Microsoft

AZ-305 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 231-question bank.

Provider
Microsoft
Question bank
231
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for AZ-305, a certification listed under Microsoft. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Microsoft. The certification credential is issued by Microsoft, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    You have an Azure subscription that contains a custom application named Application1. Application1 was developed by an external company named Fabrikam, Ltd. Developers at Fabrikam were assigned role-based access control (RBAC) permissions to the Application1 components. All users are licensed for the Microsoft 365 E5 plan. You need to recommend a solution to verify whether the Fabrikam developers still require permissions to Application1. The solution must meet the following requirements: ✑ To the manager of the developers, send a monthly email message that lists the access permissions to Application1. ✑ If the manager does not verify an access permission, automatically revoke that permission. ✑ Minimize development effort. What should you recommend?

    Choose one answer.

    • In Azure Active Directory (Azure AD), create an access review of Application1.
    • Create an Azure Automation runbook that runs the Get-AzRoleAssignment cmdlet.
    • In Azure Active Directory (Azure AD) Privileged Identity Management, create a custom role assignment for the Application1 resources.
    • Create an Azure Automation runbook that runs the Get-AzureADUserAppRoleAssignment cmdlet.
  2. Question 2 · 1

    You are designing a large Azure environment that will contain many subscriptions. You plan to use Azure Policy as part of a governance solution. To which three scopes can you assign Azure Policy definitions? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

    Choose all answers that apply.

    • Azure Active Directory (Azure AD) administrative units
    • Azure Active Directory (Azure AD) tenants
    • subscriptions
    • compute resources
    • resource groups
    • management groups
  3. Question 3 · 1

    You need to recommend a solution to generate a monthly report of all the new Azure Resource Manager (ARM) resource deployments in your Azure subscription. What should you include in the recommendation?

    Choose one answer.

    • Azure Activity Log
    • Azure Advisor
    • Azure Analysis Services
    • Azure Monitor action groups
  4. Question 4 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your company deploys several virtual machines on-premises and to Azure. ExpressRoute is deployed and configured for on-premises to Azure connectivity. Several virtual machines exhibit network connectivity issues. You need to analyze the network traffic to identify whether packets are being allowed or denied to the virtual machines. Solution: Install and configure the Azure Monitoring agent and the Dependency Agent on all the virtual machines. Use VM insights in Azure Monitor to analyze the network traffic. Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  5. Question 5 · 1

    Your company, named Contoso, Ltd., implements several Azure logic apps that have HTTP triggers. The logic apps provide access to an on-premises web service. Contoso establishes a partnership with another company named Fabrikam, Inc. Fabrikam does not have an existing Azure Active Directory (Azure AD) tenant and uses third-party OAuth 2.0 identity management to authenticate its users. Developers at Fabrikam plan to use a subset of the logic apps to build applications that will integrate with the on-premises web service of Contoso. You need to design a solution to provide the Fabrikam developers with access to the logic apps. The solution must meet the following requirements: ✑ Requests to the logic apps from the developers must be limited to lower rates than the requests from the users at Contoso. ✑ The developers must be able to rely on their existing OAuth 2.0 provider to gain access to the logic apps. ✑ The solution must NOT require changes to the logic apps. ✑ The solution must NOT use Azure AD guest accounts. What should you include in the solution?

    Choose one answer.

    • Azure Front Door
    • Azure AD Application Proxy
    • Azure AD business-to-business (B2B)
    • Azure API Management
  6. Question 6 · 1

    HOTSPOT - Your company has the divisions shown in the following table. You plan to deploy a custom application to each subscription. The application will contain the following: ✑ A resource group ✑ An Azure web app ✑ Custom role assignments ✑ An Azure Cosmos DB account You need to use Azure Blueprints to deploy the application to each subscription. What is the minimum number of objects required to deploy the application? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1
    Question illustration 2

    Management groups

    • 1
    • 2
    • 3
    • 4

    Blueprint definitions

    • 1
    • 2
    • 3
    • 4

    Blueprint assignments

    • 1
    • 2
    • 3
    • 4
  7. Question 7 · 1

    You have an Azure subscription. The subscription has a blob container that contains multiple blobs. Ten users in the finance department of your company plan to access the blobs during the month of April. You need to recommend a solution to enable access to the blobs during the month of April only. Which security solution should you include in the recommendation?

    Choose one answer.

    • shared access signatures (SAS)
    • Conditional Access policies
    • certificates
    • access keys
  8. Question 8 · 1

    You plan to deploy an Azure SQL database that will store Personally Identifiable Information (PII). You need to ensure that only privileged users can view the PII. What should you include in the solution?

    Choose one answer.

    • dynamic data masking
    • role-based access control (RBAC)
    • Data Discovery & Classification
    • Transparent Data Encryption (TDE)
  9. Question 9 · 1

    You plan to deploy an app that will use an Azure Storage account. You need to deploy the storage account. The storage account must meet the following requirements: ✑ Store the data for multiple users. ✑ Encrypt each user's data by using a separate key. ✑ Encrypt all the data in the storage account by using customer-managed keys. What should you deploy?

    Choose one answer.

    • files in a premium file share storage account
    • blobs in a general purpose v2 storage account
    • blobs in an Azure Data Lake Storage Gen2 account
    • files in a general purpose v2 storage account
  10. Question 10 · 1

    You plan to deploy an application named App1 that will run on five Azure virtual machines. Additional virtual machines will be deployed later to run App1. You need to recommend a solution to meet the following requirements for the virtual machines that will run App1: ✑ Ensure that the virtual machines can authenticate to Azure Active Directory (Azure AD) to gain access to an Azure key vault, Azure Logic Apps instances, and an Azure SQL database. ✑ Avoid assigning new roles and permissions for Azure services when you deploy additional virtual machines. ✑ Avoid storing secrets and certificates on the virtual machines. ✑ Minimize administrative effort for managing identities. Which type of identity should you include in the recommendation?

    Choose one answer.

    • a system-assigned managed identity
    • a service principal that is configured to use a certificate
    • a service principal that is configured to use a client secret
    • a user-assigned managed identity
  11. Question 11 · 1

    You have the resources shown in the following table: CDB1 hosts a container that stores continuously updated operational data. You are designing a solution that will use AS1 to analyze the operational data daily. You need to recommend a solution to analyze the data without affecting the performance of the operational data store. What should you include in the recommendation?

    Choose one answer.

    Question illustration 1
    • Azure Cosmos DB change feed
    • Azure Data Factory with Azure Cosmos DB and Azure Synapse Analytics connectors
    • Azure Synapse Link for Azure Cosmos DB
    • Azure Synapse Analytics with PolyBase data loading
  12. Question 12 · 1

    You have an application that is used by 6,000 users to validate their vacation requests. The application manages its own credential store. Users must enter a username and password to access the application. The application does NOT support identity providers. You plan to upgrade the application to use single sign-on (SSO) authentication by using an Azure Active Directory (Azure AD) application registration. Which SSO method should you use?

    Choose one answer.

    • header-based
    • SAML
    • password-based
    • OpenID Connect
  13. Question 13 · 1

    HOTSPOT - You have an Azure subscription that contains a virtual network named VNET1 and 10 virtual machines. The virtual machines are connected to VNET1. You need to design a solution to manage the virtual machines from the internet. The solution must meet the following requirements: ✑ Incoming connections to the virtual machines must be authenticated by using Azure Multi-Factor Authentication (MFA) before network connectivity is allowed. ✑ Incoming connections must use TLS and connect to TCP port 443. ✑ The solution must support RDP and SSH. What should you include in the solution? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1

    Provide access to virtual machines on VNET1

    • Azure Bastion
    • Just-in-time (JIT) VM access
    • Azure Web Application Firewall (WAF) in Azure Front Door

    Enforce Azure MFA

    • An Azure Identity Governance access package
    • A Conditional Access policy that has the Cloud apps assignment set to Azure Windows VM Sign-In
    • A Conditional Access policy that has the Cloud apps assignment set to Microsoft Azure Management
  14. Question 14 · 1

    You have an Azure Active Directory (Azure AD) tenant that syncs with an on-premises Active Directory domain. You have an internal web app named WebApp1 that is hosted on-premises. WebApp1 uses Integrated Windows authentication. Some users work remotely and do NOT have VPN access to the on-premises network. You need to provide the remote users with single sign-on (SSO) access to WebApp1. Which two features should you include in the solution? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

    Choose all answers that apply.

    • Azure AD Application Proxy
    • Azure AD Privileged Identity Management (PIM)
    • Conditional Access policies
    • Azure Arc
    • Azure AD enterprise applications
    • Azure Application Gateway
  15. Question 15 · 1

    You are designing an Azure governance solution. All Azure resources must be easily identifiable based on the following operational information: environment, owner, department and cost center. You need to ensure that you can use the operational information when you generate reports for the Azure resources. What should you include in the solution?

    Choose one answer.

    • an Azure data catalog that uses the Azure REST API as a data source
    • an Azure management group that uses parent groups to create a hierarchy
    • an Azure policy that enforces tagging rules
    • Azure Active Directory (Azure AD) administrative units

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free