AZ-300: Microsoft Azure Architect Technologies — Questions and Answers
Question 1: A company needs automatic DNS-based failover from a primary Azure region to a secondary region when the primary becomes unhealthy. Which Azure service provides this?
- Azure Application Gateway
- Azure Traffic Manager with Priority routing (Correct answer)
- Azure Front Door with WAF
- Azure Load Balancer with health probes
Correct answer: Azure Traffic Manager with Priority routing
Azure Traffic Manager with Priority routing monitors endpoint health via DNS and automatically redirects traffic to the secondary endpoint when the primary endpoint fails health checks.
Question 2: You have a tenant for Azure Active Directory (Azure AD). <br> Policy1 is an Azure AD conditional access policy that you already have. When members of the Global Administrators group authenticate to Azure AD from untrusted sites, <br>Policy1 requires them to use Azure AD-joined devices. <br> When authenticating from untrusted locations, you must guarantee that members of the Global Administrators group are likewise obliged to use multi-factor authentication. <br> What are your options?
- From multi-factor authentication page, modify the user settings
- From multi-factor authentication page, modify the service settings
- From the Azure portal, modify grant control of Policy1 (Correct answer)
- From the Azure portal, modify session control of Policy1
Correct answer: From the Azure portal, modify grant control of Policy1
To enforce multi-factor authentication (MFA) within an Azure AD Conditional Access policy, you must configure the 'Grant' control. The 'Grant' control specifies the requirements users must satisfy to gain access, such as requiring MFA, a compliant device, or a hybrid Azure AD joined device. Modifying Policy1's grant control to include 'Require multi-factor authentication' will ensure Global Administrators are prompted for MFA when authenticating from untrusted locations.
Question 3: You configure Azure Site Recovery for a VM and initiate a planned failover to the secondary region. What happens to replication after the failover?
- The VM in the secondary region becomes standalone with no replication
- Replication automatically reverses to replicate from the new primary back to the original region (Correct answer)
- Azure automatically fails back to the original region after 24 hours
- Replication stops and must be manually reconfigured
Correct answer: Replication automatically reverses to replicate from the new primary back to the original region
After a planned failover completes, Azure Site Recovery automatically sets up reverse replication so the new primary (secondary region) now replicates back to the original region, maintaining DR protection.
Question 4: Which Azure Storage account type supports both Azure Data Lake Storage Gen2 hierarchical namespace and Blob Storage features?
- BlobStorage account
- General Purpose v2 with HNS enabled (Correct answer)
- FileStorage account
- General Purpose v1
Correct answer: General Purpose v2 with HNS enabled
A General Purpose v2 storage account with Hierarchical Namespace enabled becomes an Azure Data Lake Storage Gen2 account supporting POSIX-like directory operations.
Question 5: What is the maximum number of data disks that can be attached to a Standard_D8s_v3 VM?
- 32 (Correct answer)
- 64
- 8
- 16
Correct answer: 32
The Standard_D8s_v3 VM supports up to 32 data disks.
Question 6: Which Azure Storage redundancy option provides the highest durability by replicating data both zone-redundantly in the primary region and geo-redundantly to a secondary region?
- GRS
- RA-GRS
- GZRS (Correct answer)
- ZRS
Correct answer: GZRS
Geo-Zone-Redundant Storage (GZRS) combines ZRS in the primary region with asynchronous geo-replication to a secondary region for maximum durability.
Question 7: Which feature in Azure Key Vault protects against accidental deletion by requiring an additional purge step after a soft delete?
- Access Policies
- Soft Delete
- Key Versioning
- Purge Protection (Correct answer)
Correct answer: Purge Protection
Purge Protection prevents a soft-deleted Key Vault or its objects from being permanently purged for the retention period, protecting against malicious or accidental deletion.
Question 8: Which Azure Disk encryption option uses keys stored in Azure Key Vault and managed by the customer to encrypt managed disk data?
- Server-Side Encryption with Platform-Managed Keys
- Azure Disk Encryption (ADE)
- Transparent Data Encryption
- Server-Side Encryption with Customer-Managed Keys (SSE CMK) (Correct answer)
Correct answer: Server-Side Encryption with Customer-Managed Keys (SSE CMK)
SSE with Customer-Managed Keys (CMK) stores the disk encryption key in Azure Key Vault, giving customers full control over the key lifecycle.
Question 9: A company needs their Azure VMs in an Availability Set to have a guaranteed uptime SLA. What is the minimum number of VMs required to receive the 99.95% SLA?
- 3
- 4
- 2 (Correct answer)
- 1
Correct answer: 2
Azure guarantees a 99.95% SLA for VMs in an Availability Set only when at least two instances are deployed across separate fault and update domains.
Question 10: Which Azure service provides a managed, cloud-native firewall with threat intelligence filtering and application FQDN rules?
- Azure Bastion
- Application Gateway WAF
- Azure Firewall (Correct answer)
- NSG
Correct answer: Azure Firewall
Azure Firewall is a stateful, managed network security service with built-in high availability, threat intelligence, and FQDN filtering.
Question 11: What type of Managed Identity is scoped to a single Azure resource and deleted when that resource is deleted?
- User-Assigned Managed Identity
- Service Principal
- System-Assigned Managed Identity (Correct answer)
- Application Registration
Correct answer: System-Assigned Managed Identity
A System-Assigned Managed Identity is tied to the lifecycle of a single Azure resource and is automatically created and deleted with that resource.
Question 12: What is the SLA guarantee for Azure VMs deployed across two or more Availability Zones?
- 99.99% (Correct answer)
- 99.9%
- 100%
- 99.95%
Correct answer: 99.99%
Azure guarantees a 99.99% SLA for VMs when two or more instances are deployed in two or more Availability Zones within the same region.
Question 13: What is the benefit of enabling 'Accelerated Networking' on an Azure VM?
- Automatically scales the VM
- Increases disk IOPS
- Bypasses the host vSwitch for lower latency and higher throughput (Correct answer)
- Enables RDMA between VMs
Correct answer: Bypasses the host vSwitch for lower latency and higher throughput
Accelerated Networking uses SR-IOV to bypass the host virtual switch, providing significantly lower latency and higher network throughput.
Question 14: What is the maximum size of an Azure Virtual Network address space?
- /8 (Correct answer)
- /24
- /16
- /28
Correct answer: /8
Azure Virtual Networks support address spaces from /8 to /29, making /8 the largest possible CIDR block.
Question 15: What does Recovery Point Objective (RPO) represent in a disaster recovery plan?
- The number of replicas maintained for a database
- The maximum acceptable amount of data loss measured in time (Correct answer)
- The cost associated with recovering from a disaster
- The maximum time allowed to restore a system after a disaster
Correct answer: The maximum acceptable amount of data loss measured in time
RPO defines how much data an organization can afford to lose, expressed as the maximum age of data that must be recovered — essentially the backup frequency requirement.
Question 16: In Azure, what is VNet Peering used for?
- Connecting Azure VNets across regions or subscriptions with low-latency private traffic (Correct answer)
- Encrypting traffic between VNets
- Providing internet access to VMs
- Connecting VNets in the same subscription only
Correct answer: Connecting Azure VNets across regions or subscriptions with low-latency private traffic
VNet Peering connects Azure Virtual Networks privately across regions (Global VNet Peering) or within the same region using the Microsoft backbone.
Question 17: What is an Azure App Service Environment (ASE)?
- A fully isolated, dedicated App Service deployment within your VNet for compliance and high-scale workloads (Correct answer)
- A shared multi-tenant App Service deployment
- A container orchestration service
- A free tier with VNet access
Correct answer: A fully isolated, dedicated App Service deployment within your VNet for compliance and high-scale workloads
An ASE is a single-tenant deployment of Azure App Service injected directly into a customer's VNet, providing complete network isolation and dedicated compute.
Question 18: Which Azure service enables bidirectional file sync between on-premises Windows Server file shares and Azure Files?
- Azure Data Box
- Azure File Sync (Correct answer)
- StorSimple
- Azure Import/Export
Correct answer: Azure File Sync
Azure File Sync keeps on-premises Windows Server shares in sync with Azure Files, enabling cloud tiering to free up local storage.
Question 19: Which Azure Monitor feature allows you to capture and analyze network traffic for VMs to diagnose connectivity issues?
- NSG Flow Logs
- Application Insights
- Network Watcher - Packet Capture (Correct answer)
- Traffic Manager Monitoring
Correct answer: Network Watcher - Packet Capture
Azure Network Watcher Packet Capture records network packets to/from a VM, enabling deep network traffic analysis for troubleshooting.
Question 20: For Policy Service, you must meet the scaling requirements. <br> What kind of data should you keep in Azure Redis Cache?
- Session state
- TempData
- ViewState
- HttpContext.tems (Correct answer)
Correct answer: HttpContext.tems
While `HttpContext.Items` is typically used for transient, request-scoped data within a single server instance, in highly distributed or microservices architectures, specific request context or intermediate policy evaluation results might need to be temporarily shared across multiple service instances or asynchronous operations involved in processing a single request. In such advanced scaling scenarios, `HttpContext.Items` data could be serialized and stored in a distributed cache like Azure Redis Cache to maintain context consistency across the distributed components, thereby supporting the service's scaling requirements.
Question 21: Which Azure regions are considered 'paired regions' and what is their primary benefit?
- Regions in the same country, providing legal data residency guarantees
- Geographically separated regions within the same geopolitical boundary, ensuring updates are not deployed simultaneously (Correct answer)
- Regions that share the same Availability Zones for cross-zone redundancy
- Regions in the same continent, reducing data transfer costs
Correct answer: Geographically separated regions within the same geopolitical boundary, ensuring updates are not deployed simultaneously
Azure paired regions are at least 300 miles apart within the same geopolitical area; Microsoft staggers planned updates between paired regions and prioritizes one in a pair during regional outages.
Question 22: For a user called admin1@contoso.com, you set the multi-factor authentication status to Enabled. <br> Admin1 uses a web browser to access the Azure interface. <br> When accessing the Azure portal, what additional security verifications can Admin1 use?
- a password for the app, a verification code in a text message, and a notification from the Microsoft Authenticator app
- a phone call, an email message with a verification code, and a text message with a password for the app
- a phone call, a verification code-containing text message, and a notification or verification code provided through the Microsoft Authenticator app (Correct answer)
- a password for the app, a text message with a verification code, and a code sent from the Microsoft Authenticator app
Correct answer: a phone call, a verification code-containing text message, and a notification or verification code provided through the Microsoft Authenticator app
When multi-factor authentication (MFA) is enabled for a user in Azure AD, they typically have several secure verification methods available during sign-in. These commonly include receiving a phone call to their registered device, getting a text message containing a verification code, or using the Microsoft Authenticator app to either approve a push notification or generate a time-based one-time password (verification code). These options provide robust security layers beyond just a password.
Question 23: What data does NSG Flow Logs capture in Azure Network Watcher?
- DNS query history
- IP traffic information (5-tuple, allow/deny, bytes) flowing through NSG rules (Correct answer)
- SSL certificate details
- Routing table changes
Correct answer: IP traffic information (5-tuple, allow/deny, bytes) flowing through NSG rules
NSG Flow Logs record allowed and denied IP flows through NSGs, including source/destination IP, port, protocol, and byte counts for traffic analysis.
Question 24: What does Azure Resource Graph allow architects to do?
- Create network topology diagrams
- Query the properties and relationships of Azure resources across subscriptions at scale using KQL (Correct answer)
- Manage resource locks
- Monitor resource health
Correct answer: Query the properties and relationships of Azure resources across subscriptions at scale using KQL
Azure Resource Graph provides a fast, scalable query interface to explore Azure resource properties, configurations, and relationships across tenants and subscriptions.
Question 25: Which Azure service provides a fully managed, cloud-native NFS and SMB file share that can be mounted by Windows, Linux, and macOS clients?
- Azure Blob Storage
- Azure Data Lake Storage
- Azure NetApp Files
- Azure Files (Correct answer)
Correct answer: Azure Files
Azure Files provides fully managed cloud file shares accessible via SMB and NFS protocols, mountable directly on VMs and on-premises machines.
Question 26: Which feature of Azure Virtual WAN simplifies hub-and-spoke networking at global scale?
- ExpressRoute Private Peering
- Managed virtual hubs with automated routing (Correct answer)
- NSG rule inheritance
- VNet Gateway Active-Active mode
Correct answer: Managed virtual hubs with automated routing
Azure Virtual WAN uses managed virtual hubs that automate routing configuration, enabling full-mesh connectivity between branches, VNets, and Azure services.
Question 27: What is Azure Blob Storage 'soft delete' designed to protect against?
- Unauthorized access
- Cross-region replication failures
- Data corruption during upload
- Accidental deletion or overwrite of blobs within a configurable retention period (Correct answer)
Correct answer: Accidental deletion or overwrite of blobs within a configurable retention period
Soft delete retains deleted or overwritten blobs for a configurable number of days, allowing recovery from accidental deletions.
Question 28: Which Azure feature allows you to enforce that all subscriptions in a management group comply with organizational policies and RBAC assignments by default?
- Management Group Policies
- Azure Blueprints (Correct answer)
- Azure RBAC Inheritance
- Azure Policy Initiatives
Correct answer: Azure Blueprints
Azure Blueprints package RBAC assignments, policies, and ARM templates into repeatable deployable packages, enforcing governance standards across subscriptions.
Question 29: What does the Azure VM 'Instance Metadata Service' (IMDS) provide?
- OS patch status
- Disk performance telemetry
- Network traffic statistics
- VM identity, SKU, and placement information accessible from within the VM (Correct answer)
Correct answer: VM identity, SKU, and placement information accessible from within the VM
IMDS provides metadata about the running VM instance including compute properties, network info, and Managed Identity tokens via a local non-routable endpoint.
Question 30: An organization requires RPO of 15 minutes for an Azure SQL Database. Which replication feature meets this requirement?
- Manual database backups every 15 minutes
- Active geo-replication with continuous asynchronous replication (Correct answer)
- Auto-failover groups with asynchronous replication
- Point-in-time restore from automated backups
Correct answer: Active geo-replication with continuous asynchronous replication
Active geo-replication uses continuous asynchronous replication and typically achieves RPO well under 5 seconds in practice, easily meeting a 15-minute RPO requirement.
AZ-300: Microsoft Azure Architect Technologies
A retired Microsoft certification exam (replaced by AZ-303) that validates expertise in deploying and configuring Azure infrastructure, implementing workloads and security, creating and deploying apps, and developing for the cloud.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds