Azure Solutions Architect Expert AZ-305 Practice Exam 3
55 free questions · No sign-up required to browse
Expert-level practice exam for the Microsoft Azure Solutions Architect Expert (AZ-305) certification. Tests advanced architectural knowledge, enterprise solution design, and trade-off analysis across compute, network, storage, and identity.
Difficulty breakdown
Topics covered
Browse all topics →Sample questions
Contoso Ltd is a global manufacturing company with 50,000 employees across 30 countries. They currently operate a mix of on-premises infrastructure and Azure (20 subscriptions with 100+ VMs and various PaaS services).
The company needs to design a centralized logging and monitoring solution. The security team requires full visibility into all security events across all subscriptions. However, individual application teams must only be able to view logs and metrics for their specific resources. Data sovereignty laws require that logs generated by resources in the European Union (EU) remain in the EU.
Which Log Analytics workspace architecture should you recommend to meet ALL requirements while minimizing operational overhead?
Fabrikam Inc. is a Managed Service Provider (MSP) managing Azure environments for 50 different enterprise customers. Each customer has their own Microsoft Entra ID (Azure AD) tenant and multiple Azure subscriptions.
Fabrikam needs to implement a centralized security monitoring and incident response solution. The Fabrikam Security Operations Center (SOC) team must be able to view alerts, hunt for threats, and run automated playbooks across all 50 customer tenants from a single pane of glass. Customers must retain ownership of their data, and Fabrikam must not require guest accounts in customer tenants.
Which combination of Azure services should you recommend?
A financial institution generates 5 TB of telemetry and audit logs daily across its Azure environment.
The company has the following requirements for log data:
- Security audit logs must be queried frequently for the first 30 days for immediate incident response.
- Application debug logs are rarely queried but must be retained for 7 years to meet compliance regulations.
- The overall cost of log ingestion and retention must be minimized.
Which TWO actions should you recommend to optimize the architecture? (Select TWO)
A retail company has recently migrated several workloads to Azure. The IT Director wants a centralized dashboard that provides actionable recommendations to optimize their Azure deployments.
The recommendations must cover:
- Identifying underutilized virtual machines to reduce costs
- Highlighting missing high availability configurations
- Identifying security vulnerabilities
- Recommending performance improvements for SQL databases
Which Azure service should you recommend as the primary tool to meet these requirements?
A healthcare organization with 10,000 employees uses on-premises Active Directory. They are migrating to Microsoft 365 and Azure.
The Chief Information Security Officer (CISO) has established the following strict identity requirements:
- Users must experience Single Sign-On (SSO) when accessing cloud apps from domain-joined devices.
- Authentication must be evaluated against on-premises Active Directory security policies (e.g., account lockout, permitted logon hours) in real-time.
- Due to strict compliance regulations, user password hashes MUST NOT be synchronized to the cloud under any circumstances.
- The solution must support high availability.
Which hybrid identity authentication method should you recommend?
Ready to Practice the full exam?
All 55 questions with worked answers, mark schemes, and AI tutoring.
Expert