AZ-305 Practice Questions
These original AZ-305 scenarios practice architecture decisions across identity, governance, storage, continuity, compute, applications, and networking.
- They are teaching examples, not Microsoft secure exam questions, a full mock, or a score predictor.
- For each item, identify the business constraint first, choose the design that fits it, and explain the closest alternative’s trade-off.
On this page6 sections
How to use this practice set
Answer each scenario before opening its explanation. Write the business outcome, the constraint that matters most, the recommended pattern, and one trade-off. AZ-305 is a design exam, so the point is not to match a remembered product name. A service that is appropriate in one architecture can be a poor fit when the recovery, data, operational, or cost requirement changes.
These examples are original and are not copied from Microsoft’s secure assessment. Microsoft does not publish a fixed AZ-305 item count or identify which role-based exams include labs in advance. This set is not a full-length mock and does not simulate a live Azure configuration task. Use the public April 17, 2026 study guide to confirm scope and use the explanations to improve decision reasoning.
A customer-facing service must continue operating if one availability zone fails. The business also needs a tested way to recover deleted records from an earlier point in time. Which design approach addresses both requirements?
- Select a zone-resilient architecture for service continuity and configure a separate backup or point-in-time recovery plan with a tested restore process.
- Use a local replica and assume it protects against deletion.
- Configure a backup only; it guarantees uninterrupted service during a zone outage.
- Use a resource lock to satisfy both availability and data recovery.
The key is to map failure scenarios separately. A candidate who sees the word ‘resilience’ and selects one high-availability feature may miss the explicit deletion requirement. Define recovery time and recovery point needs before selecting implementation details, and validate the restore procedure rather than treating a configured policy as proof.
A large organization wants to prevent teams from deploying resources in prohibited regions while allowing each product team to manage its own resources. Which design best separates configuration governance from day-to-day permissions?
- Apply an Azure Policy initiative at an appropriate management scope to enforce permitted locations, and assign teams least-privilege RBAC within their subscriptions or resource groups.
- Give every product team Owner at the tenant root and rely on tags to block deployments.
- Use Azure Monitor alerts to reject resource creation in a prohibited location.
- Create a resource lock on every existing resource and assume future deployments are governed.
Architectural governance should be placed where it is consistent and operable. The scope needs to cover the relevant subscriptions, while exceptions should be controlled rather than allowing a policy to become meaningless. Separate the rule that configurations must satisfy from the permissions that let people manage compliant resources.
A new order-processing system requires relational transactions, an existing SQL data model, predictable regional latency, and a managed service to reduce database administration. Which step should the architect take first?
- Compare supported Azure relational database services and tiers against transaction, compatibility, latency, scaling, protection, and operational requirements.
- Select object storage because it automatically provides relational transactions.
- Move the database to a globally distributed NoSQL service without checking data access patterns.
- Choose the highest-priced database tier before estimating workload demand.
This item deliberately asks for the first design step rather than a specific service. A responsible recommendation needs details such as transaction volume, growth, latency target, high availability, regional deployment, and recovery objective. The candidate should avoid inventing missing workload facts.
A company is moving a latency-sensitive application in phases. Some services will remain on-premises for a year, and the teams require private connectivity with predictable performance. Which design consideration is most central?
- Evaluate private hybrid connectivity options against throughput, latency, redundancy, routing, regional placement, and the migration sequence.
- Expose every application component through public endpoints because that is easiest to configure.
- Use a storage lifecycle policy to provide network connectivity.
- Choose a private endpoint and assume it connects the on-premises network to every Azure service automatically.
The phrase ‘for a year’ suggests the architecture must support a transition rather than a permanent end state alone. Plan routes, DNS, security controls, and eventual cutover, then validate performance under realistic traffic. The exact circuit or gateway choice depends on facts not supplied in the question.
An online booking service experiences spikes when a marketing campaign launches. The booking API should accept requests even when a downstream document-generation worker is temporarily busy. Which architecture pattern best addresses this requirement?
- Place a durable message queue between the API and worker so requests can be buffered and processed asynchronously.
- Make the API call the worker synchronously and increase the client timeout indefinitely.
- Send every request to a monitoring alert and discard the payload.
- Store requests in a cache with no persistence or retry mechanism.
A complete design would check ordering, duplicate delivery, message retention, processing guarantees, and how the API informs users that work is pending. If the business needs immediate completion, asynchronous processing may change user experience. The scenario says the API should accept requests while the worker is busy, making decoupling central.
A regulated organization needs centralized security logs from Azure resources, application telemetry for service health, and a way for responders to investigate incidents. Which design principle is strongest?
- Design log collection and routing, application monitoring, retention, access controls, and incident workflows as connected but distinct requirements.
- Collect all data in one ungoverned workspace and grant every engineer Owner.
- Use a backup vault as the sole monitoring and investigation platform.
- Enable a dashboard but omit data retention and responder access design.
What the explanations have in common
Each scenario includes a requirement that changes the architecture: restore deleted data; enforce governance while delegating operations; retain relational transactions; maintain private hybrid performance; absorb a downstream workload burst; or support security investigation. First identify what must be true. Then choose the pattern that directly supports it and check dependencies, failure modes, and cost.
A tempting answer can be technically useful but still miss the requirement. A replica may improve availability but not protect a deleted record. A private endpoint can improve service access but does not build hybrid connectivity. A monitor alert can detect a breach but not enforce a location rule. Good exam reasoning names the boundary of a feature.
Practice architecture rather than product recall
For each item, diagram users, application components, data flows, identity, network boundaries, logs, and recovery. Write the nonfunctional requirements next to the components: recovery time, latency, scale, compliance, cost, and operational responsibility. Then identify what the prompt does not tell you. If a missing fact is essential, compare the options based on the supported requirements instead of inventing a detailed design.
Change one requirement after solving. Reduce allowable recovery loss, remove internet access, increase the message rate, require a second region, or limit the operations team’s skill. Ask whether your recommendation changes. If it does, explain which design element moves and why. If it does not, make sure you are not ignoring the new constraint.
Use official practice in context
Microsoft’s Practice Assessment can familiarize candidates with sample wording and help identify gaps. Microsoft states that it is not the secure exam, does not represent the full length or complexity, and may not include every question format, case, or lab. Third-party percentages likewise do not convert to Microsoft’s 700 scaled passing score.
Microsoft’s current policy says role-based exams typically contain 40 to 60 questions, but exact counts vary. Labs may be included, but Microsoft does not publish which specific exams have them in advance. Use this practice set to learn architecture reasoning; use the exam sandbox to understand the general interface; use safe labs to explore services. These tools provide different kinds of preparation evidence.
A review method for misses
Write four notes for every missed question: the business outcome; the decisive constraint; why your choice failed; and what changed constraint would make your choice suitable. For example, a queue is valuable when a worker can process later, but not when every request requires an immediate synchronous result. This turns a miss into a reusable design distinction.
Do not copy or distribute secure items remembered from an exam. General notes such as ‘I confused backup with availability’ are useful without disclosing protected content. Review official documentation for current service details and the study guide for scope.
Readiness check
You are ready to move beyond basic questions when you can discuss requirements before naming services, explain a design’s dependencies, compare a credible alternative, and identify operational trade-offs. A good architect answer is often conditional on workload facts, but it still gives a clear recommendation under the facts supplied. Practice stating the answer directly, then explain what would change it.
When two options appear equivalent, look for a hidden operational constraint. Does one need custom failover scripts? Does one depend on a feature unsupported in the target region? Does one create duplicate data or require a consistency model the application cannot tolerate? The exam’s best answer usually reflects the specific facts rather than a generic preference for managed services or maximum redundancy.
Common questions
Are these official AZ-305 questions?
No. They are original educational scenarios and do not reproduce Microsoft’s secure exam.
Do these questions predict a Microsoft score?
No. This short set is not a full exam and does not use Microsoft scaled scoring.
What should I do after getting an architecture question wrong?
Identify the business requirement, the deciding constraint, and the trade-off you missed; then practice a changed scenario.
Does AZ-305 include labs?
Labs may appear on role-based exams, but Microsoft does not publish exam-specific lab inclusion in advance.