Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 58 pages
Exam (elaborations)

AZ-305 Azure Solutions Architect Exam Prep 2026 Comprehensive Microsoft Azure Architecture Certification Review Practice Questions with Detailed Rationales

Document preview thumbnail
Preview 4 out of 58 pages

AZ-305 Azure Solutions Architect Exam Prep 2026 Comprehensive Microsoft Azure Architecture Certification Review Practice Questions with Detailed Rationales

Content preview

AZ-305 Azure Solutions Architect Exam Prep
2026 Comprehensive Microsoft Azure
Architecture Certification Review Practice
Questions with Detailed Rationales

Question 1
A multinational enterprise is designing an identity strategy using Microsoft Entra
ID. The company has 15,000 employees across 20 global offices and uses an on-
premises Active Directory Domain Services (AD DS) environment. The company
needs to enable seamless single sign-on (SSO) for all cloud applications, enforce
conditional access policies, and ensure password hash synchronization for disaster
recovery. Which identity solution should the Solutions Architect recommend?
A) Microsoft Entra ID with password hash synchronization and Seamless SSO
B) Microsoft Entra ID with pass-through authentication and Seamless SSO
C) Microsoft Entra ID with federation using Active Directory Federation Services
(AD FS)
D) Microsoft Entra ID with cloud-only identities and no on-premises integration
Answer: A
Rationale: Password hash synchronization (PHS) with Seamless SSO provides the
best balance of simplicity, security, and functionality for this scenario. PHS
synchronizes password hashes to Entra ID, enabling disaster recovery if the on-
premises environment becomes unavailable. Seamless SSO provides automatic
sign-on for users on domain-joined devices. Pass-through authentication (Option
B) requires on-premises agents and lacks the disaster recovery benefit of PHS.
Federation with AD FS (Option C) adds unnecessary complexity for 15,000 users.
Cloud-only identities (Option D) would require a complete migration away from
on-premises AD, which is not the requirement. PHS also enables leaked credential
detection and Entra ID Identity Protection features.


Question 2
A company is implementing Azure Policy to enforce governance across multiple

,Azure subscriptions. The company has three management
groups: Root, Production, and Development. The Solutions Architect needs to
ensure that all virtual machines in the Production management group are deployed
only from approved VM images. The policy should NOT apply to
the Development management group. Which Azure Policy assignment should the
Architect configure?
A) Assign the policy at the Root management group with an exclusion for
the Development management group
B) Assign the policy at the Production management group level only
C) Assign the policy at the subscription level for each production subscription
D) Assign the policy at the Root management group with a parameter that filters
by resource group
Answer: B
Rationale: Assigning the policy directly at the Production management group
level ensures the policy applies to all subscriptions and resources
under Production while not affecting the Development management group. Policy
inheritance flows from management group to child management groups and
subscriptions. Assigning at Root with an exclusion (Option A) would require
additional configuration and creates a broader policy footprint. Assigning at each
subscription (Option C) creates management overhead and does not leverage
management group inheritance. Filtering by resource group (Option D) does not
address the management group structure.


Question 3
A Solutions Architect is designing a monitoring strategy for a mission-critical e-
commerce application hosted on Azure Virtual Machines. The application has the
following requirements:
• Monitor CPU, memory, and disk utilization
• Detect application performance anomalies
• Receive alerts when error rates exceed thresholds
• Centralize logs from all application components
• Enable distributed tracing across microservices

,Which combination of Azure services should the Architect recommend?
A) Azure Monitor, Log Analytics workspace, and Application Insights
B) Azure Monitor and Azure Network Watcher only
C) Azure Log Analytics and Azure Security Center only
D) Azure Application Insights and Azure Monitor only (without Log Analytics)
Answer: A
Rationale: This combination provides comprehensive monitoring coverage. Azure
Monitor collects platform metrics (CPU, memory, disk). Log Analytics workspace
centralizes logs for querying and analysis. Application Insights provides
application performance monitoring (APM), distributed tracing, and anomaly
detection. Option B lacks application-level monitoring and log centralization.
Option C lacks APM capabilities. Option D provides APM and metrics but lacks
the centralized log querying capabilities provided by Log Analytics. Application
Insights data is stored in a Log Analytics workspace by default, making the
combination of all three services the most complete solution.


Question 4
A company is designing an Azure governance model with multiple subscriptions.
The company needs to:
• Enforce a naming convention for all resources
• Automatically apply a CostCenter tag to all resources
• Prevent the deployment of virtual machines in unauthorized regions
• Audit compliance with security policies
Which Azure service should the Solutions Architect use to achieve ALL of these
requirements?
A) Azure Policy with initiative definitions
B) Azure RBAC with custom roles
C) Azure Blueprints
D) Azure Management Groups with subscription policies
Answer: A

, Rationale: Azure Policy with initiative definitions (groups of related policies) can
enforce naming conventions (using the deny effect with pattern matching),
automatically apply tags (using the modify or append effect), restrict regions
(using the deny effect with locations parameter), and audit compliance (using
the audit or auditIfNotExists effect). This provides centralized governance across
multiple subscriptions. RBAC (Option B) controls permissions, not resource
configuration. Blueprints (Option C) compose environments but do not enforce
ongoing compliance. Management groups (Option D) organize subscriptions but
do not enforce policies directly.


Question 5
A Solutions Architect is designing access control for a complex enterprise
environment. The company has 5,000 users, 200 applications, and 150 Azure
subscriptions. The Architect needs to implement a solution that:
• Provides a single pane of glass for identity governance
• Enables just-in-time (JIT) access for privileged roles
• Automates access reviews and certifications
• Integrates with the existing identity governance processes
Which Azure service should the Architect recommend?
A) Microsoft Entra ID
B) Microsoft Entra ID Governance
C) Azure Privileged Identity Management (PIM)
D) Microsoft Entra ID with Conditional Access
Answer: B
Rationale: Microsoft Entra ID Governance (formerly Azure AD Governance) is
the comprehensive solution for identity governance, providing access reviews,
entitlement management, and privileged access management. It delivers a single
pane of glass for identity governance. PIM (Option C) is a component of Entra ID
Governance that provides JIT access for privileged roles but does not include
access reviews or entitlement management. Entra ID (Option A) is the identity
service itself, not the governance layer. Conditional Access (Option D) is for
access policies, not governance lifecycle management.

Document information

Uploaded on
August 9, 2026
Number of pages
58
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$26.59

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
18
Followers
0
Items
2497
Last sold
3 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions