Azure · AZ-305

AZ-305 · Architecture test

25 scenario-based questions about identity, governance, data, continuity, compute, integration and network design in Azure.

25 questions4 domainsEstimated 30–40 min

Reviewed · 13 July 2026

0 / 25 answered

Question 1: An organization has 40 Azure subscriptions across production, test and several business units. Security requirements must be consistent, while some rules vary by unit. Which design provides the most scalable governance?
Question 2: An App Service application must read secrets from Key Vault without storing a password, certificate or client secret in configuration. What should the architect recommend?
Question 3: External consultants should use their home organization accounts for time-limited access to internal applications, and access must be reviewable. Which solution fits best?
Question 4: A security team must run KQL queries across platform logs from many subscriptions and correlate data across resources. What is the key design element?
Question 5: An operations team should manage virtual machines in one resource group but not networks or other resource groups. How should access be designed?
Question 6: Production administrators need privileged access only during incidents, with MFA, justification and approval. Which service is designed for this?
Question 7: A solution must notify operations when error rate rises and start an automated incident workflow. Which design is most direct?
Question 8: A global application stores JSON documents and needs low read latency across regions, tunable consistency and automatic distribution. Which service fits best?
Question 9: A new relational application has unpredictable usage, long idle periods and must pause compute automatically to reduce cost. What should be recommended?
Question 10: Documents in Blob Storage should move to a cheaper tier after 90 days and be deleted after seven years. What achieves this with the least custom code?
Question 11: A solution must retain PostgreSQL compatibility, use a managed service and survive one availability-zone failure. Which design is most relevant?
Question 12: A team needs scheduled, monitored movement of data between on-premises SQL sources, Blob Storage and analytics. Which service should it use?
Question 13: A requirement allows at most five minutes of data loss and requires service restoration within one hour. What do the five minutes describe?
Question 14: Virtual machines must replicate to another Azure region and start there through an orchestrated failover plan. Which service is designed for this?
Question 15: Two Azure SQL logical servers in different regions need a readable secondary and stable listener that can switch regions. What should be used?
Question 16: An application spans three availability zones in one region. Which risk remains unaddressed by that design alone?
Question 17: An order system needs durable commands, dead-lettering and FIFO processing per customer. Which service fits best?
Question 18: Several independent subscribers should react when a blob is created. Events are discrete and the publisher should not know the consumers. What should be used?
Question 19: A public web service has global users and needs edge acceleration, global routing, TLS and WAF. Which ingress service is most relevant?
Question 20: A regional web application needs layer-7 routing, TLS termination and WAF inside a virtual network. What should be selected?
Question 21: A PaaS database must be reached from a VNet over a private IP while public network access is disabled. Which pattern should be used?
Question 22: Short-lived code should run when a message arrives, scale to zero and bill by use without container administration. What is the first choice?
Question 23: A team has containerized microservices and needs HTTP and event-driven scaling plus revisions, but does not want to operate Kubernetes. What fits best?
Question 24: When is Azure Kubernetes Service a more natural choice than Container Apps?
Question 25: A large on-premises datacentre needs private, predictable connectivity to an Azure hub-and-spoke network without using the public internet. What belongs in the design?