โ† All AZ-301 Flashcard Decks

Case Studies & Practical Application Flashcards

7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Case Studies & Practical Application flashcards as text
  1. A SaaS company serves multiple enterprise customers and must ensure each customer's data is completely isolated at the database level while minimizing management overhead. Which Azure SQL approach is best?

    Answer: Azure SQL Elastic Pool with one database per tenant and row-level security

    Elastic Pools share compute resources cost-effectively while providing database-level isolation per tenant, reducing management overhead versus per-tenant servers.

  2. An architect is designing a solution where Azure Functions must access a SQL database without storing connection strings in application settings or code. What is the recommended approach?

    Answer: Store the connection string in Azure Key Vault and reference it via Key Vault references in App Settings

    Key Vault references in App Settings allow Azure Functions to retrieve secrets from Key Vault at runtime without exposing them in configuration files.

  3. A gaming company needs a globally distributed, low-latency data store for player session state. Reads must return data within 10ms from any region, and writes must be accepted in multiple regions simultaneously. Which Azure service is appropriate?

    Answer: Azure Cosmos DB with multi-region writes enabled

    Cosmos DB with multi-region writes (multi-master) allows writes and reads in any configured region with single-digit millisecond latency guarantees.

  4. A company's architecture review identifies that their Azure Kubernetes Service cluster nodes are running at 90% CPU during peak hours, causing pod evictions. What is the correct remediation at the infrastructure level?

    Answer: Enable cluster auto-scaler to add nodes when resource pressure is detected

    The cluster auto-scaler monitors for unschedulable pods or resource pressure and automatically provisions additional nodes to accommodate load.

  5. An insurance company must ensure all data in transit between Azure services within their VNet is encrypted and that API endpoints are never exposed to the public internet. Which design pattern achieves this?

    Answer: Use Azure Private Endpoints for all PaaS services and deploy within a VNet, disabling public access

    Private Endpoints bring PaaS services into the VNet with a private IP, eliminating public internet exposure, while disabling public access ensures no alternative path exists.

  6. A logistics company needs to process order events in the exact sequence they are placed and ensure that order events for the same customer are always processed by the same consumer instance. Which Event Hubs feature supports this?

    Answer: Event Hubs partition key set to customer ID with a dedicated consumer group per service

    Setting the partition key to customer ID ensures all events for a customer land in the same partition, which is consumed sequentially by the same consumer instance.

  7. A company's security team requires that all privileged role assignments in Azure AD last no longer than 8 hours and require MFA at the time of activation. Which feature enforces this?

    Answer: Azure AD Privileged Identity Management (PIM) with time-bound activation and MFA requirement

    PIM enables just-in-time privileged access with configurable activation duration limits and MFA enforcement at activation time.