{"id":12224,"date":"2026-09-15T07:00:39","date_gmt":"2026-09-15T07:00:39","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12224"},"modified":"2026-09-15T07:00:39","modified_gmt":"2026-09-15T07:00:39","slug":"microsoft-az-305-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-305-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Microsoft AZ-305 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <a href=\"https:\/\/www.examlabs.com\/az-305-exam-dumps\">Microsoft AZ-305 Exam Dumps<\/a> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>A company needs to connect an on-premises network to Azure using a dedicated private connection that does not traverse the public internet. Which service should the architect recommend?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ExpressRoute<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure ExpressRoute provides private connectivity between an organization&#8217;s on-premises network and Microsoft cloud services. The connection is established through an ExpressRoute provider or exchange provider rather than using the public internet. ExpressRoute can provide more predictable performance, reliability, and connectivity characteristics than a site-to-site VPN. Traffic Manager provides DNS-based routing, VPN Gateway provides encrypted network connectivity over supported VPN connections, and CDN provides content delivery. Architects should evaluate bandwidth, provider availability, routing requirements, redundancy, cost, and ExpressRoute Global Reach requirements when designing the connection.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which Azure service provides centralized DNS hosting and name resolution for resources that require custom domain names?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DNS provides hosting for DNS domains and supports DNS records that can direct users and applications to Azure or external resources. It uses Azure&#8217;s global infrastructure and integrates with Azure resource management and access control. Azure Private DNS is used when private name resolution is required within virtual networks. Bastion provides secure VM access, Firewall controls network traffic, and Policy provides governance. Architects should determine whether public or private DNS is required and design appropriate zones, records, delegation, and resolution paths for the application architecture.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>A web application is deployed in multiple Azure regions. Users should automatically be directed to the region providing the lowest network latency. Which routing method is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geographic routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Priority routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weighted routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Performance routing in Azure Traffic Manager directs users toward the endpoint that provides the best network performance based on latency measurements between users and Azure regions. This is useful for globally distributed applications where reducing network latency is an important requirement. Geographic routing instead bases decisions on the geographic location of users, while priority routing is commonly used for ordered failover and weighted routing distributes traffic according to assigned weights. Architects should also consider endpoint health, application state, DNS caching, regional capacity, and data consistency when designing global traffic distribution.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>A company wants to connect two virtual networks in Azure and requires resources in both networks to communicate privately. What should the architect configure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VNet peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Event Grid<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VNet peering provides private connectivity between Azure virtual networks. Resources in peered networks can communicate using private IP addresses over Microsoft&#8217;s network infrastructure. Peering can be configured between virtual networks in the same region or between supported regions using global VNet peering. Architects should remember that VNet peering is not automatically transitive, meaning a connection from VNet A to VNet B and from VNet B to VNet C does not automatically connect A to C. Routing, address spaces, security rules, and DNS should also be considered.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which Azure capability allows applications to use managed identities instead of storing credentials in application configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID provides the identity platform used by Azure managed identities. Managed identities allow supported Azure resources and applications to authenticate to services without requiring developers to store passwords, client secrets, or certificates in application code. Azure automatically manages the identity credentials and rotation. Resource Graph is used for resource querying, Policy provides governance, and Traffic Manager provides DNS-based routing. Architects should assign only the permissions required by the workload and use role-based access control to maintain least privilege when managed identities access resources such as Key Vault or Storage.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>A company wants to ensure that a storage account can only be accessed through selected networks and not from arbitrary public locations. Which configuration should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage account network rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Advisor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Insights<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cost Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Storage account network rules allow organizations to control which networks can access a storage account. Depending on the architecture, access can be restricted using virtual networks, IP network rules, resource instances, or private endpoints. These controls help reduce the public exposure of storage resources and support defense-in-depth security. Azure Advisor provides recommendations, Application Insights monitors applications, and Cost Management tracks spending. Architects should combine network restrictions with identity-based authorization, encryption, secure transfer requirements, and appropriate logging rather than relying on network rules as the only security control.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>An application requires a highly available PostgreSQL database with automatic failover within an Azure region. Which service should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Table Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Database for PostgreSQL Flexible Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Service Bus<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cosmos DB<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Database for PostgreSQL Flexible Server provides managed PostgreSQL database capabilities and supports high availability configurations for supported workloads. High availability can provide a standby server and automatic failover when the primary instance experiences an eligible failure. This reduces the operational effort required to build and maintain database redundancy. Table Storage is a NoSQL key-value service, Service Bus provides messaging, and Cosmos DB is a globally distributed NoSQL database. Architects should evaluate zone placement, backup requirements, recovery objectives, application connection behavior, performance, and regional availability before selecting the database configuration.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>A company needs to execute a containerized batch job for a short period without managing a Kubernetes cluster. Which Azure service is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Kubernetes Service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Container Registry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Container Instances<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure App Configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Container Instances provides a simple way to run containers without requiring organizations to manage virtual machines or a Kubernetes cluster. It is suitable for short-lived workloads, development tasks, batch processing, and burst scenarios where full container orchestration is unnecessary. Azure Kubernetes Service is appropriate when advanced orchestration is required, while Container Registry stores container images and App Configuration manages application settings. Architects should evaluate startup requirements, networking, storage, workload duration, scaling needs, and orchestration complexity before selecting Container Instances for a containerized workload.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>A company needs to store large amounts of analytics data using a hierarchical namespace and access controls similar to a file system. Which Azure service should be selected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Data Lake Storage Gen2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cache for Redis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Data Lake Storage Gen2 provides scalable object storage with a hierarchical namespace designed for analytics workloads. It supports directory structures and access control lists that allow organizations to manage permissions at directory and file levels. ADLS Gen2 is commonly used with services such as Azure Synapse Analytics, Azure Databricks, and Azure Data Factory. Queue Storage is intended for asynchronous messaging, Redis provides in-memory caching, and Azure Files provides managed file shares. Architects should plan directory structures, ACLs, identity integration, storage tiers, lifecycle policies, and workload access patterns.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which Azure service is designed to provide global edge delivery and caching for static and dynamic web content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure NetApp Files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Event Hubs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Front Door provides global application delivery capabilities and can use Microsoft&#8217;s edge network to improve application performance for geographically distributed users. Depending on the configuration, Front Door can provide caching, traffic routing, health-based failover, TLS termination, and Web Application Firewall integration. Azure SQL Database provides relational database services, NetApp Files provides high-performance file storage, and Event Hubs provides event ingestion. Architects should evaluate caching requirements, cache invalidation, routing rules, backend health, security policies, and regional architecture when using Front Door for global applications.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>An organization wants to separate Azure subscriptions by development, testing, and production while applying common governance policies to all of them. Which design is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Place all workloads in one resource group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use management groups above the subscriptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create a separate tenant for every environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use one storage account for every environment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management groups provide a hierarchy above Azure subscriptions, making them suitable for applying common governance controls across multiple subscriptions. An organization can create separate subscriptions for development, testing, and production and organize them under an appropriate management group hierarchy. Policies and role assignments can then be applied at the management group level and inherited by child subscriptions. Resource groups organize resources within subscriptions, while separate tenants are generally unnecessary for normal environment separation. Architects should design subscription boundaries around governance, billing, security, ownership, and operational requirements.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which Azure feature is most useful for identifying unused resources and opportunities to reduce Azure spending?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Advisor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Event Grid<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Advisor analyzes Azure resources and provides recommendations across areas such as cost, security, reliability, operational excellence, and performance efficiency. Cost recommendations can identify opportunities such as underutilized virtual machines or other resources that may be resized, stopped, or removed. Bastion provides secure VM access, Event Grid routes events, and DNS provides name resolution. Architects should review Advisor recommendations alongside actual workload requirements, business constraints, and performance measurements before implementing changes. Cost optimization should avoid reducing resources in ways that compromise availability or application performance.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>A company wants a centralized solution for routing API requests, applying policies, and providing developer-facing API management capabilities. Which Azure service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure API Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Data Box<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure API Management provides a managed platform for publishing, securing, transforming, monitoring, and governing APIs. It can act as an API gateway between clients and backend services and supports policies for capabilities such as authentication, rate limiting, transformation, and traffic control. API Management can also provide developer portal functionality depending on the configuration and tier. Storage provides data storage, Load Balancer distributes network traffic, and Data Box supports physical data transfer. Architects should evaluate networking, authentication, backend integration, scalability, API lifecycle management, and required API gateway features.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>An organization wants to enforce a rule that all storage accounts must use secure transfer. Which Azure governance mechanism should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cache for Redis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy can enforce configuration requirements such as requiring secure transfer for supported storage accounts. A policy can audit existing resources or deny deployments that do not meet the defined security requirement. Secure transfer helps ensure that requests to storage services use encrypted connections such as HTTPS. Bastion provides secure VM administration, Traffic Manager performs DNS-based routing, and Redis provides caching. Architects should combine Policy with identity controls, encryption, network restrictions, monitoring, and logging to create a comprehensive storage security architecture rather than depending on a single governance control.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>A company needs a database that can distribute data globally and support multiple consistency models. Which Azure service is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Managed Instance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Database for MySQL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cosmos DB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Cosmos DB is a globally distributed database service designed for applications requiring low-latency access across geographic regions. It supports multiple consistency models, allowing architects to balance consistency, latency, and availability according to application requirements. Cosmos DB also supports automatic global distribution and can be configured for multi-region writes in suitable architectures. SQL Managed Instance and MySQL provide relational database capabilities, while Azure Files provides file storage. Architects should carefully select partition keys, consistency levels, throughput configuration, regional distribution, and conflict-handling strategies when designing a Cosmos DB solution.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>A workload has unpredictable traffic and must automatically add or remove compute instances based on demand. Which Azure capability should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Autoscale<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Data Box<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Autoscale allows supported services to automatically adjust capacity based on workload demand or predefined schedules. This can help maintain application performance during periods of increased traffic while reducing resource consumption during periods of lower demand. Autoscale can be used with services such as App Service and Virtual Machine Scale Sets, depending on the workload architecture. Resource Locks protect resources, Key Vault manages secrets and keys, and Data Box supports large-scale physical data transfer. Architects should define appropriate scaling metrics, minimum and maximum capacity, cooldown periods, and application performance thresholds.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which disaster recovery service can replicate Azure virtual machines to another Azure region and support failover during a regional outage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Site Recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure App Configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Site Recovery provides disaster recovery capabilities for supported workloads by orchestrating replication and failover to a secondary location. For Azure virtual machines, it can replicate workloads to another Azure region and support planned or unplanned failover scenarios. Recovery plans can also coordinate the startup sequence of dependent workloads. Resource Graph is used for querying resource information, App Configuration manages application settings, and CDN provides content delivery. Architects should define recovery objectives, replication policies, network mappings, dependencies, test failover procedures, and post-failover operations before implementing Site Recovery.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>A company needs a storage solution that provides managed SMB file shares accessible by multiple Windows and Linux clients. Which Azure service should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Blob Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Event Hubs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Files provides fully managed cloud file shares that can be accessed using protocols such as SMB and, for supported configurations, NFS. Azure Files can be used when applications or users require shared file-system semantics rather than object storage. Blob Storage is optimized for object data, Event Hubs handles high-throughput event ingestion, and Queue Storage supports asynchronous messaging. Architects should consider authentication, network access, performance tier, redundancy, quotas, backup, and protocol requirements when designing an Azure Files solution for shared application or user data.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>A company wants to protect an application from a volumetric distributed denial-of-service attack while keeping normal application traffic available. Which Azure service should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Advisor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Data Factory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DDoS Protection provides capabilities designed to help protect Azure resources from distributed denial-of-service attacks. It uses Azure&#8217;s network infrastructure and attack detection mechanisms to help distinguish malicious traffic from normal traffic and can provide enhanced protection and visibility compared with basic platform-level protection. Advisor provides recommendations, Policy manages governance, and Data Factory provides data integration. Architects should combine DDoS protection with other controls such as WAF, network segmentation, secure authentication, monitoring, and appropriate application architecture to create layered protection against both network-level and application-level threats.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>A business-critical application must continue operating even if an entire Azure region becomes unavailable. Which architecture should the solution prioritize?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-region deployment with backups only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multi-region deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single availability zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single virtual machine<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A multi-region architecture provides protection against a complete Azure region failure by deploying application components and required data across geographically separate regions. Traffic can be redirected to a healthy region using services such as Azure Front Door or Traffic Manager, depending on the application architecture. The exact design depends on whether the application uses active-active or active-passive deployment and how data replication is handled. A single region, availability zone, or VM cannot provide equivalent regional resilience. Architects should define RTO, RPO, data residency, failover, cost, and operational requirements.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-305 Exam Dumps and Practice Test Dumps &nbsp; Question 361 A company needs to connect an on-premises network to Azure using a dedicated private connection that does not traverse the public internet. Which service should the architect recommend? Azure Traffic Manager Azure VPN Gateway ExpressRoute Azure CDN Correct Answer: 3 Explanation Azure [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12224"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12224"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12224\/revisions"}],"predecessor-version":[{"id":12227,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12224\/revisions\/12227"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}