Weekend Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

AZ-305 Questions and Answers

Question # 6

You plan to migrate App1 to Azure. The solution must meet the authentication and authorization requirements.

Which type of endpoint should App1 use to obtain an access token?

A.

Azure Instance Metadata Service (IMDS)

B.

Azure AD

C.

Azure Service Management

D.

D. Microsoft identity platform

Full Access
Question # 7

You need to recommend a solution that meets the data requirements for App1.

What should you recommend deploying to each availability zone that contains an instance of App1?

A.

an Azure Cosmos DB that uses multi-region writes

B.

an Azure Data Lake store that uses geo-zone-redundant storage (GZRS)

C.

an Azure SQL database that uses active geo-replication

D.

an Azure Storage account that uses geo-zone-redundant storage (GZRS)

Full Access
Question # 8

What should you implement to meet the identity requirements? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 9

You plan to migrate App1 to Azure.

You need to estimate the compute costs for App1 in Azure. The solution must meet the security and compliance requirements.

What should you use to estimate the costs, and what should you implement to minimize the costs? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 10

How should the migrated databases DB1 and DB2 be implemented in Azure?

Full Access
Question # 11

You need to implement the Azure RBAC role assignments for the Network Contributor role. The solution must meet the authentication and authorization requirements.

What is the minimum number of assignments that you must use?

A.

1

B.

2

C.

5

D.

10

E.

15

Full Access
Question # 12

You need to configure an Azure policy to ensure that the Azure SQL databases have TDE enabled. The solution must meet the security and compliance requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Full Access
Question # 13

You need to ensure that users managing the production environment are registered for Azure MFA and must authenticate by using Azure MFA when they sign in to the Azure portal. The solution must meet the authentication and authorization requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 14

You plan to migrate DB1 and DB2 to Azure.

You need to ensure that the Azure database and the service tier meet the resiliency and business requirements.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 15

You plan to migrate App1 to Azure.

You need to recommend a high-availability solution for App1. The solution must meet the resiliency requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 16

You migrate App1 to Azure. You need to ensure that the data storage for App1 meets the security and compliance requirement

What should you do?

A.

Create an access policy for the blob

B.

Modify the access level of the blob service.

C.

Implement Azure resource locks.

D.

Create Azure RBAC assignments.

Full Access
Question # 17

You plan to migrate App1 to Azure.

You need to recommend a storage solution for App1 that meets the security and compliance requirements.

Which type of storage should you recommend, and how should you recommend configuring the storage? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 18

You plan to migrate App1 to Azure.

You need to recommend a network connectivity solution for the Azure Storage account that will host the App1 data. The solution must meet the security and compliance requirements.

What should you include in the recommendation?

A.

a private endpoint

B.

a service endpoint that has a service endpoint policy

C.

Azure public peering for an ExpressRoute circuit

D.

Microsoft peering for an ExpressRoute circuit

Full Access
Question # 19

You have an Azure subscription. The subscription contains 100 virtual machine that am Windows Server.

You need to recommend a solution that will provide monitoring and an audit trail of the following modifications:

• Changes to the Windows registry on the virtual machines

• Changes to the DNS settings of the virtual machines

The solution must minimize administrative effort.

What should you recommend using for each change? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 20

You plan to deploy an Azure BareMetal Infrastructure instance that will host the data tier of a business-critical workload. The application tier of the workload will be hosted on Azure virtual machines.

You need to configure the virtual machines to minimize network latency between the application tier and the data tier.

What should you use?

A.

an availability zone

B.

ExpressRoute FastPath

C.

an availability set

D.

a proximity placement group

Full Access
Question # 21

The application will host video files that range from 50 MB to 12 GB. The application will use certificate-based authentication and will be available to users on the internet.

You need to recommend a storage option for the video files. The solution must provide the fastest read performance and must minimize storage costs.

What should you recommend?

A.

Azure Files

B.

Azure Data Lake Storage Gen2

C.

Azure Blob Storage

D.

Azure SQL Database

Full Access
Question # 22

You plan to store data in Azure Blob storage for many years. The stored data will be accessed rarely.

You need to ensure that the data in Blob storage is always available for immediate access. The solution must

minimize storage costs.

Which storage tier should you use?

A.

Cool

B.

Archive

C.

Hot

Full Access
Question # 23

You have an Azure subscription that contains an Azure SQL database.

You plan to use Azure reservations on the Azure SQL database.

To which resource type will the reservation discount be applied?

A.

vCore compute

B.

DTU compute

C.

Storage

D.

License

Full Access
Question # 24

You have an application that is used by 6,000 users to validate their vacation requests. The application manages its own credential

Users must enter a username and password to access the application. The application does NOT support identity providers.

You plan to upgrade the application to use single sign-on (SSO) authentication by using an Azure Active Directory (Azure AD) application registration.

Which SSO method should you use?

A.

password-based

B.

OpenID Connect

C.

header-based

D.

SAML

Full Access
Question # 25

Your company has offices in the United States, Europe, Asia, and Australia.

You have an on-premises app named App1 that uses Azure Table storage. Each office hosts a local instance of App1.

You need to upgrade the storage for App1. The solution must meet the following requirements:

Enable simultaneous write operations in multiple Azure regions.

Ensure that write latency is less than 10 ms.

Support indexing on all columns.

Minimize development effort.

Which data platform should you use?

A.

Azure SQL Database

B.

Azure SQL Managed Instance

C.

Azure Cosmos DB

D.

Table storage that uses geo-zone-redundant storage (GZRS) replication

Full Access
Question # 26

You have an on-premises file server that stores 2 TB of data files.

You plan to move the data files to Azure Blob storage in the Central Europe region.

You need to recommend a storage account type to store the data files and a replication solution for the storage account. The solution must meet the following requirements:

Be available if a single Azure datacenter fails.

Support storage tiers.

Minimize cost.

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 27

Your on-premises datacenter contains a server named Server1 that runs Microsoft SQL Server 2022. Server1 contains a 30-TB database named DB1 that stores customer data. Server1 runs a custom application named App1 that verifies the compliance of records in DB1. App1 must run on the same server as DB1.

You have an Azure subscription.

You need to migrate DB1 to Azure. The solution must minimize administrative effort.

To which service should you migrate DB1, and what should you use to perform the migration? To answer, select the appropriate options in the answer area.

Full Access
Question # 28

Your company has an on-premises Hyper-V cluster that contains 20 virtual machines. Some of the virtual machines are based on Windows and some in Linux. You have to migrate the virtual machines onto Azure.

You have to recommend a solution that would be used to replicate the disks of the virtual machines to Azure. The solution needs to ensure that the virtual machines remain available when the migration of the disks is in progress.

You decide to create an Azure storage account and then run AzCopy

Would this fulfill the requirement?

A.

Yes

B.

No

Full Access
Question # 29

You are planning an Azure Storage solution for sensitive data. The data will be accessed daily. The data set is less than 10 GB.

You need to recommend a storage solution that meets the following requirements:

• All the data written to storage must be retained for five years.

• Once the data is written, the data can only be read. Modifications and deletion must be prevented.

• After five years, the data can be deleted, but never modified.

• Data access charges must be minimized

What should you recommend? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 30

You need to recommend an App Service architecture that meets the requirements for Appl. The solution must minimize costs.

What should few recommend?

A.

one App Service Environment (ASE) per availability zone

B.

one App Service plan per availability zone

C.

one App Service plan per region

D.

one App Service Environment (ASE) per region

Full Access
Question # 31

What should you recommend to meet the monitoring requirements for App2?

A.

Microsoft Sentinel

B.

Azure Application Insights

C.

Container insights

D.

VM insights

Full Access
Question # 32

You have an Azure subscription that contains 10 web apps. The apps are integrated with Azure AD and are accessed by users on different project teams.

The users frequently move between projects.

You need to recommend an access management solution for the web apps. The solution must meet the following requirements:

• The users must only have access to the app of the project to which they are assigned currently.

• Project managers must verify which users have access to their project s app and remove users that are no longer assigned to their project.

• Once every 30 days, the project managers must be prompted automatically to verify which users are assigned to the projects.

What should you include in the recommendation?

A.

Microsoft Defender for Identity

B.

Azure AD Identity Governance

C.

Microsoft Entra Permissions Management

D.

Azure AD Identity Protection

Full Access
Question # 33

You have to deploy an Azure SQL database named db1 for your company. The databases must meet the following security requirements

When IT help desk supervisors query a database table named customers, they must be able to see the full number of each credit card

When IT help desk operators query a database table named customers, they must only see the last four digits of each credit card number

A column named Credit Card rating in the customers table must never appear in plain text in the database system. Only client applications must be able to decrypt the information that is stored in this column

Which of the following can be implemented for the Credit Card rating column security requirement?

A.

Always Encrypted

B.

Azure Advanced Threat Protection

C.

Transparent Data Encryption

D.

Dynamic Data Masking

Full Access
Question # 34

You are designing an Azure web app.

You plan to deploy the web app to the North Europe Azure region and the West Europe Azure region.

You need to recommend a solution for the web app. The solution must meet the following requirements:

Users must always access the web app from the North Europe region, unless the region fails.

The web app must be available to users if an Azure region is unavailable.

Deployment costs must be minimized.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 35

You have the Azure subscriptions shown in the following table.

Contoso.onmicrosft.com contains a user named User1.

You need to deploy a solution to protect against ransomware attacks. The solution must meet the following requirements:

• Ensure that all the resources in Sub1 are backed up by using Azure Backup.

• Require that User1 first be assigned a role for Sub2 before the user can make major changes to the backup configuration.

What should you create in each subscription? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Full Access
Question # 36

You plan to use an Azure Storage account to store data assets.

You need to recommend a solution that meets the following requirements:

• Supports immutable storage

• Disables anonymous access to the storage account

• Supports access control list (ACL)-based Azure AD permissions

What should you include in the recommendation?

A.

Azure Blob Storage

B.

Azure Data Lake Storage

C.

Azure NetApp Files

D.

Azure Files

Full Access
Question # 37

Your company has IT, security, and finance departments.

You need to implement a new Azure deployment that will include multiple Azure subscriptions and management groups. The solution must meet the following requirements:

• Ensure that all policies are assigned at the management group level.

• Ensure that all the finance department resources have specific encryption policies applied.

• Ensure that only users in the IT department can create virtual machines in any Azure region.

• Ensure that users in the finance department can create virtual machines in only the East US Azure region.

What is the minimum number of management groups you can create for the planned deployment?

A.

1

B.

2

C.

3

D.

4

Full Access
Question # 38

Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1. Server1 contains an app named App1 that uses AD DS authentication. Remote users access App1 by using a VPN connection to the on-premises network.

You have a Microsoft Entra tenant that syncs with the AD DS domain by using Microsoft Entra Connect.

You need to ensure that the remote users can access App1 without using a VPN. The solution must meet the following requirements:

• Ensure that the users authenticate by using Azure Multi-Factor Authentication (MFA).

• Minimize administrative effort.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 39

You have an Azure AD tenant that contains a management group named MG1. You have the Azure subscriptions shown in the following table.

The subscriptions contain the resource groups shown in the following table.

The subscription contains the Azure AD security groups shown in the following table.

The subscription contains the user accounts shown in the following table.

You perform the following actions:

• Assign User3 the Contributor role for Sub1.

• Assign Group1 the Virtual Machine Contributor role for MG1.

• Assign Group3 the Contributor role for the Tenant Root Group.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 40

NO: 237

You are designing a solution that will include containerized applications running in an Azure Kubernetes Service (AKS) cluster.

You need to recommend a load balancing solution for HTTPS traffic. The solution must meet the following requirements:

Automatically configure load balancing rules as the applications are deployed to the cluster.

Support Azure Web Application Firewall (WAF).

Support cookie-based affinity.

Support URL routing.

What should you include the recommendation?

A.

an NGINX ingress controller

B.

Application Gateway Ingress Controller (AGIC)

C.

an HTTP application routing ingress controller

D.

the Kubernetes load balancer service

Full Access
Question # 41

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

Your company, named Contoso, Ltd., has a Microsoft Entra tenant named contoso.com that uses Privileged Identity Management (PIM) and is linked to an Azure subscription named Sub1.

You use Azure Backup to back up all the resources in Sub! to a Recovery Services vault named Vault1.

An external company named Fabrikam, Inc. provides security management services to Contoso. Fabrikam has a Microsoft Entra tenant named fabrikam.com and an Azure subscription.

You need to prevent a compromised administiator account in contoso.com from modifying backup policies in and deleting backups from Sub1.

Solution: You configure Multi-user authorization (MUA) in Sub1 by using a Resource Guard from fabiikam.com. Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 42

You are evaluating the components of the migration to Azure that require you to provision an Azure Storage account.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Full Access
Question # 43

A company has an on-premises file server cbflserver that runs Windows Server 2019. Windows Admin Center manages this server. The company owns an Azure subscription. You need to provide an Azure solution to prevent data loss if the file server fails.

Solution: You decide to register Windows Admin Center in Azure and then configure Azure Backup.

Would this meet the requirement?

A.

Yes

B.

No

Full Access
Question # 44

You need to recommend a solution to ensure that App1 can access the third-party credentials and access strings. The solution must meet the security requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 45

You need to recommend a solution that meets the file storage requirements for App2.

What should you deploy to the Azure subscription and the on-premises network? To answer, drag the appropriate services to the correct locations. Each service may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Full Access
Question # 46

What should you recommend lo meet the monitoring requirements for App2?

A.

Azure Application Insights

B.

Container insights

C.

Microsoft Sentinel

D.

VM insights

Full Access
Question # 47

You are evaluating whether to use Azure Traffic Manager and Azure Application Gateway to meet the connection requirements for App1.

What is the minimum numbers of instances required for each service? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 48

You design a solution for the web tier of WebApp1 as shown in the exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Full Access
Question # 49

You need to recommend a data storage strategy for WebApp1.

What should you include in in the recommendation?

A.

an Azure SQL Database elastic pool

B.

a vCore-based Azure SQL database

C.

an Azure virtual machine that runs SQL Server

D.

a fixed-size DTU AzureSQL database.

Full Access
Question # 50

To meet the authentication requirements of Fabrikam, what should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 51

You need to recommend a solution to meet the database retention requirement. What should you recommend?

A.

Configure a long-term retention policy for the database.

B.

Configure Azure Site Recovery.

C.

Configure geo replication of the database.

D.

Use automatic Azure SQL Database backups.

Full Access