AZ-204: Developing Solutions for Microsoft Azure — Questions and Answers
Question 1: What Azure AD object represents an application's identity and is used to authenticate against Azure AD to obtain tokens?
- Managed identity
- User principal
- Enterprise application
- Service principal (Correct answer)
Correct answer: Service principal
A service principal is the local representation of an Azure AD application registration within a tenant, used for authentication and authorization.
Question 2: What is the default maximum size for a single Azure Blob Storage block blob?
- 4.75 TB (Correct answer)
- 5 TB
- 500 GB
- 200 GB
Correct answer: 4.75 TB
A block blob can be up to 4.75 TB in size, composed of up to 50,000 blocks each up to 100 MB.
Question 3: What header must a client include when calling an Azure AD-protected API to prove it has a valid access token?
- Authorization: Bearer {token} (Correct answer)
- Access-Token: {token}
- X-Auth-Token: Bearer {token}
- X-MS-Token: {token}
Correct answer: Authorization: Bearer {token}
APIs protected by Azure AD expect the access token in the HTTP `Authorization` header using the `Bearer` scheme.
Question 4: A developer must ensure that Azure App Service running a regulated workload cannot deploy code unless it has passed a security scan. Which DevOps control enforces this gate?
- Release pipeline approval gates with security scan task (Correct answer)
- Azure Policy DeployIfNotExists effect
- Azure App Service deployment slots
- Azure Resource Manager template validation
Correct answer: Release pipeline approval gates with security scan task
Release pipeline approval gates with a security scan task block deployment promotion until scan results meet defined quality criteria.
Question 5: What is the purpose of Azure AD Application Roles defined in an app's manifest?
- Implement role-based authorization within the application (Correct answer)
- Assign Azure RBAC roles to users
- Define Conditional Access policies
- Configure multi-tenant access
Correct answer: Implement role-based authorization within the application
Application Roles defined in the app manifest let you implement custom RBAC within your application using `roles` claims in the access token.
Question 6: In Azure Functions, which trigger type monitors a Service Bus queue depth and automatically scales instances to process backlogged messages?
- Service Bus trigger (Correct answer)
- Timer trigger
- Event Grid trigger
- HTTP trigger
Correct answer: Service Bus trigger
The Service Bus trigger integrates with KEDA-based scaling to spin up additional function instances as queue depth increases.
Question 7: A developer needs to comply with SOC 2 controls by ensuring all data at rest in Azure Storage is encrypted. What is the correct professional action?
- Store data in an unencrypted format and hash the filenames
- Manually encrypt files before uploading using a custom algorithm
- Verify that Azure Storage Service Encryption is enabled, which is on by default (Correct answer)
- Use a third-party encryption tool after writing to storage
Correct answer: Verify that Azure Storage Service Encryption is enabled, which is on by default
Azure Storage Service Encryption encrypts all data at rest by default using AES-256, satisfying compliance requirements without additional configuration.
Question 8: A .NET application deployed to Azure App Service needs to write logs that can be queried in Log Analytics. Which approach integrates natively with Azure Monitor?
- Use Application Insights SDK with ILogger integration to send structured telemetry (Correct answer)
- Use Log4Net to write to a custom Azure Table Storage sink
- Write logs to a local file and use Azure Blob Storage log archiving
- Write logs to Console.WriteLine and enable App Service Logs streaming
Correct answer: Use Application Insights SDK with ILogger integration to send structured telemetry
The Application Insights SDK integrates with .NET's ILogger to capture structured logs and send them to Application Insights, which stores data in a Log Analytics workspace queryable via KQL.
Question 9: What Azure CLI command deploys a container image from Azure Container Registry to Azure Container Instances?
- az acr deploy
- az aci create
- az container create (Correct answer)
- az aks deploy
Correct answer: az container create
The `az container create` command provisions a new Azure Container Instances group from a specified container image.
Question 10: An Azure developer must ensure their web app meets the AZ-204 requirement for secure secret management. Which approach is the recommended best practice?
- Pass secrets as query string parameters to API calls
- Store secrets in appsettings.json committed to source control
- Use Azure Key Vault references in App Service configuration (Correct answer)
- Hard-code secrets in environment variables inside Dockerfile
Correct answer: Use Azure Key Vault references in App Service configuration
Azure Key Vault references allow App Service to fetch secrets at runtime without exposing them in code or config files.
Question 11: You need to mock an external HTTP dependency in an ASP.NET Core integration test without hitting the real endpoint. What is the recommended approach?
- Use a static HttpClient instance shared across tests
- Call the real endpoint but ignore its response
- Disable TLS verification on the HttpClient
- Replace the HttpClient with a mock using IHttpClientFactory and a custom DelegatingHandler (Correct answer)
Correct answer: Replace the HttpClient with a mock using IHttpClientFactory and a custom DelegatingHandler
A custom DelegatingHandler registered via IHttpClientFactory intercepts outbound requests and returns canned responses without making real network calls.
Question 12: Which claim in an Azure AD access token uniquely identifies the tenant that issued the token?
- oid
- sub
- tid (Correct answer)
- iss
Correct answer: tid
The `tid` claim contains the Azure AD tenant ID (GUID) of the directory that issued the token.
Question 13: Which Azure service provides a fully managed environment to run Selenium-based UI tests at scale across multiple browsers?
- Azure Load Testing
- Azure DevTest Labs
- Azure Test Plans (Correct answer)
- Azure Kubernetes Service
Correct answer: Azure Test Plans
Azure Test Plans includes exploratory and manual testing tools and integrates with automated test runners including Selenium for browser-based tests.
Question 14: Which Cosmos DB consistency level provides the best read performance for a single-region account?
- Bounded Staleness
- Session
- Strong
- Eventual (Correct answer)
Correct answer: Eventual
Eventual consistency offers the lowest latency and highest throughput by allowing reads to return any replica's data without ordering guarantees.
Question 15: What is the recommended way to allow an Azure App Service to read secrets from Azure Key Vault without managing credentials?
- Use a Key Vault reference with a system-assigned managed identity (Correct answer)
- Pass the client secret via environment variable
- Use a service principal with a certificate in App Settings
- Store the Key Vault access key in App Settings
Correct answer: Use a Key Vault reference with a system-assigned managed identity
Key Vault references in App Service use the app's managed identity to fetch secrets automatically at runtime with no credential storage.
Question 16: Which Azure AD feature allows you to require multi-factor authentication for users accessing specific applications based on risk signals?
- Azure AD Identity Protection
- Privileged Identity Management
- Azure AD B2B
- Conditional Access (Correct answer)
Correct answer: Conditional Access
Conditional Access policies evaluate signals such as user, location, device, and app to enforce access controls like MFA.
Question 17: Your Azure Logic App workflow must send an HTTP request to an external API and wait up to 48 hours for an asynchronous callback. Which pattern should you implement?
- Use an Azure Function to proxy and hold the connection open
- Polling action loop with a 1-minute delay between polls
- HTTP action with a 48-hour timeout parameter
- Webhook action that pauses the workflow until the callback URL is called (Correct answer)
Correct answer: Webhook action that pauses the workflow until the callback URL is called
Logic Apps' Webhook action subscribes to a callback URL and pauses execution, resuming only when the external service calls back — supporting waits of days without polling.
Question 18: In Azure, a company hosts web apps. Azure Monitor is used by the company. You see that some of the online apps have had their configurations changed. You'll need to figure out what's changed in the setting. Which Azure Monitor logs do you need to look at?
- AppServiceAuditLogs (Correct answer)
- AppServiceEnvironmentPlatformLogs
- AppServiceApplogs
- AppServiceConsoteLogs
Correct answer: AppServiceAuditLogs
The correct answer: <br> AppServiceAuditLogs
Question 19: Which C# class in the Azure.Messaging.ServiceBus SDK is used to send messages to a Service Bus queue or topic?
- ServiceBusClient
- ServiceBusProcessor
- ServiceBusReceiver
- ServiceBusSender (Correct answer)
Correct answer: ServiceBusSender
ServiceBusSender is the class used to send messages to a Service Bus queue or topic, created by calling ServiceBusClient.CreateSender() with the target queue or topic name.
Question 20: Which approach best demonstrates professional competency in AZ-204 practice?
- Following only personal preferences
- Relying solely on initial training
- Integrating continuing education, practical experience, and evidence-based decision making (Correct answer)
- Avoiding challenging situations
Correct answer: Integrating continuing education, practical experience, and evidence-based decision making
This is fundamental to AZ-204 - Microsoft Azure Developer Associate practice. Integrating continuing education, practical experience, and evidence-based decision making represents the professional standard for professional standards in the AZ-204 certification framework.
Question 21: What is a risk mitigation strategy in AZ-204 - Microsoft Azure Developer Associate practice?
- Ignoring low-probability risks
- Only addressing risks after they occur
- Implementing controls that reduce the likelihood or impact of identified risks (Correct answer)
- Transferring all responsibility
Correct answer: Implementing controls that reduce the likelihood or impact of identified risks
This is fundamental to AZ-204 - Microsoft Azure Developer Associate practice. Implementing controls that reduce the likelihood or impact of identified risks represents the professional standard for risk management in the AZ-204 certification framework.
Question 22: How do AZ-204 professionals build trust with clients or stakeholders?
- By always agreeing with clients
- Through marketing only
- Through competitive pricing only
- Through consistent competence, transparency, reliability, and ethical behavior (Correct answer)
Correct answer: Through consistent competence, transparency, reliability, and ethical behavior
This is fundamental to AZ-204 - Microsoft Azure Developer Associate practice. Through consistent competence, transparency, reliability, and ethical behavior represents the professional standard for communication in the AZ-204 certification framework.
Question 23: Which Azure role assignment correctly follows the principle of least privilege for an application that only needs to read secrets from a Key Vault?
- Owner on the resource group containing the Key Vault
- Key Vault Contributor on the Key Vault
- Key Vault Secrets User on the Key Vault (Correct answer)
- Key Vault Administrator on the Key Vault
Correct answer: Key Vault Secrets User on the Key Vault
Key Vault Secrets User grants only get and list permissions on secrets, which is the minimum required for an application to read secrets without any management rights.
Question 24: An Azure developer is implementing feature flags for a progressive rollout. Which Azure service provides dynamic feature flag management without redeployment?
- Azure App Configuration with feature management (Correct answer)
- Azure Key Vault with versioned secrets
- Azure Storage Table with a flags column
- Azure DevOps pipeline variables
Correct answer: Azure App Configuration with feature management
Azure App Configuration's feature management capability allows feature flags to be toggled at runtime without requiring a new deployment.
Question 25: An Event Grid subscription has dead-lettering enabled. Events that cannot be delivered after all retries are exhausted are sent where?
- The Event Grid system topic dead-letter queue
- An Azure Service Bus dead-letter subqueue
- A configured Azure Storage blob container (Correct answer)
- Back to the event publisher
Correct answer: A configured Azure Storage blob container
Event Grid dead-lettering stores undeliverable events in an Azure Storage Blob container that you configure on the event subscription.
Question 26: What is the partition key in Azure Cosmos DB primarily used for?
- Sorting documents alphabetically
- Distributing data across physical partitions for scalability (Correct answer)
- Setting TTL on documents
- Encrypting stored data
Correct answer: Distributing data across physical partitions for scalability
The partition key determines how Cosmos DB distributes data and requests across physical partitions to achieve horizontal scalability.
Question 27: A team migrating from an on-premises Kafka cluster to Azure wants to reuse existing Kafka producer and consumer code unchanged. Which Azure service supports the Kafka protocol surface natively?
- Azure Service Bus with AMQP bridge
- Azure Event Hubs with Kafka endpoint enabled (Correct answer)
- Azure Event Grid with Kafka schema
- Azure IoT Hub with Kafka connector
Correct answer: Azure Event Hubs with Kafka endpoint enabled
Event Hubs exposes a Kafka-compatible endpoint so existing Kafka clients can connect without code changes by pointing to the Event Hubs namespace.
Question 28: Which Azure Event Grid schema is based on the CNCF CloudEvents 1.0 specification for cross-platform event interoperability?
- CloudEvents Schema (Correct answer)
- Azure Event Schema Registry
- Custom Input Schema
- Event Grid Schema
Correct answer: CloudEvents Schema
Azure Event Grid supports the CloudEvents 1.0 schema, the CNCF open standard that provides a common format for describing event data across platforms and cloud providers.
Question 29: In Azure Cosmos DB, what is the unit used to measure provisioned throughput?
- Compute Units (CUs)
- IO Operations per Second (IOPS)
- Request Units (RUs) (Correct answer)
- Data Throughput Units (DTUs)
Correct answer: Request Units (RUs)
Cosmos DB uses Request Units per second (RU/s) to represent the throughput provisioned for a database or container.
Question 30: Which Azure Key Vault object type stores asymmetric cryptographic keys used for signing and encryption operations?
- Secret
- Managed HSM
- Certificate
- Key (Correct answer)
Correct answer: Key
Azure Key Vault Keys store RSA or EC cryptographic key material and support operations such as encrypt, decrypt, sign, and verify.
Question 31: How should an AZ-204 professional handle an outcome that differs from expectations?
- Blame external factors
- Ignore the discrepancy
- Analyze contributing factors, document findings, and adjust approach based on lessons learned (Correct answer)
- Repeat the same approach
Correct answer: Analyze contributing factors, document findings, and adjust approach based on lessons learned
This is fundamental to AZ-204 - Microsoft Azure Developer Associate practice. Analyze contributing factors, document findings, and adjust approach based on lessons learned represents the professional standard for practical in the AZ-204 certification framework.
Question 32: Which Azure Blob Storage feature allows you to enforce immutability policies to prevent blobs from being deleted or overwritten?
- Legal hold
- Versioning
- Soft delete
- Immutable storage (WORM policies) (Correct answer)
Correct answer: Immutable storage (WORM policies)
Immutable blob storage supports time-based retention and legal hold WORM (Write Once Read Many) policies to prevent modification or deletion.
Question 33: An AZ-204 candidate must configure Azure Functions to use Managed Identity instead of connection strings for Key Vault access. What is the primary compliance benefit?
- Lower latency for secret retrieval
- Eliminates static credentials that must be rotated and audited (Correct answer)
- Allows secrets to be stored in environment variables
- Enables cross-tenant secret sharing
Correct answer: Eliminates static credentials that must be rotated and audited
Managed Identity eliminates long-lived static credentials, reducing the risk of credential leakage and simplifying compliance with rotation requirements.
Question 34: A developer is building a chat application with Azure SignalR Service in Azure Functions using the serverless hosting mode. How does the client establish a connection?
- Establish a Service Bus relay connection through the function
- Use an HTTP long-poll to the Azure Function every second
- Negotiate with a function endpoint to get the SignalR connection info, then connect directly to the SignalR Service (Correct answer)
- Connect directly to the Azure Function URL using WebSockets
Correct answer: Negotiate with a function endpoint to get the SignalR connection info, then connect directly to the SignalR Service
In serverless mode, clients call a negotiate function to receive the SignalR Service endpoint and access token, then connect directly to the service.
Question 35: Which Azure AD consent type must an administrator grant for an application to access organization-wide resources like all users' calendars?
- Delegated user consent
- Incremental consent
- Static consent
- Admin consent (Correct answer)
Correct answer: Admin consent
Admin consent is required for application permissions and high-privilege delegated permissions that access data across the entire organization.
Question 36: How do you enable soft delete for Azure Blob Storage to protect against accidental deletion?
- Enable soft delete on the storage account Data Protection blade and set a retention period (Correct answer)
- Set a lifecycle management rule with deleteBlob action disabled
- Apply a WORM immutability policy
- Configure Azure Backup for the storage account
Correct answer: Enable soft delete on the storage account Data Protection blade and set a retention period
Enabling soft delete on the storage account's Data Protection settings retains deleted blobs for a configurable number of days before permanent removal.
Question 37: A developer wants to automatically archive all Event Hubs events to Azure Blob Storage for offline analytics. Which feature should they enable?
- Diagnostic settings export
- Stream Analytics output
- Event Hubs Auto-Inflate
- Event Hubs Capture (Correct answer)
Correct answer: Event Hubs Capture
Event Hubs Capture automatically delivers streaming events to Azure Blob Storage or Data Lake in Avro format at configurable time/size intervals.
Question 38: Your organization must comply with FedRAMP Moderate. Which Azure environment is pre-authorized for FedRAMP Moderate workloads?
- Azure Commercial East US region
- Azure Stack Hub on-premises
- Azure China 21Vianet
- Azure Government cloud (Correct answer)
Correct answer: Azure Government cloud
Azure Government is specifically designed and pre-authorized for U.S. government workloads requiring FedRAMP compliance.
Question 39: Which Azure Blob Storage access tier is optimized for data that is accessed infrequently and stored for at least 30 days?
- Hot
- Premium
- Archive
- Cool (Correct answer)
Correct answer: Cool
The Cool tier is designed for infrequently accessed data with lower storage costs but higher retrieval costs, with a minimum retention of 30 days.
Question 40: Which Azure Cosmos DB API is most suitable when migrating an existing MongoDB application to Azure?
- Gremlin API
- MongoDB API (Correct answer)
- Core (SQL) API
- Cassandra API
Correct answer: MongoDB API
The MongoDB API in Cosmos DB is wire-protocol compatible with MongoDB, allowing applications to connect with minimal code changes.
Question 41: A developer uses Azure API Management to expose a backend API. Some API operations should only be accessible to users with the 'admin' role in their JWT token. How should you enforce this in APIM?
- Configure OAuth 2.0 in the APIM Developer Portal subscription settings
- Add a validate-jwt inbound policy that checks the roles claim (Correct answer)
- Enable Azure AD authentication on the backend API itself
- Use a product-level subscription key scoped to admin users
Correct answer: Add a validate-jwt inbound policy that checks the roles claim
The validate-jwt inbound policy in APIM can inspect JWT claims, including roles, and return a 403 if the required role is absent — enforcing authorization at the gateway layer.
Question 42: Which OAuth 2.0 flow should a daemon application use to acquire an Azure AD token when acting on its own behalf with no user interaction?
- Client Credentials flow (Correct answer)
- Implicit flow
- On-Behalf-Of flow
- Authorization Code flow
Correct answer: Client Credentials flow
The Client Credentials flow authenticates the application itself using a client ID and secret/certificate, with no user involved.
Question 43: What Azure Key Vault feature enables automatic renewal of TLS certificates from supported certificate authorities?
- Key rotation policy
- Secret versioning
- Certificate import
- Certificate auto-renewal (lifecycle action) (Correct answer)
Correct answer: Certificate auto-renewal (lifecycle action)
Key Vault certificates support lifecycle auto-renewal actions that automatically request a new certificate from DigiCert or GlobalSign before expiry.
Question 44: A developer needs to ensure that related Azure Service Bus messages are processed in order by the same consumer. Which feature should they enable?
- Scheduled delivery
- Message sessions (Correct answer)
- Duplicate detection
- Dead-letter queue
Correct answer: Message sessions
Message sessions in Service Bus group related messages and guarantee FIFO processing by a single consumer holding the session lock.
Question 45: You're in charge of a data processing program that gets requests from an Azure Storage queue. <br> <br> You must control who has access to the queue. You must meet the following criteria: <br> <br> Allow access to the Azure queue for other applications. <br> <br> Make sure you can disable queue access without having to re-generate the storage account keys. <br> <br> Access should be specified at the queue level rather than at the storage account level. <br> <br> Should you use a shared access signature (SAS) of a certain type?
- Service SAS with ad hoc SAS
- Service SAS with a stored access policy (Correct answer)
- Account SAS
- User Delegation SAS
Correct answer: Service SAS with a stored access policy
Explanation: <br> The storage account key protects SAS. SAS grants access to a resource in only one of the Azure Storage services: Blob storage, Queue storage, Table storage, or Azure Files. <br> <br> You can revoke rights for a service SAS using stored access policies rather than having to regenerate the storage account keys.
Question 46: What is the first step in risk assessment for AZ-204 - Microsoft Azure Developer Associate professionals?
- Purchasing insurance
- Identifying potential hazards and vulnerabilities in the specific context (Correct answer)
- Delegating to others
- Implementing controls immediately
Correct answer: Identifying potential hazards and vulnerabilities in the specific context
This is fundamental to AZ-204 - Microsoft Azure Developer Associate practice. Identifying potential hazards and vulnerabilities in the specific context represents the professional standard for risk management in the AZ-204 certification framework.
Question 47: Which SAS type in Azure Blob Storage is signed with the storage account key and grants access to the entire service?
- Service SAS
- User delegation SAS
- Managed Identity SAS
- Account SAS (Correct answer)
Correct answer: Account SAS
An Account SAS is signed with the storage account key and can grant access to resources across multiple storage services.
Question 48: A company's App Service web app must access an internal SQL Server hosted on-premises without exposing it to the public internet. What is the recommended connectivity option?
- Use Azure VPN Gateway with site-to-site VPN and VNet Integration
- Whitelist the App Service outbound IPs in the on-premises firewall
- Configure Hybrid Connections on the App Service to reach the on-premises SQL Server (Correct answer)
- Deploy an Azure Application Gateway in front of the SQL Server
Correct answer: Configure Hybrid Connections on the App Service to reach the on-premises SQL Server
Hybrid Connections use an outbound TCP relay via Service Bus, requiring no inbound firewall rules and no VNet, making it the simplest option for App Service to on-premises connectivity.
Question 49: Which Azure Functions binding type allows a function to output a message to an Azure Service Bus queue?
- queueTrigger
- serviceBus output binding (Correct answer)
- serviceBusTrigger
- eventHubTrigger
Correct answer: serviceBus output binding
The Service Bus output binding writes messages to a Service Bus queue or topic from an Azure Function.
AZ-204: Developing Solutions for Microsoft Azure
The AZ-204 exam validates skills in designing, building, testing, and maintaining cloud applications and services on Microsoft Azure. It covers compute solutions, Azure storage, security, monitoring, and connecting to Azure and third-party services.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds