← All AZ-305 Flashcard Decks

Mixed Deck — All AZ-305 Topics Flashcards

100 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All AZ-305 Topics flashcards as text
  1. You need an alert that fires when CPU utilization on a VM exceeds 80% for five consecutive minutes. Which Azure Monitor alert type should you use?

    Answer: Metric alert

    Metric alerts evaluate numeric resource metrics at regular intervals and trigger when a threshold is crossed, making them ideal for CPU utilization monitoring.

  2. Your web application is hosted in Azure and needs to be protected against OWASP top-10 web vulnerabilities at the network edge. Which service should you enable?

    Answer: Azure Web Application Firewall (WAF)

    Azure WAF, deployable on Application Gateway or Front Door, inspects HTTP/S traffic against OWASP rule sets to block common web attacks.

  3. You need to design a solution to detect and alert when users sign in from locations that are anomalous for their profile. Which feature should you enable?

    Answer: Azure AD Identity Protection sign-in risk policies

    Azure AD Identity Protection uses machine learning to compute sign-in risk scores and can automatically block or require MFA for risky sign-ins.

  4. When deploying a resource on Azure, what choice do you frequently have to make?

    Answer: Choose the region where you want your resource deployed

    When deploying a resource on Azure, you frequently have to choose the region where you want your resource deployed. This decision is crucial as it determines the physical location of your resources, impacting factors like data residency, latency for users, and available services. Selecting the appropriate region helps optimize performance, meet regulatory requirements, and manage costs effectively.

  5. Which Azure AD license tier is required to use both Privileged Identity Management and Identity Protection features?

    Answer: Azure AD Premium P2

    Both PIM and Identity Protection are Azure AD Premium P2 features that require that specific license tier.

  6. Your data engineering team needs a storage account that supports hierarchical namespace for big data analytics workloads using Apache Spark. Which storage type should you enable?

    Answer: Azure Data Lake Storage Gen2 (ADLS Gen2) with hierarchical namespace enabled

    Enabling the hierarchical namespace on an Azure Storage account creates ADLS Gen2, which provides directory semantics and atomic operations optimized for analytics engines.

  7. You need to connect an on-premises datacenter to Azure with a guaranteed bandwidth SLA, low latency, and private connectivity not traversing the internet. Which option should you recommend?

    Answer: Azure ExpressRoute

    ExpressRoute provides dedicated private connectivity between on-premises and Azure through a connectivity provider with an SLA-backed bandwidth guarantee.

  8. An application requires an ExpressRoute connection with 99.99% availability SLA. What design achieves this?

    Answer: ExpressRoute circuit with a backup Site-to-Site VPN

    Dual ExpressRoute circuits from geographically diverse peering locations with a zone-redundant gateway delivers the 99.99% SLA Microsoft guarantees for that design.

  9. An application needs to run a batch processing job once per night that processes data for exactly 30 minutes and then stops. Which Azure compute option minimizes cost?

    Answer: Azure Functions Consumption plan with a timer trigger

    Azure Functions Consumption plan bills only for the time the function runs, making it extremely cost-efficient for short-duration, scheduled batch jobs.

  10. An application writes large files to Azure Blob Storage and needs to ensure files are only visible to readers after the entire upload is complete. Which upload method ensures this?

    Answer: Block Blob upload with Commit Block List as the final step

    Block Blob staging uploads data in blocks using Put Block, and only the final Commit Block List operation makes the complete blob visible to readers.

  11. You are designing a solution where Azure VMs need outbound internet access but must not have public IP addresses. Which managed service provides this?

    Answer: Azure NAT Gateway

    Azure NAT Gateway provides outbound internet connectivity for VMs in a subnet without requiring public IPs on each VM.

  12. An organization needs to test their Azure disaster recovery plan quarterly without interrupting production services and with automatic cleanup of test resources afterward. Which ASR feature supports this?

    Answer: ASR Recovery Plans with test failover automation scripts

    ASR Recovery Plans allow scripted test failovers with pre/post automation hooks that can spin up and tear down test environments in isolated networks automatically.

  13. You are designing storage for an IoT application that ingests millions of small messages per second and needs a hot path for immediate analytics. Which combination is recommended?

    Answer: Azure Event Hubs + Azure Stream Analytics + Azure Data Lake Storage Gen2

    Event Hubs captures the high-throughput stream, Stream Analytics processes data in real time, and ADLS Gen2 stores the cold path for batch analytics.

  14. You have an on-premises Active Directory domain that is synchronized with an Azure Active Directory (Azure AD) tenant. WebApp1 is an internal web application that is hosted on your premises. WebApp1 makes use of Windows Integrated authentication. Some users access the on-premises network via remote access but do not have VPN access. You must grant single sign-on (SSO) access to WebApp1 to the remote users. What two features ought to be incorporated into the solution?

    Answer: Azure AD enterprise applications

    Azure AD Application Proxy is essential for securely publishing on-premises web applications, like WebApp1, to external users without requiring VPN access. By integrating with Azure AD enterprise applications, it enables single sign-on (SSO) for these remote users, leveraging their Azure AD credentials to access the internal application that uses Windows Integrated Authentication. This combination allows seamless and secure access from outside the corporate network.

  15. You need to provide stakeholders with personalized recommendations to reduce Azure spending, improve reliability, and address security vulnerabilities without building custom queries. Which service should you use?

    Answer: Azure Advisor

    Azure Advisor analyzes your resource configurations and usage telemetry to provide prioritized, actionable recommendations across cost, reliability, security, performance, and operational excellence.

  16. What do Azure regions' availability zones do?

    Answer: Different Azure datacenters within a region

    Azure regions' Availability Zones are physically separate, independent datacenters located within a single Azure region. Each zone has its own independent power, cooling, and networking, providing isolation from failures in other zones within the same region. This architecture ensures high availability and fault tolerance for applications and data by distributing resources across these distinct physical locations.

  17. Mark is working at PTG Ltd. has two Azure virtual machines deployed in different regions. Given, each of the virtual machine has a public IP address that has been assigned to its network interface. Also, an application is installed on the virtual machines. Requirement - Peter has been asked to implement Azure Front Door-based load balancing across the virtual machines. He needs to ensure the application on the virtual machines only accept traffic that is routed from Azure Front Door. Which of the following options should Mark choose to meet the requirement?

    Answer: Network Security Groups with service tags

    To ensure that virtual machines only accept traffic routed from Azure Front Door, Network Security Groups (NSGs) with service tags are the appropriate solution. Service tags represent a group of IP address prefixes from a given Azure service, such as `AzureFrontDoor.Backend`. By creating an inbound NSG rule that allows traffic from the `AzureFrontDoor.Backend` service tag, you can restrict access to your virtual machines, ensuring only legitimate traffic originating from Azure Front Door can reach them, without needing to manage dynamic IP addresses.

  18. You need to design a caching layer to reduce read latency for an Azure SQL Database backing a high-traffic web application. Which service should you add?

    Answer: Azure Cache for Redis

    Azure Cache for Redis provides an in-memory key-value store that dramatically reduces database read latency by caching frequently queried data.

  19. Your organization requires that administrative actions on Azure resources be performed only after a second approval is obtained. Which Azure feature fulfills this requirement?

    Answer: Privileged Identity Management (PIM) with approval workflows

    PIM approval workflows require a designated approver to authorize role activation before an admin can perform privileged actions.

  20. You need to design a solution where service-to-service authentication happens without storing credentials in code or configuration files. Which approach is recommended?

    Answer: Use Azure Managed Identities

    Managed Identities eliminate the need to manage credentials by providing Azure resources with an automatically managed identity in Azure AD.