage account access keys every 180 days
    • D.Configure a key rotation policy on each key with automatic rotation and a near-expiry notification, and configure the storage accounts to use the latest key version automaticallycorrect

    Why: A Key Vault rotation policy creates new key versions on a schedule and can raise a near-expiry event through Event Grid, and services such as Azure Storage can automatically pick up the latest version of a customer-managed key. A runbook is custom automation to maintain. Storage access keys are unrelated to encryption keys, and an expiration date alone does not create a new version.

    Open this question on its own page →
  3. Sample · question 3 · Queue Storage for large simple backlogs

    Copperfield Print queues work items for background processing. Messages are small, ordering and transactions are not needed, and during seasonal peaks the backlog in a single queue can exceed 80 GB. The team wants the simplest and cheapest messaging service. What should you recommend?

    • A.An Event Grid topic with a webhook subscriber
    • B.Service Bus queues in the Standard tier
    • C.Azure Queue Storagecorrect
    • D.An event hub that retains events for seven days

    Why: Queue Storage offers simple, low-cost queues whose total size is limited only by the storage account's capacity, which suits very large backlogs when advanced broker features are not needed. Service Bus queues have a maximum entity size of tens of gigabytes and add features this workload does not use. Event Grid delivers events rather than holding a work backlog, and Event Hubs is built for telemetry streams.

    Open this question on its own page →
  4. Sample · question 4 · API Management multi-region deployment

    Dunstan Retail wants API consumers in Europe, North America, and Asia to call nearby API gateways, while administrators manage one API Management instance with a single configuration. Which API Management tier should you recommend?

    • A.Standard v2
    • B.Premium (classic) with additional gateway regionscorrect
    • C.Premium v2
    • D.Consumption

    Why: Multi-region deployment, where one API Management instance runs managed gateways in several Azure regions, is supported in the classic Premium tier. Premium v2, Standard v2, and Consumption do not support multi-region deployment, so they would require separate instances in each region. Multi-region gateways also improve availability when one region has an outage.

    Open this question on its own page →
  5. Sample · question 5 · Dedicated Host for physical isolation

    Eskdale Defense requires that its Windows Server VMs run on physical servers dedicated to its own subscription, with control over when platform maintenance is applied, and it wants to use existing Windows Server licenses. What should you recommend?

    • A.Isolated App Service plans in an App Service Environment
    • B.Spot virtual machines in an availability set
    • C.Azure Dedicated Host with a maintenance configurationcorrect
    • D.Confidential virtual machines

    Why: Dedicated Host provides physical servers used only by the customer, supports maintenance configurations to control when platform updates are applied, and supports Azure Hybrid Benefit for Windows Server. Confidential VMs encrypt memory but still run on shared hosts. Spot VMs can be evicted at any time, and an App Service Environment hosts web apps, not general-purpose VMs.

    Open this question on its own page →
  6. Sample · question 6 · Private Link service for SaaS providers

    Fairview Analytics runs a SaaS reporting service behind a Standard Load Balancer in its own Azure subscription. Customers want to reach the service privately from their own virtual networks, without VNet peering and without overlapping address conflicts. What should you recommend that Fairview deploy?

    • A.An Azure Private Link service attached to the load balancer, which customers connect to by using private endpointscorrect
    • B.VNet peering from each customer virtual network to Fairview's virtual network
    • C.A virtual network service endpoint on Fairview's subnet
    • D.A site-to-site VPN from each customer to Fairview

    Why: A Private Link service exposes a service behind a Standard Load Balancer so consumers in other tenants can connect through private endpoints in their own virtual networks; traffic uses Microsoft's backbone, and overlapping address spaces are not a problem. Peering and VPNs require non-overlapping addresses and expose wider network access. Service endpoints apply to Azure PaaS services, not to a provider's own service.

    Open this question on its own page →
  7. Sample · question 7 · Event Hubs Kafka endpoint

    Gisburn Media has dozens of producer applications that publish to Apache Kafka. It wants to move to a managed Azure service without rewriting producers, changing only connection configuration. What should you recommend?

    • A.Azure Event Hubs in the Basic tier
    • B.Azure Service Bus Premium with topics
    • C.Azure Event Grid namespaces with MQTT
    • D.Azure Event Hubs in the Standard tier or higher, using its Kafka endpointcorrect

    Why: Event Hubs provides an endpoint compatible with the Apache Kafka protocol, so existing Kafka clients can connect by changing their bootstrap server and authentication settings; the Kafka endpoint is not available in the Basic tier. Service Bus uses AMQP rather than the Kafka protocol. Event Grid's MQTT broker serves MQTT clients, not Kafka producers.

    Open this question on its own page →
  8. Sample · question 8 · Template specs for versioned templates

    Heathfield Group's platform team maintains approved Bicep templates for storage accounts and virtual networks. Application teams in many subscriptions should deploy only versioned, approved templates that the platform team publishes and controls access to with Azure RBAC. What should you recommend?

    • A.Create an Azure Blueprints definition for each template
    • B.Store the templates in a public GitHub repository and share links
    • C.Email the templates to application teams after each change
    • D.Publish the templates as template specs with version numbers and grant application teams Reader accesscorrect

    Why: Template specs store ARM templates, including those compiled from Bicep, as Azure resources with versions, and access is controlled with Azure RBAC so teams deploy published versions. A public repository exposes the templates and offers no access control in Azure, and email distribution has no versioning or governance. Azure Blueprints was retired in July 2026.

    Open this question on its own page →
  9. Sample · question 9 · Cosmos DB for Apache Cassandra

    Ivybridge Telecom's application uses CQL to talk to an Apache Cassandra cluster. It wants a fully managed service with global distribution and no nodes or clusters to size, patch, or repair, while keeping its CQL code. What should you recommend?

    • A.Azure Cosmos DB for NoSQL
    • B.Azure Managed Instance for Apache Cassandra
    • C.Azure Cosmos DB for Apache Cassandracorrect
    • D.Azure Table Storage

    Why: Azure Cosmos DB for Apache Cassandra supports the Cassandra wire protocol and CQL, with throughput-based scaling and turnkey global distribution and no nodes to manage. Managed Instance for Apache Cassandra automates operations but still requires choosing and scaling node-based datacenters. The NoSQL API and Table Storage would require rewriting the data access code.

    Open this question on its own page →
  10. Sample · question 10 · Resource Graph for cross-subscription inventory

    Jesmond Holdings has more than 200 subscriptions. The governance team needs to list, within seconds, every virtual machine that has no CostCenter tag, across all subscriptions, and export the list on demand. What should you recommend?

    • A.Query the activity log of each subscription in Log Analytics
    • B.Run an Azure Resource Graph query across the subscriptionscorrect
    • C.Run a PowerShell script that calls Get-AzVM in each subscription in turn
    • D.Open Cost Management cost analysis grouped by tag

    Why: Azure Resource Graph queries resource properties, including tags, across many subscriptions at once with KQL and returns results quickly. Activity logs record operations rather than the current state of resources. Cost analysis shows spending rather than a resource inventory, and looping through subscriptions with PowerShell is slow and needs maintenance.

    Open this question on its own page →
  11. Sample · question 11 · Azure Data Explorer for telemetry analytics

    Kirkby Robotics collects billions of telemetry records per day from factory machines and needs interactive, ad hoc analysis with KQL, including time-series functions and anomaly detection, with results returned in seconds over months of data. What should you recommend?

    • A.Azure Data Explorercorrect
    • B.Azure Cosmos DB for Table
    • C.Azure SQL Database in the General Purpose tier
    • D.Azure Blob Storage with the cool access tier

    Why: Azure Data Explorer is designed for fast, interactive analytics over large volumes of telemetry and log data with KQL, including native time-series analysis and anomaly detection functions. A General Purpose SQL database is not built for billions of rows per day of ad hoc telemetry analysis. Blob Storage stores data without a query engine, and Cosmos DB for Table is a key-value store.

    Open this question on its own page →
  12. Sample · question 12 · Performance-based sizing in Azure Migrate

    Lindale Foods is assessing 250 on-premises servers with Azure Migrate. Many servers are overprovisioned, and the company wants Azure VM sizes recommended from actual CPU and memory utilization collected over a month, with headroom for peaks. What should you recommend?

    • A.Create an assessment with performance-based sizing, a one-month performance history, and a comfort factorcorrect
    • B.Use Azure Advisor right-sizing recommendations before migration
    • C.Size VMs to match each server's configured vCPU and memory exactly
    • D.Create an assessment with as on-premises sizing

    Why: Performance-based sizing uses utilization data collected by Azure Migrate over the chosen period, and the comfort factor adds headroom for peaks and growth. As on-premises sizing, like matching configured vCPU and memory, copies the overprovisioning into Azure. Azure Advisor analyzes resources already running in Azure, not servers that have not been migrated.

    Open this question on its own page →

Like the sample?

Other practice exams