AZ-305 Practice Questions
Prepare for AZ-305 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 205 questions Current
- AZ-303Legacy Microsoft Azure Architect Technologies 158 questions Locked
- Exam fee
- $165 USD
- Level
- Expert
- Valid for
- 1 year
Domains covered on the exam 4
- Design identity, governance, and monitoring solutions
- Design data storage solutions
- Design business continuity solutions
- Design infrastructure solutions
- 1
You are designing a data solution for a company that needs to ingest millions of events per second from IoT devices. The solution must be able to capture this streaming data and make it available for multiple downstream consumers, including a real-time analytics engine and a long-term archival system. The ingestion service must be highly scalable and support event partitioning.
Which Azure service is the most appropriate for this data ingestion requirement?
Show answer details
Correct answer: A
Azure Event Hubs is a fully managed, real-time data ingestion service that's simple, trusted, and scalable. It is specifically designed to stream millions of events per second from sources like IoT devices. It supports partitioning to enable parallel processing by downstream consumers and integrates seamlessly with services like Azure Stream Analytics for real-time processing and Azure Data Lake for archival.
- 2
A company has a set of on-premises virtual machines that they plan to migrate to Azure. Before the migration, they need to perform a comprehensive assessment to understand dependencies between VMs, determine the appropriate VM sizing in Azure, and estimate the monthly costs. The assessment process should be as automated as possible.
Which Azure tool should you recommend for this purpose?
Show answer details
Correct answer: A
Azure Migrate is the central hub for Azure migration projects. Its assessment tools are specifically designed to discover on-premises VMs, analyze dependencies between them without requiring agents, recommend right-sized Azure VM SKUs based on performance history, and provide detailed cost estimations. This directly addresses all the requirements for the pre-migration assessment phase.
- 3
A company is concerned about the security of its Azure Active Directory (Azure AD) tenant. They want to proactively detect and respond to potential identity-based risks, such as leaked credentials, sign-ins from anonymous IP addresses, and impossible travel to atypical locations. The solution should automatically force users to perform multi-factor authentication or reset their password when a high-risk event is detected.
Which Azure AD feature should be implemented?
Show answer details
Correct answer: A
Azure AD Identity Protection is the feature designed to detect, remediate, and investigate identity-based risks. It uses Microsoft's vast threat intelligence to identify suspicious activities like leaked credentials and anomalous sign-ins. It allows for the configuration of risk-based policies (e.g., user risk policy, sign-in risk policy) that can automatically trigger remediation actions, such as requiring an MFA prompt or forcing a password reset, when a certain risk level is detected.
- 4
You are designing the storage for a new application that requires extremely low latency and high throughput for read and write operations on its data files. The data will be accessed from a cluster of Linux virtual machines running a high-performance computing (HPC) workload. The storage solution must provide a fully managed file share that supports the NFSv3 protocol.
Which Azure storage service is the best fit for this requirement?
Show answer details
Correct answer: A
Azure NetApp Files is a high-performance, enterprise-grade file storage service. It is specifically designed for the most demanding workloads like HPC, SAP, and electronic design automation (EDA). It offers extremely low latency, high throughput, and supports both NFS (including NFSv3) and SMB protocols, making it the perfect choice for this high-performance Linux-based workload.
- 5
A media company is designing a solution to ingest and process a high-throughput stream of real-time analytics data from its global video platform. The solution must meet the following criteria:
- Ingest millions of events per second with low latency.
- Provide a durable, ordered buffer for events for at least 7 days.
- Allow multiple independent consumer applications to process the same stream of events concurrently, each at its own pace.
- Partition the data stream by user ID to enable parallel processing.
Which combination of Azure services provides the most appropriate architecture for the ingestion and buffering part of this solution?
sequenceDiagram participant P as Video Platform participant I as Ingestion Service participant C1 as Consumer 1 (Real-time Dashboard) participant C2 as Consumer 2 (Archival) P->>I: Event Stream (Millions/sec) I-->>C1: Process Stream (Consumer Group A) I-->>C2: Process Stream (Consumer Group B)Show answer details
Correct answer: C
Azure Event Hubs is specifically designed for large-scale, low-latency event ingestion (big data streaming). It supports millions of events per second and partitioning by a key (like user ID) for ordered, parallel processing. The concept of 'consumer groups' allows multiple applications to read the entire event stream independently from the same Event Hub, each maintaining its own pointer in the stream. This directly meets all the stated requirements for ingestion, buffering, and concurrent consumption.
- 6
A financial services company is designing a new three-tier application on Azure. The company has a strict security policy that requires all network traffic between the web, application, and data tiers to be inspected by a Network Virtual Appliance (NVA). The company also wants to centralize the management of this NVA and other shared services like DNS and Active Directory domain controllers. You need to design a network topology that meets these requirements.
Which network design should you recommend?
Show answer details
Correct answer: A
A hub-and-spoke topology is the recommended design for centralizing shared services and enforcing security policies. Placing the NVA and other shared services in the hub VNet allows for centralized management and inspection of all traffic. Each application tier can be isolated in its own spoke VNet, and user-defined routes (UDRs) can force all inter-spoke traffic through the NVA in the hub, meeting the inspection requirement. This design is scalable, cost-effective, and aligns with Azure best practices.
- 7
A retail company is migrating its e-commerce platform to Azure. The platform experiences massive, unpredictable traffic spikes during flash sales. The product catalog is stored in an Azure SQL Database. During sales, the database becomes a bottleneck due to an extremely high volume of read operations. The company needs a solution that can handle the read traffic without requiring a permanent, expensive scale-up of the primary database. The solution must minimize changes to the application's data access layer.
What is the most suitable solution to recommend?
Show answer details
Correct answer: A
Read scale-out replicas are designed for read-heavy workloads. This feature allows you to provision one or more read-only replicas of the primary database. The application can then be configured to direct read-only queries (like browsing the product catalog) to these replicas, offloading the primary database to handle write transactions. This directly addresses the read bottleneck during traffic spikes without over-provisioning the primary database year-round. It is a built-in feature of Azure SQL Database Premium and Business Critical service tiers.
- 8
An organization has deployed a critical application on a set of Azure Virtual Machines. The security team wants to ensure that administrative access (RDP and SSH) to these VMs is only possible from a secure, managed jump box and not directly from the internet. They also want to audit all administrative sessions. The solution should avoid exposing any public IP addresses on the VMs themselves.
Which Azure service should be recommended to meet these requirements?
Show answer details
Correct answer: A
Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP and SSH connectivity to your virtual machines directly through the Azure portal. It is deployed within a virtual network and allows access without exposing public IP addresses on the target VMs. All sessions are conducted over SSL, and it provides a centralized point of access that can be easily integrated with network security groups and Azure AD for enhanced security and auditing.
- 9
A company has a hybrid cloud environment with resources both on-premises and in Azure. The governance team needs to enforce a consistent set of policies, such as requiring specific tags on resources and restricting deployments to certain regions, across both Azure and their on-premises servers. They want a single control plane to manage and audit compliance for all resources, regardless of their location.
What Azure service should be the cornerstone of this governance design?
Show answer details
Correct answer: A
Azure Arc extends the Azure control plane (Azure Resource Manager) to manage resources outside of Azure, including on-premises servers (Windows and Linux) and Kubernetes clusters. By onboarding on-premises servers to Azure Arc, they become Azure resources with a Resource ID. This allows you to apply Azure Policy, tagging, and other Azure management services to them, providing a unified governance and compliance solution across a hybrid environment from a single pane of glass.
- 10
You are designing a disaster recovery strategy for a stateful application running in Azure Kubernetes Service (AKS). The application uses Azure Disks for persistent storage via Persistent Volumes (PVs). The business requires a Recovery Point Objective (RPO) of 4 hours and a Recovery Time Objective (RTO) of 8 hours. The disaster recovery site will be in a paired Azure region.
You need to recommend a solution for backing up and restoring the application's state, including its Kubernetes objects and persistent data.
Which solution should you recommend?
Show answer details
Correct answer: A
Azure Backup for AKS is a native, enterprise-grade solution designed specifically for this scenario. It can back up and restore both the Kubernetes objects (deployments, services, etc.) and the persistent data stored in Persistent Volumes (backed by Azure Disks). It supports scheduled backups to meet the RPO and cross-region restore to meet the RTO, integrating directly with the Backup Vault and providing a centralized management experience.
