- 1
A company needs to design a solution that stores documents uploaded by users. The documents must remain available even if an entire Azure region goes offline. Which storage redundancy option should the architect recommend?
Show answer
Answer: C
RA-GRS replicates data asynchronously to a secondary region hundreds of kilometres away and provides read access to the secondary copy. If the primary region fails, the data is still accessible from the secondary. LRS and ZRS only protect within a single region. Managed disks are block storage for VMs, not document storage.
- 2 Select all that apply
A solution architect is designing an application that processes orders. The ordering API must handle unpredictable traffic spikes without losing any orders. Which TWO components should be included in the design? (Select two.)
Show answer
Answer: B, D
A Service Bus queue acts as a buffer — the API writes orders to the queue and they're never lost, even during traffic spikes. Azure Functions with a queue trigger processes the messages asynchronously at a sustainable rate. Traffic Manager and Front Door are load balancing and routing services that don't provide message buffering. Bastion is for secure VM access.
- 3
An organisation requires that all Azure resources are deployed only to the West Europe and North Europe regions. No exceptions should be allowed, regardless of the user's role. What should the architect recommend?
Show answer
Answer: A
Azure Policy can enforce allowed locations at the subscription or management group level. Any deployment to a non-allowed region is denied automatically, regardless of the user's RBAC role. RBAC controls what actions a user can take, but it cannot restrict which regions resources are deployed to. Advisor provides recommendations but does not enforce them.
- 4
A company is migrating a legacy application that requires a Windows Server with specific third-party drivers installed. The application cannot be containerised. Which Azure compute option should the architect recommend?
Show answer
Answer: D
Azure VMs provide full control over the operating system, allowing installation of custom drivers and legacy software. App Service, AKS, and Functions are all PaaS/serverless options that abstract away the OS — you cannot install custom drivers on them. VMs are the right choice when you need OS-level control.
- 5 Select all that apply
A solution architect is designing a highly available web application. Which THREE design principles should be applied? (Select three.)
Show answer
Answer: A, C, E
High availability requires: spreading resources across Availability Zones (survives data centre failure), health probes to detect and route around failed instances, and managed database services with automatic failover (e.g. Azure SQL with auto-failover groups). A single large VM is a single point of failure. Local session state breaks when traffic moves between instances. Disabling auto-scaling means the app cannot respond to demand changes.
- 6
An architect is designing identity for a customer-facing mobile application. Customers must be able to sign up with their email address or social accounts (Google, Facebook). Which Azure service should be used?
Show answer
Answer: B
Azure AD B2C (now Entra External ID) is designed for consumer-facing identity — it supports self-service sign-up, social identity providers, and custom branding. Azure AD is for organisational identities. B2B is for inviting external business users into your Azure AD. AD DS is for domain-joined on-premises or VM workloads.
- 7 Put these in order
Place the following steps in the correct order when designing a disaster recovery strategy for an Azure SQL Database.
Show answer
Correct order
- C Define the Recovery Point Objective (RPO) and Recovery Time Objective (RTO)
- A Configure active geo-replication to a secondary region
- D Set up a failover group with automatic failover policy
- B Test failover and validate application connectivity to the secondary
Start by defining your RPO and RTO — these business requirements drive all technical decisions. Then configure geo-replication to a paired region. Set up a failover group to automate the failover process and manage DNS endpoints. Finally, test the failover to ensure the application reconnects correctly and meets the defined RTO.
- 8
A company stores sensitive customer data in Azure Blob Storage. Regulatory requirements mandate that the data is encrypted with keys managed by the company, not Microsoft. What should the architect recommend?
Show answer
Answer: C
Customer-managed keys (CMK) stored in Azure Key Vault give the company full control over the encryption keys while still using Azure's server-side encryption. Microsoft-managed keys are the default but don't meet the requirement for company-managed keys. Client-side encryption works but adds complexity and isn't necessary when CMK is available. Disk Encryption applies to VM disks, not Blob Storage.
- 9
Azure Traffic Manager performs health checks at the application layer (HTTP/HTTPS) by default and can route traffic based on URL path.
Show answer
Answer: B
Azure Traffic Manager operates at the DNS level, not the application layer. It directs clients to different endpoints based on DNS resolution using routing methods like priority, weighted, or geographic. It performs health checks via HTTP/HTTPS/TCP, but it does not inspect or route based on URL paths. For URL path-based routing, use Azure Application Gateway or Azure Front Door.
- 10
An architect needs to design a solution where multiple microservices communicate asynchronously. Messages must be processed in the exact order they are sent, and each message must be processed exactly once. Which service should they use?
Show answer
Answer: A
Azure Service Bus with sessions guarantees FIFO (first-in, first-out) ordering and exactly-once processing within a session. Event Grid is for event-driven reactive programming (at-least-once delivery). Event Hubs is for high-throughput telemetry streaming. Azure Queue Storage provides basic queuing but does not guarantee ordering or exactly-once processing.
- 11 Select all that apply
A company is designing a solution that must meet a 99.99% availability SLA. Which TWO architectural decisions help achieve this? (Select two.)
Show answer
Answer: B, D
99.99% availability (about 52 minutes downtime per year) typically requires multi-region deployment with automatic failover — a single-region deployment cannot achieve this SLA regardless of the number of Availability Zones. Azure Front Door provides global load balancing across regions. Active-active deployment means both regions serve traffic, with automatic failover if one fails. A single SQL Database and nightly restarts introduce single points of failure.
- 12
An architect is designing a data pipeline that ingests millions of IoT telemetry events per second. The data must be available for real-time dashboards and later for batch analytics. Which ingestion service should they recommend?
Show answer
Answer: D
Azure Event Hubs is designed for massive-scale event ingestion — millions of events per second with low latency. It supports both real-time consumers (e.g. Stream Analytics for dashboards) and batch consumers (e.g. capture to storage for later analysis). Service Bus is for transactional messaging, not high-throughput telemetry. Queue Storage is basic and low-throughput. Logic Apps is for workflow orchestration.
- 13
A company wants to run containerised workloads without managing any underlying infrastructure. The workloads are short-lived batch jobs that run for 10-30 minutes and then terminate. Which service should the architect recommend?
Show answer
Answer: B
Azure Container Instances provides serverless containers — no infrastructure to manage, per-second billing, and fast startup. It's ideal for short-lived batch workloads. AKS requires managing a cluster (overkill for simple batch jobs). App Service is for long-running web applications. VM Scale Sets require managing VMs.
- 14
When designing for cost optimisation, reserved instances provide significant discounts over pay-as-you-go pricing in exchange for a one-year or three-year commitment.
Show answer
Answer: A
Azure Reserved Instances offer up to 72% savings compared to pay-as-you-go pricing for VMs, SQL Database, Cosmos DB, and other services. You commit to a one-year or three-year term. This is ideal for workloads with predictable, steady-state usage. For variable or short-lived workloads, pay-as-you-go or spot instances are more cost-effective.
- 15
An architect is designing a solution that needs to cache frequently accessed data to reduce database load. The cache must support data structures like sorted sets and hashes, and must be accessible from multiple application instances. What should they recommend?
Show answer
Answer: C
Azure Cache for Redis provides a fully managed, in-memory data store that supports rich data structures (strings, hashes, lists, sets, sorted sets). It's accessible from any application instance over the network, making it perfect for shared caching. Blob Storage with CDN caches static files, not application data. Table Storage is persistent NoSQL, not an in-memory cache. Cosmos DB is a database, not a caching layer.
- 16 Select all that apply
An architect must ensure that API keys and connection strings used by an application are stored securely and never appear in source code or configuration files. Which TWO services should be used together? (Select two.)
Show answer
Answer: A, C
Azure Key Vault stores secrets securely (encrypted at rest, access-controlled). Managed Identity lets the application authenticate to Key Vault without needing credentials — the identity is managed by Azure and never exposed in code. Together, they eliminate secrets from source code and config files entirely. Policy enforces rules, Advisor gives recommendations, and NSGs control network traffic — none of them store or retrieve secrets.
- 17 Put these in order
Place the following steps in the correct order when designing a migration from on-premises SQL Server to Azure SQL Database.
Show answer
Correct order
- B Assess the on-premises database for compatibility issues using Data Migration Assistant
- D Remediate any compatibility issues identified in the assessment
- A Perform the data migration using Azure Database Migration Service
- C Validate application functionality against the migrated database and cut over
Start with assessment — Data Migration Assistant identifies T-SQL compatibility issues, deprecated features, and breaking changes. Fix those issues before migrating. Then use Azure Database Migration Service for the actual data migration (supports online migration with minimal downtime). Finally, validate that the application works correctly against the new Azure SQL Database before cutting over production traffic.
- 18
A company needs to expose internal APIs to external partners with rate limiting, authentication, and usage analytics. Which Azure service should the architect recommend?
Show answer
Answer: A
Azure API Management is a full API gateway — it provides rate limiting (throttling policies), authentication (OAuth2, API keys, certificates), usage analytics, developer portal, and API versioning. Application Gateway is a web traffic load balancer with WAF. Front Door is a global CDN and load balancer. Load Balancer operates at layer 4 (TCP/UDP) with no API-level features.
- 19
An architect is designing a globally distributed application where users on every continent need sub-10ms read latency. The data model is flexible and includes JSON documents. Which database service should they recommend?
Show answer
Answer: D
Azure Cosmos DB offers guaranteed single-digit millisecond reads at the 99th percentile globally, with turnkey multi-region distribution and multi-region writes. It natively supports JSON documents. SQL Database and PostgreSQL can geo-replicate but don't guarantee sub-10ms reads globally. Redis provides low latency but is a cache, not a primary database for documents.
- 20 Select all that apply
An architect is designing network security for a web application in Azure. Which TWO services work together to protect the application from common web exploits and DDoS attacks? (Select two.)
Show answer
Answer: A, D
WAF (deployed on Application Gateway or Front Door) protects against common web exploits like SQL injection, XSS, and other OWASP top 10 threats. DDoS Protection Standard provides enhanced DDoS mitigation with traffic monitoring, automatic attack detection, and mitigation policies. Together they form a comprehensive protection layer. Bastion is for secure VM management access. Private Link provides private connectivity to services. Key Vault stores secrets.