For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAzure Solutions Architect Expert (AZ-305)Azure Solutions Architect Expert AZ-305 Practice Exam 4Question 03
    Hard1 markMultiple Choice
    Domain 1.2: Authentication and AuthorizationIdentitySecurityZero Trust
    This question is part of a case study — click to read the full scenario(Case 01)

    CASE STUDY: Tailspin Toys

    Tailspin Toys is a global manufacturing company with 50,000 employees across 30 countries. They currently operate a mix of on-premises infrastructure (500 servers across 5 data centers) and Azure (20 subscriptions with 100+ VMs and various PaaS services). Their annual IT budget is $50 million, with plans to migrate 70% of workloads to Azure within 2 years.

    Business Requirements: The company needs to reduce IT costs by 30%, improve disaster recovery (current RTO: 24 hours -> target: 2 hours), enhance security posture to meet ISO 27001 and SOC 2 compliance, and enable remote work for 80% of employees. All solutions must support future growth of 20% annually.

    Technical Constraints: Some legacy applications cannot be modified and must run on Windows Server 2012. Network connectivity requires 10 Gbps throughput to Azure with <20ms latency. GDPR compliance mandates that EU customer data must remain in European Azure regions.

    You need to design a migration strategy for the legacy Windows Server 2012 applications. The solution must minimize operational overhead and maintain compliance while ensuring the applications remain supported.

    Which compute solution should you recommend?

    View full case study page →

    AZ-305 · Question 03 · Domain 1.2: Authentication and Authorization

    CASE STUDY: Tailspin Toys

    Tailspin Toys is a global manufacturing company with 50,000 employees across 30 countries. They currently operate a mix of on-premises infrastructure (500 servers across 5 data centers) and Azure (20 subscriptions with 100+ VMs and various PaaS services). Their annual IT budget is $50 million, with plans to migrate 70% of workloads to Azure within 2 years.

    Business Requirements: The company needs to reduce IT costs by 30%, improve disaster recovery (current RTO: 24 hours -> target: 2 hours), enhance security posture to meet ISO 27001 and SOC 2 compliance, and enable remote work for 80% of employees. All solutions must support future growth of 20% annually.

    Technical Constraints: Some legacy applications cannot be modified and must run on Windows Server 2012. Network connectivity requires 10 Gbps throughput to Azure with <20ms latency. GDPR compliance mandates that EU customer data must remain in European Azure regions.

    You need to design the identity and access management solution to support the remote work requirement while meeting the strict security compliance standards.

    Which TWO features should you include in your design? (Select TWO)

    Answer options:

    A.

    Microsoft Entra Conditional Access

    B.

    Azure AD Domain Services

    C.

    Microsoft Entra Multi-Factor Authentication (MFA)

    D.

    Microsoft Entra External ID (B2C)

    E.

    Microsoft Entra Workload Identities

    How to approach this question

    Focus on 'remote work for employees' and 'security compliance'. You need solutions that verify user identity and context.

    Full Answer

    Microsoft Entra Conditional Access, Microsoft Entra Multi-Factor Authentication
    To secure a remote workforce and meet strict compliance standards (ISO 27001, SOC 2), a Zero Trust approach is required. Microsoft Entra Multi-Factor Authentication (MFA) ensures strong authentication, while Conditional Access policies enforce access controls based on real-time risk, device compliance, and location.

    Common mistakes

    Selecting Azure AD Domain Services thinking it's required for remote workers to authenticate to legacy apps, but Conditional Access + MFA is the primary security boundary.
    Question 02All questionsQuestion 04

    Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 4

    55 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...MediumQ02CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...MediumQ04CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...MediumQ05CASE STUDY: Tailspin Toys Tailspin Toys is a global manufacturing company with 50,000 employees ...HardQ06Contoso Ltd has 50 Azure subscriptions managed via a complex Management Group hierarchy. They are...Medium
    View all 55 questions →