AZ-300: Microsoft Azure Architect Technologies — Questions and Answers
Question 1: Which Azure RBAC role allows full management of all Azure resources but does not allow assignment of roles to others?
- Contributor (Correct answer)
- User Access Administrator
- Reader
- Owner
Correct answer: Contributor
The Contributor role grants full create/read/update/delete access to resources but cannot assign Azure roles to others — that requires Owner or User Access Administrator.
Question 2: In the e-commerce web app, you must access user claims. What should you start with?
- Using the Resource Manager create role assignment API, assign the Contributor RBAC role to the e-commerce web app.
- Enable cross-origin resource sharing (CORS) from the e-commerce checkout API to the e-commerce web using the Azure CU.
- Make a Microsoft Graph API call from the ecommerce web app using custom code. (Correct answer)
- To access the HTTP request header values, update the e-commerce web app.
Correct answer: Make a Microsoft Graph API call from the ecommerce web app using custom code.
To access comprehensive user claims beyond basic identity information in an e-commerce web app, the most effective method is to make a Microsoft Graph API call using custom code. The Microsoft Graph API provides a unified endpoint for accessing data across Microsoft 365, including detailed user profiles and claims from Azure AD. The web app can obtain an access token and then use it to query the Graph API for the specific user's claims, ensuring access to rich and up-to-date information.
Question 3: What is the purpose of Diagnostic Settings in Azure Monitor?
- Configure where resource logs and metrics are sent (Log Analytics, Storage, Event Hub) (Correct answer)
- Set RBAC permissions on resources
- Patch Azure resources automatically
- Create custom dashboards
Correct answer: Configure where resource logs and metrics are sent (Log Analytics, Storage, Event Hub)
Diagnostic Settings route a resource's platform logs and metrics to one or more destinations: Log Analytics workspace, Azure Storage, or Azure Event Hub.
Question 4: What is the maximum number of fault domains supported by an Azure Availability Set?
- 5
- 3 (Correct answer)
- 2
- 10
Correct answer: 3
Azure Availability Sets support up to 3 fault domains, which correspond to separate physical racks with independent power and network within a datacenter.
Question 5: What is the minimum subnet size required for an Azure Application Gateway v2 deployment?
- /24
- /29
- /26 (Correct answer)
- /28
Correct answer: /26
Azure Application Gateway v2 requires a dedicated subnet with at least a /26 CIDR block to accommodate scaling and management addresses.
Question 6: What feature of Azure Storage allows you to automatically move blobs between access tiers based on age or last access time?
- Immutable Blob Storage
- Storage Policies
- Lifecycle Management Policies (Correct answer)
- Object Replication
Correct answer: Lifecycle Management Policies
Azure Blob Lifecycle Management policies automatically transition or delete blobs based on rules you define, such as moving to Cool after 30 days.
Question 7: What Azure feature enables you to reserve compute capacity for VMs in a specific region, guaranteeing availability even during capacity constraints?
- On-Demand Instances
- Spot Instances
- Reserved Instances
- Capacity Reservations (Correct answer)
Correct answer: Capacity Reservations
Azure Capacity Reservations allow you to reserve compute capacity in a region, ensuring it is available when needed without committing to a specific VM.
Question 8: What is an Action Group in Azure Monitor?
- A policy assignment scope
- A set of RBAC permissions
- A reusable collection of notification and remediation actions triggered when an alert fires (Correct answer)
- A group of Azure resources for billing
Correct answer: A reusable collection of notification and remediation actions triggered when an alert fires
Action Groups define who gets notified (email, SMS, webhook) and what automated actions occur (runbook, function, ITSM) when an Azure Monitor alert is triggered.
Question 9: What is the purpose of Azure Storage shared access signatures (SAS)?
- Grant limited, time-bound access to storage resources without sharing the account key (Correct answer)
- Encrypt storage account data
- Manage storage account firewall rules
- Enable cross-region replication
Correct answer: Grant limited, time-bound access to storage resources without sharing the account key
SAS tokens provide delegated, fine-grained access to Azure Storage resources with configurable permissions, IP restrictions, and expiry times.
Question 10: You configure Azure Site Recovery for a VM and initiate a planned failover to the secondary region. What happens to replication after the failover?
- The VM in the secondary region becomes standalone with no replication
- Replication stops and must be manually reconfigured
- Replication automatically reverses to replicate from the new primary back to the original region (Correct answer)
- Azure automatically fails back to the original region after 24 hours
Correct answer: Replication automatically reverses to replicate from the new primary back to the original region
After a planned failover completes, Azure Site Recovery automatically sets up reverse replication so the new primary (secondary region) now replicates back to the original region, maintaining DR protection.
Question 11: For a user called admin1@contoso.com, you set the multi-factor authentication status to Enabled. <br> Admin1 uses a web browser to access the Azure interface. <br> When accessing the Azure portal, what additional security verifications can Admin1 use?
- a phone call, an email message with a verification code, and a text message with a password for the app
- a password for the app, a verification code in a text message, and a notification from the Microsoft Authenticator app
- a phone call, a verification code-containing text message, and a notification or verification code provided through the Microsoft Authenticator app (Correct answer)
- a password for the app, a text message with a verification code, and a code sent from the Microsoft Authenticator app
Correct answer: a phone call, a verification code-containing text message, and a notification or verification code provided through the Microsoft Authenticator app
When multi-factor authentication (MFA) is enabled for a user in Azure AD, they typically have several secure verification methods available during sign-in. These commonly include receiving a phone call to their registered device, getting a text message containing a verification code, or using the Microsoft Authenticator app to either approve a push notification or generate a time-based one-time password (verification code). These options provide robust security layers beyond just a password.
Question 12: Which Azure load balancing service operates at Layer 7 (HTTP/HTTPS) and provides global distribution of web traffic with SSL offloading?
- Azure Application Gateway
- Azure Front Door (Correct answer)
- Azure Load Balancer
- Azure Traffic Manager
Correct answer: Azure Front Door
Azure Front Door operates at Layer 7 globally, providing HTTP/HTTPS load balancing, SSL offloading, WAF, and Anycast routing to the closest healthy backend across regions.
Question 13: What does the Recovery Time Objective (RTO) define in a business continuity plan?
- The geographic distance between primary and secondary regions
- The number of replicas required to meet availability SLA
- The maximum time allowed to restore business operations after a disaster (Correct answer)
- The maximum acceptable age of recovery data
Correct answer: The maximum time allowed to restore business operations after a disaster
RTO is the maximum tolerable duration of a service outage — it defines how quickly systems must be restored to avoid unacceptable business impact.
Question 14: What does Recovery Point Objective (RPO) represent in a disaster recovery plan?
- The cost associated with recovering from a disaster
- The maximum acceptable amount of data loss measured in time (Correct answer)
- The number of replicas maintained for a database
- The maximum time allowed to restore a system after a disaster
Correct answer: The maximum acceptable amount of data loss measured in time
RPO defines how much data an organization can afford to lose, expressed as the maximum age of data that must be recovered — essentially the backup frequency requirement.
Question 15: Which Azure networking service performs DNS-based global traffic distribution and supports geographic, weighted, and priority routing methods?
- Azure Traffic Manager (Correct answer)
- Azure Load Balancer
- Azure Front Door
- Azure Application Gateway
Correct answer: Azure Traffic Manager
Azure Traffic Manager uses DNS to route users to the most appropriate endpoint based on routing methods like geographic, performance, weighted, or priority.
Question 16: What is the purpose of AKS 'namespaces' in a multi-team Kubernetes environment?
- Provide logical isolation between teams or workloads within a single cluster (Correct answer)
- Encrypt inter-pod communication
- Separate cluster networking
- Assign GPU resources to pods
Correct answer: Provide logical isolation between teams or workloads within a single cluster
Kubernetes namespaces divide a cluster into virtual sub-clusters, enabling resource isolation, RBAC scoping, and quota management per team or workload.
Question 17: Which Azure AD feature detects risky sign-ins and compromised user accounts using machine learning and threat intelligence?
- Privileged Identity Management
- Identity Protection (Correct answer)
- Access Reviews
- Conditional Access
Correct answer: Identity Protection
Azure AD Identity Protection uses ML-based risk detection to identify compromised accounts and risky sign-in behaviors, triggering automated remediation policies.
Question 18: Subscription1 and Subscription2 are the names of two subscriptions you have. Each Azure AD tenant is paired with a distinct subscription. <br> VNet1 is a virtual network that is part of Subscription1. VNet1 has an IP address space of 10.0.0.0/16 and contains an Azure virtual machine named VM1. <br> VNet2 is a virtual network that is part of Subscription2. Vnet2 has an IP address space of 10.10.0.0/24 and contains an Azure virtual machine named VM2. <br> VNet1 must be connected to VNet2. <br> What should you start with?
- Move VM1 to Subscription2
- Provision virtual network gateways (Correct answer)
- Modify the IP address space of VNet2.
- Move VNet1 to Subscription2
Correct answer: Provision virtual network gateways
To connect two virtual networks (VNets) that reside in different Azure subscriptions, you need to establish a VNet-to-VNet connection. This type of connection requires provisioning a virtual network gateway in each VNet. These gateways act as the endpoints for the VPN tunnel, enabling secure and private communication between resources in VNet1 and VNet2 across the different subscriptions.
Question 19: Which Azure load balancing option provides health probing and distributes traffic at Layer 4 within a region with support for HA Ports?
- Azure Standard Load Balancer (Correct answer)
- Azure Traffic Manager
- Azure Application Gateway
- Azure Front Door
Correct answer: Azure Standard Load Balancer
Azure Standard Load Balancer operates at Layer 4 with support for HA ports, zone redundancy, and outbound rules for internet-bound traffic.
Question 20: For VM4, you must meet the technical requirements. What should you make and how should you set it up?
- an Azure Event Hub
- an Azure Logic App (Correct answer)
- an Azure Service Bus
- an Azure Notification Hub
Correct answer: an Azure Logic App
Azure Logic Apps are a serverless platform ideal for building automated workflows and integrating various services, both within Azure and externally. If VM4 has technical requirements involving orchestration of tasks, connecting to different systems, or responding to specific events, a Logic App is the best choice. It provides a visual designer to create complex, event-driven workflows without extensive coding, making it suitable for integration and automation needs.
Question 21: Which Azure Storage redundancy option replicates data synchronously across three availability zones within the same region?
- LRS
- GZRS
- GRS
- ZRS (Correct answer)
Correct answer: ZRS
Zone-Redundant Storage (ZRS) replicates data synchronously across three availability zones in a single region, protecting against datacenter failures.
Question 22: What is the purpose of Azure AD Application Proxy?
- Route API traffic to backend services
- Cache authentication tokens
- Provide secure remote access to on-premises web applications without a VPN via Azure AD authentication (Correct answer)
- Manage service principal permissions
Correct answer: Provide secure remote access to on-premises web applications without a VPN via Azure AD authentication
Azure AD Application Proxy allows remote users to securely access on-premises web applications through Azure AD, without requiring VPN or exposing the app to the internet.
Question 23: Which Azure feature prevents accidental deletion or modification of critical resources by applying a lock?
- Azure Policy Deny
- Resource Locks (CanNotDelete / ReadOnly) (Correct answer)
- RBAC Deny Assignments
- Azure Blueprints Lock
Correct answer: Resource Locks (CanNotDelete / ReadOnly)
Resource Locks apply CanNotDelete or ReadOnly constraints to resources, overriding RBAC permissions to prevent accidental deletion or modification.
Question 24: Which Azure service provides insights into the planned maintenance and service incidents that may impact your Azure resources?
- Azure Advisor
- Azure Service Health (Correct answer)
- Azure Policy
- Azure Monitor
Correct answer: Azure Service Health
Azure Service Health tracks active incidents, planned maintenance, and health advisories for Azure services in your subscriptions and regions.
Question 25: Which Azure feature replicates virtual machines to a secondary region and enables failover in the event of a regional outage?
- Azure Backup
- Azure Load Balancer
- Azure Site Recovery (Correct answer)
- Azure Traffic Manager
Correct answer: Azure Site Recovery
Azure Site Recovery (ASR) continuously replicates VMs to a secondary region and orchestrates failover to restore workloads during a disaster.
Question 26: Which Azure Storage account type supports both Azure Data Lake Storage Gen2 hierarchical namespace and Blob Storage features?
- BlobStorage account
- General Purpose v2 with HNS enabled (Correct answer)
- FileStorage account
- General Purpose v1
Correct answer: General Purpose v2 with HNS enabled
A General Purpose v2 storage account with Hierarchical Namespace enabled becomes an Azure Data Lake Storage Gen2 account supporting POSIX-like directory operations.
Question 27: What is the purpose of Azure AD Privileged Identity Management (PIM)?
- Provide just-in-time elevation of privileged roles with approval and time limits (Correct answer)
- Sync on-premises AD with Azure AD
- Monitor sign-in risk
- Manage password resets
Correct answer: Provide just-in-time elevation of privileged roles with approval and time limits
PIM enables just-in-time privileged access, requiring users to activate elevated roles for a limited time with optional approval and MFA.
Question 28: Which Azure Cosmos DB feature provides automatic failover to a secondary region with zero data loss?
- Multi-master writes with strong consistency
- Single-region writes with geo-redundancy enabled
- Multi-region writes (multi-master) configuration (Correct answer)
- Read replicas in a secondary region
Correct answer: Multi-region writes (multi-master) configuration
Multi-region writes (multi-master) in Azure Cosmos DB allow writes to any region, and with bounded staleness or strong consistency, automatic failover occurs with no data loss.
Question 29: In Azure, what is the purpose of a NAT Gateway?
- Provides private DNS resolution
- Provides inbound load balancing
- Routes traffic between VNets
- Enables outbound internet connectivity for VNet resources without exposing them with public IPs (Correct answer)
Correct answer: Enables outbound internet connectivity for VNet resources without exposing them with public IPs
Azure NAT Gateway provides scalable, reliable outbound internet connectivity for subnet resources using a pool of static public IP addresses.
Question 30: Which Azure service should you use to store OS disk images and data disk snapshots for VM backup and disaster recovery?
- Azure Managed Disks
- Azure Backup (Correct answer)
- Azure Files
- Azure Blob Storage
Correct answer: Azure Backup
Azure Backup provides a managed, policy-driven backup solution for VMs including OS and data disks.
Question 31: Which Azure service acts as a globally distributed, scalable load balancer that operates at Layer 7 and provides SSL termination and URL-based routing?
- Azure Front Door (Correct answer)
- Azure Load Balancer
- Azure Traffic Manager
- Azure Application Gateway
Correct answer: Azure Front Door
Azure Front Door is a global Layer 7 load balancer with SSL offload, URL routing, and WAF capabilities built in.
Question 32: Which Azure Traffic Manager routing method directs users to the endpoint with the lowest latency?
- Priority
- Geographic
- Weighted
- Performance (Correct answer)
Correct answer: Performance
The Performance routing method in Traffic Manager measures latency to all endpoints and directs users to the one with the lowest network latency.
Question 33: A company needs automatic DNS-based failover from a primary Azure region to a secondary region when the primary becomes unhealthy. Which Azure service provides this?
- Azure Application Gateway
- Azure Front Door with WAF
- Azure Load Balancer with health probes
- Azure Traffic Manager with Priority routing (Correct answer)
Correct answer: Azure Traffic Manager with Priority routing
Azure Traffic Manager with Priority routing monitors endpoint health via DNS and automatically redirects traffic to the secondary endpoint when the primary endpoint fails health checks.
Question 34: What is the maximum number of data disks that can be attached to a Standard_D8s_v3 VM?
- 64
- 32 (Correct answer)
- 16
- 8
Correct answer: 32
The Standard_D8s_v3 VM supports up to 32 data disks.
Question 35: Which Azure App Service feature allows you to run a new version of your app alongside production and swap them with no downtime?
- Traffic Manager
- Deployment Slots (Correct answer)
- WebJobs
- Custom Domains
Correct answer: Deployment Slots
Deployment Slots let you stage a new version, warm it up, then swap it into production instantly with no downtime and the ability to roll back.
Question 36: You need to protect Azure VMs with a daily backup and retain recovery points for 30 days. Which service should you use?
- Azure Backup with a Recovery Services vault (Correct answer)
- Azure Site Recovery
- Azure Blob Storage with geo-redundancy
- Azure Managed Disk snapshots via ARM templates
Correct answer: Azure Backup with a Recovery Services vault
Azure Backup with a Recovery Services vault supports policy-based daily VM backups with configurable retention periods, making it the correct service for this requirement.
Question 37: What is Azure Blob Storage 'soft delete' designed to protect against?
- Data corruption during upload
- Cross-region replication failures
- Accidental deletion or overwrite of blobs within a configurable retention period (Correct answer)
- Unauthorized access
Correct answer: Accidental deletion or overwrite of blobs within a configurable retention period
Soft delete retains deleted or overwritten blobs for a configurable number of days, allowing recovery from accidental deletions.
Question 38: On Azure virtual machines, you have a Microsoft SQL Server Always On availability group. As a listener for the availability group, you must configure an Azure internal load balancer. <br> What are your options?
- Create an HTTP health probe on port 1433
- Set Session persistence to Client IP and protocol
- Set Session persistence to Client IP
- Enable Floating lP (Correct answer)
Correct answer: Enable Floating lP
When configuring an Azure Internal Load Balancer for a SQL Server Always On Availability Group listener, it is essential to enable Direct Server Return (DSR), also known as Floating IP. This setting ensures that the primary replica (the active SQL VM) can respond directly to client requests without the response traffic having to pass back through the load balancer. This direct response mechanism is crucial for the listener to function correctly and maintain high availability for the SQL Always On group.
Question 39: For Policy Service, you must meet the scaling requirements. <br> What kind of data should you keep in Azure Redis Cache?
- ViewState
- TempData
- HttpContext.tems (Correct answer)
- Session state
Correct answer: HttpContext.tems
While `HttpContext.Items` is typically used for transient, request-scoped data within a single server instance, in highly distributed or microservices architectures, specific request context or intermediate policy evaluation results might need to be temporarily shared across multiple service instances or asynchronous operations involved in processing a single request. In such advanced scaling scenarios, `HttpContext.Items` data could be serialized and stored in a distributed cache like Azure Redis Cache to maintain context consistency across the distributed components, thereby supporting the service's scaling requirements.
Question 40: You've got an Azure Service Bus installed. <br> You'll need to set up a Service Bus queue that ensures messages are delivered first-in-first-out (FIFO). <br> So, what are your options?
- Enable duplicate detection
- Set the Lock Duration setting to 10 seconds
- Enable sessions (Correct answer)
- Set the Max Size setting of the queue to 5 GB
Correct answer: Enable sessions
The correct answer: <br> Enable sessions
Question 41: What is the purpose of Azure Dedicated Host?
- To enable faster VM boot times
- To provide a physical server dedicated to your organization for compliance (Correct answer)
- To host containers exclusively
- To share hardware with multiple tenants at a discount
Correct answer: To provide a physical server dedicated to your organization for compliance
Azure Dedicated Host provides a physical server that is dedicated to your organization, meeting compliance and regulatory isolation requirements.
Question 42: What is the purpose of Azure Private DNS Zones?
- Cache public DNS records
- Route traffic to the nearest endpoint
- Resolve custom domain names privately within VNets without exposing DNS to the internet (Correct answer)
- Provide public DNS resolution
Correct answer: Resolve custom domain names privately within VNets without exposing DNS to the internet
Azure Private DNS Zones provide name resolution for resources within Azure VNets using custom domain names that are not resolvable from the public internet.
Question 43: Which Azure Blob Storage access tier is designed for data that is rarely accessed and stored for at least 180 days, with the lowest storage cost but highest retrieval cost?
- Cool tier
- Hot tier
- Archive tier (Correct answer)
- Cold tier
Correct answer: Archive tier
The Archive tier offers the lowest storage price for rarely accessed data but requires rehydration (hours) before data can be read.
Question 44: Which Azure AD feature allows you to control access to applications based on user, device, location, and risk signals?
- Conditional Access (Correct answer)
- Privileged Identity Management
- Identity Protection
- Multi-Factor Authentication
Correct answer: Conditional Access
Conditional Access policies evaluate signals like user identity, device compliance, and location to grant, block, or require additional verification for app access.
Question 45: Which Azure feature allows you to enforce that all subscriptions in a management group comply with organizational policies and RBAC assignments by default?
- Azure RBAC Inheritance
- Azure Policy Initiatives
- Management Group Policies
- Azure Blueprints (Correct answer)
Correct answer: Azure Blueprints
Azure Blueprints package RBAC assignments, policies, and ARM templates into repeatable deployable packages, enforcing governance standards across subscriptions.
Question 46: Which feature should you enable in Azure to get a Secure Score that benchmarks your environment against security best practices?
- Microsoft Defender for Cloud (Correct answer)
- Azure Advisor
- Azure Blueprints
- Azure Sentinel
Correct answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud calculates a Secure Score by assessing your resources against security controls, providing prioritized recommendations.
Question 47: What does enabling 'secure transfer required' on an Azure Storage account enforce?
- All data must be encrypted at rest
- All connections to the storage account must use HTTPS or SMB with encryption (Correct answer)
- Blob public access is disabled
- Storage must use customer-managed keys
Correct answer: All connections to the storage account must use HTTPS or SMB with encryption
The 'secure transfer required' setting rejects any connections that use unencrypted HTTP or SMB without encryption, ensuring all data in transit is protected.
Question 48: Which Azure service provides a fully managed, cloud-native NFS and SMB file share that can be mounted by Windows, Linux, and macOS clients?
- Azure Blob Storage
- Azure Data Lake Storage
- Azure NetApp Files
- Azure Files (Correct answer)
Correct answer: Azure Files
Azure Files provides fully managed cloud file shares accessible via SMB and NFS protocols, mountable directly on VMs and on-premises machines.
Question 49: Which Azure Storage feature enables storing multiple versions of a blob, protecting against accidental overwrites?
- Snapshots
- Blob Versioning (Correct answer)
- Change Feed
- Soft Delete
Correct answer: Blob Versioning
Blob Versioning automatically preserves previous versions of a blob whenever it is overwritten, allowing restoration to any earlier version.
Question 50: Which Azure Backup retention tier stores recovery points at a lower cost for long-term archive?
- Operational tier
- Vault-standard tier
- Archive tier (Correct answer)
- Cool access tier
Correct answer: Archive tier
The Archive tier in Azure Backup stores recovery points cheaply for long-term retention (e.g., compliance requirements of 7+ years) at significantly lower cost than the vault-standard tier.
AZ-300: Microsoft Azure Architect Technologies
A retired Microsoft certification exam (replaced by AZ-303) that validates expertise in deploying and configuring Azure infrastructure, implementing workloads and security, creating and deploying apps, and developing for the cloud.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds