Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

AZ-305 Practice Questions

Updated 10 min read
Key takeaway

These original AZ-305 scenarios practice architecture decisions across identity, governance, storage, continuity, compute, applications, and networking.

  • They are teaching examples, not Microsoft secure exam questions, a full mock, or a score predictor.
  • For each item, identify the business constraint first, choose the design that fits it, and explain the closest alternative’s trade-off.
On this page6 sections
  1. How to use this practice set
  2. What the explanations have in common
  3. Practice architecture rather than product recall
  4. Use official practice in context
  5. A review method for misses
  6. Readiness check

How to use this practice set

Answer each scenario before opening its explanation. Write the business outcome, the constraint that matters most, the recommended pattern, and one trade-off. AZ-305 is a design exam, so the point is not to match a remembered product name. A service that is appropriate in one architecture can be a poor fit when the recovery, data, operational, or cost requirement changes.

These examples are original and are not copied from Microsoft’s secure assessment. Microsoft does not publish a fixed AZ-305 item count or identify which role-based exams include labs in advance. This set is not a full-length mock and does not simulate a live Azure configuration task. Use the public April 17, 2026 study guide to confirm scope and use the explanations to improve decision reasoning.

Question 1: recovery versus availability

A customer-facing service must continue operating if one availability zone fails. The business also needs a tested way to recover deleted records from an earlier point in time. Which design approach addresses both requirements?

  1. Select a zone-resilient architecture for service continuity and configure a separate backup or point-in-time recovery plan with a tested restore process.
  2. Use a local replica and assume it protects against deletion.
  3. Configure a backup only; it guarantees uninterrupted service during a zone outage.
  4. Use a resource lock to satisfy both availability and data recovery.
Answer: A. The scenario has two distinct failure objectives. Zone resilience addresses availability during a zone failure; backup or point-in-time recovery addresses restoration after deletion, subject to service support and retention. A local replica may not span the failure boundary and can replicate destructive changes. Backup alone does not guarantee uninterrupted service. A resource lock protects some resource operations but is not a data recovery system.

The key is to map failure scenarios separately. A candidate who sees the word ‘resilience’ and selects one high-availability feature may miss the explicit deletion requirement. Define recovery time and recovery point needs before selecting implementation details, and validate the restore procedure rather than treating a configured policy as proof.

Question 2: governance and deployment constraints

A large organization wants to prevent teams from deploying resources in prohibited regions while allowing each product team to manage its own resources. Which design best separates configuration governance from day-to-day permissions?

  1. Apply an Azure Policy initiative at an appropriate management scope to enforce permitted locations, and assign teams least-privilege RBAC within their subscriptions or resource groups.
  2. Give every product team Owner at the tenant root and rely on tags to block deployments.
  3. Use Azure Monitor alerts to reject resource creation in a prohibited location.
  4. Create a resource lock on every existing resource and assume future deployments are governed.
Answer: A. Policy evaluates or denies noncompliant resource configurations at scope, while RBAC defines who can perform management actions. A management-group or subscription policy can establish a common boundary, with RBAC allowing delegated operations below it. Root-level Owner is excessive. Tags alone do not enforce a location policy. Alerts notify about conditions and do not themselves prevent a prohibited deployment, and locks on existing resources do not govern every new resource.

Architectural governance should be placed where it is consistent and operable. The scope needs to cover the relevant subscriptions, while exceptions should be controlled rather than allowing a policy to become meaningless. Separate the rule that configurations must satisfy from the permissions that let people manage compliant resources.

Question 3: data model and service selection

A new order-processing system requires relational transactions, an existing SQL data model, predictable regional latency, and a managed service to reduce database administration. Which step should the architect take first?

  1. Compare supported Azure relational database services and tiers against transaction, compatibility, latency, scaling, protection, and operational requirements.
  2. Select object storage because it automatically provides relational transactions.
  3. Move the database to a globally distributed NoSQL service without checking data access patterns.
  4. Choose the highest-priced database tier before estimating workload demand.
Answer: A. The requirements point to relational data and an existing SQL model, but do not supply enough detail to select a service tier outright. The architect should compare compatibility, performance, scaling, availability, backup, and cost against the workload. Object storage does not provide relational transaction semantics. A globally distributed NoSQL service may be appropriate for another access pattern but should not be selected without evaluating the model. The most expensive tier is not a design method.

This item deliberately asks for the first design step rather than a specific service. A responsible recommendation needs details such as transaction volume, growth, latency target, high availability, regional deployment, and recovery objective. The candidate should avoid inventing missing workload facts.

Question 4: hybrid connectivity and performance

A company is moving a latency-sensitive application in phases. Some services will remain on-premises for a year, and the teams require private connectivity with predictable performance. Which design consideration is most central?

  1. Evaluate private hybrid connectivity options against throughput, latency, redundancy, routing, regional placement, and the migration sequence.
  2. Expose every application component through public endpoints because that is easiest to configure.
  3. Use a storage lifecycle policy to provide network connectivity.
  4. Choose a private endpoint and assume it connects the on-premises network to every Azure service automatically.
Answer: A. The requirements call for private hybrid connectivity and predictable performance during a phased migration. The architect must compare connectivity patterns such as VPN and ExpressRoute based on bandwidth, latency, resilience, route control, cost, and existing network design. Public exposure contradicts the private requirement. Lifecycle policy manages stored data, not network paths. Private endpoints provide private access to supported services but do not by themselves create the overall hybrid connection.

The phrase ‘for a year’ suggests the architecture must support a transition rather than a permanent end state alone. Plan routes, DNS, security controls, and eventual cutover, then validate performance under realistic traffic. The exact circuit or gateway choice depends on facts not supplied in the question.

Question 5: application decoupling

An online booking service experiences spikes when a marketing campaign launches. The booking API should accept requests even when a downstream document-generation worker is temporarily busy. Which architecture pattern best addresses this requirement?

  1. Place a durable message queue between the API and worker so requests can be buffered and processed asynchronously.
  2. Make the API call the worker synchronously and increase the client timeout indefinitely.
  3. Send every request to a monitoring alert and discard the payload.
  4. Store requests in a cache with no persistence or retry mechanism.
Answer: A. A durable queue decouples request acceptance from worker availability and can buffer bursts for later processing. The design still needs retry, idempotency, dead-letter handling, scaling, and monitoring, but the queue directly addresses temporary downstream capacity constraints. An indefinitely extended synchronous call ties up clients and does not absorb bursts. Alerts do not store work. A cache without durability may lose requests.

A complete design would check ordering, duplicate delivery, message retention, processing guarantees, and how the API informs users that work is pending. If the business needs immediate completion, asynchronous processing may change user experience. The scenario says the API should accept requests while the worker is busy, making decoupling central.

Question 6: monitoring and security signals

A regulated organization needs centralized security logs from Azure resources, application telemetry for service health, and a way for responders to investigate incidents. Which design principle is strongest?

  1. Design log collection and routing, application monitoring, retention, access controls, and incident workflows as connected but distinct requirements.
  2. Collect all data in one ungoverned workspace and grant every engineer Owner.
  3. Use a backup vault as the sole monitoring and investigation platform.
  4. Enable a dashboard but omit data retention and responder access design.
Answer: A. The requirements include security logging, application monitoring, and incident investigation. The architecture should identify the sources, route and normalize data appropriately, control who can access it, set retention according to policy, and connect signals to response procedures. A single ungoverned store can violate access or retention requirements. Backup is for recovery, not a complete security analytics platform. A dashboard without underlying data and access design is insufficient.

What the explanations have in common

Each scenario includes a requirement that changes the architecture: restore deleted data; enforce governance while delegating operations; retain relational transactions; maintain private hybrid performance; absorb a downstream workload burst; or support security investigation. First identify what must be true. Then choose the pattern that directly supports it and check dependencies, failure modes, and cost.

A tempting answer can be technically useful but still miss the requirement. A replica may improve availability but not protect a deleted record. A private endpoint can improve service access but does not build hybrid connectivity. A monitor alert can detect a breach but not enforce a location rule. Good exam reasoning names the boundary of a feature.

Practice architecture rather than product recall

For each item, diagram users, application components, data flows, identity, network boundaries, logs, and recovery. Write the nonfunctional requirements next to the components: recovery time, latency, scale, compliance, cost, and operational responsibility. Then identify what the prompt does not tell you. If a missing fact is essential, compare the options based on the supported requirements instead of inventing a detailed design.

Change one requirement after solving. Reduce allowable recovery loss, remove internet access, increase the message rate, require a second region, or limit the operations team’s skill. Ask whether your recommendation changes. If it does, explain which design element moves and why. If it does not, make sure you are not ignoring the new constraint.

Use official practice in context

Microsoft’s Practice Assessment can familiarize candidates with sample wording and help identify gaps. Microsoft states that it is not the secure exam, does not represent the full length or complexity, and may not include every question format, case, or lab. Third-party percentages likewise do not convert to Microsoft’s 700 scaled passing score.

Microsoft’s current policy says role-based exams typically contain 40 to 60 questions, but exact counts vary. Labs may be included, but Microsoft does not publish which specific exams have them in advance. Use this practice set to learn architecture reasoning; use the exam sandbox to understand the general interface; use safe labs to explore services. These tools provide different kinds of preparation evidence.

A review method for misses

Write four notes for every missed question: the business outcome; the decisive constraint; why your choice failed; and what changed constraint would make your choice suitable. For example, a queue is valuable when a worker can process later, but not when every request requires an immediate synchronous result. This turns a miss into a reusable design distinction.

Do not copy or distribute secure items remembered from an exam. General notes such as ‘I confused backup with availability’ are useful without disclosing protected content. Review official documentation for current service details and the study guide for scope.

Readiness check

You are ready to move beyond basic questions when you can discuss requirements before naming services, explain a design’s dependencies, compare a credible alternative, and identify operational trade-offs. A good architect answer is often conditional on workload facts, but it still gives a clear recommendation under the facts supplied. Practice stating the answer directly, then explain what would change it.

When two options appear equivalent, look for a hidden operational constraint. Does one need custom failover scripts? Does one depend on a feature unsupported in the target region? Does one create duplicate data or require a consistency model the application cannot tolerate? The exam’s best answer usually reflects the specific facts rather than a generic preference for managed services or maximum redundancy.

Common questions

Are these official AZ-305 questions?

No. They are original educational scenarios and do not reproduce Microsoft’s secure exam.

Do these questions predict a Microsoft score?

No. This short set is not a full exam and does not use Microsoft scaled scoring.

What should I do after getting an architecture question wrong?

Identify the business requirement, the deciding constraint, and the trade-off you missed; then practice a changed scenario.

Does AZ-305 include labs?

Labs may appear on role-based exams, but Microsoft does not publish exam-specific lab inclusion in advance.