Case Studies & Practical Application Flashcards
7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Case Studies & Practical Application flashcards as text
A bank must archive transaction logs older than 90 days to cold storage automatically while keeping recent logs immediately accessible for audits. Which Azure Blob Storage feature implements this with no custom code?
Answer: Azure Blob Storage lifecycle management policies that transition blobs to Archive tier after 90 days
Blob Storage lifecycle management policies automatically transition blobs to cooler tiers (Cool, Cold, Archive) based on last-modified age without custom code.
A company runs a monolithic application on Azure VMs and wants to break it into microservices. They need service discovery, load balancing between services, and secure mTLS communication without changing application code. Which Azure service provides this?
Answer: Azure Kubernetes Service with a service mesh (e.g., Istio or Linkerd)
A service mesh on AKS provides transparent mTLS, service discovery, and load balancing as infrastructure-level capabilities without application code changes.
An architect must ensure that a critical Azure Resource Manager template deployment is rolled back automatically if any resource in the deployment fails. Which deployment mode achieves this?
Answer: ARM template deployment with a rollback-on-failure linked to a last-successful deployment
ARM deployments support automatic rollback on failure by specifying `rollbackOnError` to redeploy the last successful deployment state.
A company needs to expose an on-premises REST API to Azure services securely without opening inbound firewall rules on their corporate network. Which Azure hybrid connectivity option achieves this?
Answer: Azure API Management with Azure Relay (Hybrid Connections)
Azure Relay Hybrid Connections establish an outbound connection from on-premises to Azure, allowing Azure services to call on-premises APIs without inbound firewall rules.
A media company stores large video files in Azure Blob Storage and must prevent accidental deletion by operations staff while still allowing authorized updates. Which approach provides the right balance?
Answer: Apply a resource lock of type 'CanNotDelete' and use RBAC to limit who holds the Storage Blob Data Contributor role
A CanNotDelete resource lock prevents deletion while RBAC controls which principals can write updates, balancing protection with operational flexibility.
An organization needs centralized logging for all Azure resources across 10 subscriptions with the ability to run cross-subscription queries and set alerts. What is the recommended architecture?
Answer: Deploy a centralized Log Analytics workspace and configure diagnostic settings in all subscriptions to send data to it
A centralized Log Analytics workspace allows all subscriptions to forward diagnostics logs, enabling unified querying and alerting across the entire organization.
A company deploys a containerized application to AKS and must ensure that container images are scanned for vulnerabilities before being deployed to production. Which solution integrates into the CI/CD pipeline and blocks vulnerable images at admission?
Answer: Azure Security Center (Defender for Containers) with AKS admission controller integration
Defender for Containers scans images in ACR and integrates with AKS admission control to block deployments of images with critical vulnerabilities.