Microsoft Designing Microsoft Azure Infrastructure Solutions AZ-305 Exam Questions

Page: 1 / 14
Total 379 questions
Question 1

You need to deploy resources to host a stateless web app in an Azure subscription. The solution must meet the following requirements:

* Provide access to the full .NET framework.

* Provide redundancy if an Azure region fails.

* Grant administrators access to the operating system to install custom application dependencies.

Solution: You deploy an Azure virtual machine to two Azure regions, and you deploy an Azure Application Gateway.

Does this meet the goal?



Answer : B

You need to deploy two Azure virtual machines to two Azure regions, but also create a Traffic Manager profile.


Question 2

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

Your company, named Contoso, Ltd., has a Microsoft Entra tenant named contoso.com that uses Privileged Identity Management (PIM) and is linked to an Azure subscription named Sub1.

You use Azure Backup to back up all the resources in Sub1 to a Recovery Services vault named Vault1.

An external company named Fabrikam, Inc. provides security management services to Contoso. Fabrikam has a Microsoft Entra tenant named fabrikam.com and an Azure subscription.

You need to prevent a compromised administrator account in contoso.com from modifying backup policies in and deleting backups from Sub1.

Solution: In Vault 1, you generate a security PIN for critical operations.

Does this meet the goal?



Answer : B

A security PIN does not provide the required independent authorization in another tenant. Use Resource Guard and MUA.


Question 3

You have an Azure subscription that contains an Azure HDInsight cluster named Cluster! and an Azure Data Lake Storage Gen2 account named account1 account1 uses read-access geo-redundant storage (RA-GRS) and blob snapshots. Cluster! stores 2 TB of data in account1.

The primary Azure region of account! experiences an outage.

You create a new Data Lake Storage Gen2 account named account2 in a different Azure region and register the account as the default storage for Cluster 1.

You need to populate account2 with the data from account1. The solution must meet the following requirements:

* Minimize how long it takes to restore access to the data.

* Minimize administrative effort.

What should you use?



Answer : B


Question 4

You are designing an Azure solution.

The network traffic for the solution must be securely distributed by providing the following features:

HTTPS protocol

Round robin routing

SSL offloading

You need to recommend a load balancing option.

What should you recommend?



Answer : D

If you are looking for Transport Layer Security (TLS) protocol termination ('SSL offload') or per-HTTP/HTTPS

request, application-layer processing, review Application Gateway.

Application Gateway is a layer 7 load balancer, which means it works only with web traffic (HTTP, HTTPS, WebSocket, and HTTP/2). It supports capabilities such as SSL termination, cookie-based session affinity, and round robin for load-balancing traffic. Load Balancer load-balances traffic at layer 4 (TCP or UDP).


https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-faq

Question 5

You are designing a solution that will include containerized applications running in an Azure Kubernetes Service (AKS) cluster.

You need to recommend a load balancing solution for HTTPS traffic. The solution must meet the following requirements:

Automatically configure load balancing rules as the applications are deployed to the cluster.

Support Azure Web Application Firewall (WAF).

Support cookie-based affinity.

Support URL routing.

What should you include the recommendation?



Answer : B

Much like the most popular Kubernetes Ingress Controllers, the Application Gateway Ingress Controller provides several features, leveraging Azure's native Application Gateway L7 load balancer. To name a few:

URL routing

Cookie-based affinity

Secure Sockets Layer (SSL) termination

End-to-end SSL

Support for public, private, and hybrid web sites

Integrated support of Azure web application firewall

Application Gateway redirection support isn't limited to HTTP to HTTPS redirection alone. This is a generic redirection mechanism, so you can redirect from and to any port you define using rules. It also supports redirection to an external site as well.


https://docs.microsoft.com/en-us/azure/application-gateway/features

Question 6

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

Your company, named Contoso, Ltd., has a Microsoft Entra tenant named contoso.com that uses Privileged Identity Management (PIM) and is linked to an Azure subscription named Sub1.

You use Azure Backup to back up all the resources in Sub! to a Recovery Services vault named Vault1.

An external company named Fabrikam, Inc. provides security management services to Contoso. Fabrikam has a Microsoft Entra tenant named fabrikam.com and an Azure subscription.

You need to prevent a compromised administiator account in contoso.com from modifying backup policies in and deleting backups from Sub1.

Solution: You configure Multi-user authorization (MUA) in Sub1 by using a Resource Guard from fabiikam.com. Does this meet the goal?



Answer : A

A Resource Guard in another tenant is the recommended separation-of-duties design for Azure Backup multi-user authorization.


Question 7

You have an on-premises server named Server1 that runs Windows Server and contains a Microsoft SQL Server database named DB1.

You have an Azure subscription.

You plan to migrate D81 to Azure.

You use the Azure Database Migration Service to assess DB1 and receive the assessment results shown in the following table.

You need to recommend a migration target for DB1. The migration target must meet the following requirements:

* Eliminate the need for post-migration operating system maintenance.

* Minimize administrative effort to prepare for the migration.

What should you recommend?



Answer : A


Page:    1 / 14   
Total 379 questions