AZ-305 sample questions with answers

10 free practice questions for the Microsoft Certified: Azure Solutions Architect Expert exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Design identity, governance, and monitoring solutions

An auditor requires that nobody who can raise a supplier payment can also approve one. Both capabilities are granted through access packages, and the block must take effect when the second package is requested rather than being found afterwards. What should you recommend?

  1. A.

    Create a quarterly access review of both access packages and ask the reviewers to remove anyone holding both

  2. B.

    Require two-stage approval on both access packages so that a second approver notices the conflict before granting access

  3. C.

    Add a Conditional Access policy that blocks sign-in to the payments application when the user is a member of both groups

  4. D.

    Configure the two access packages as incompatible with each other in entitlement management, so a request is blocked while the user holds the other

Show answer

Answer: D

Entitlement management can mark access packages as incompatible, which prevents the request at the point of request rather than detecting the conflict later.

  • A. A quarterly review detects the conflict after the fact and relies on reviewers correlating two packages themselves.
  • B. Two-stage approval adds another human judgement and still depends on the approver knowing what else the requester holds.
  • C. Conditional Access blocks a sign-in rather than the entitlement, leaving the conflicting access assigned and other systems unaffected.
  • D. Incompatible access packages are checked during the request, so the conflicting combination is never granted in the first place.
Question 2Design identity, governance, and monitoring solutions

An intranet application uses Integrated Windows Authentication and expects a Kerberos ticket. It must be published to remote employees, who should be prompted by Microsoft Entra ID once and then reach the application without a second credential prompt. What should you recommend?

  1. A.

    Federate the application with Active Directory Federation Services and publish the federation service through a web application proxy in the perimeter network

  2. B.

    Publish the application through application proxy and configure Integrated Windows Authentication single sign-on using Kerberos constrained delegation for the connector's computer account

  3. C.

    Publish the application through application proxy with the single sign-on mode set to password-based, storing each user's Active Directory credentials in the enterprise application

  4. D.

    Publish the application through application proxy with pre-authentication disabled, so that the application performs its own Windows authentication against the client

Show answer

Answer: B

Kerberos constrained delegation lets the connector obtain a ticket on the user's behalf, so a Windows-authenticated application accepts the session without a second prompt.

  • A. Federation needs an application that understands claims and reintroduces the perimeter federation infrastructure the design is trying to avoid.
  • B. Constrained delegation lets the connector obtain a Kerberos ticket for the authenticated user, so the Windows-authenticated application accepts the session silently.
  • C. Password-based single sign-on replays stored credentials into a form and is not how an Integrated Windows Authentication application is satisfied.
  • D. Passthrough pre-authentication removes Microsoft Entra evaluation entirely, losing Conditional Access and exposing the application unauthenticated.
Question 3Design identity, governance, and monitoring solutions

A defence contractor runs eight Log Analytics workspaces that together ingest about 2 TB per day. A security policy requires that the log data at rest is encrypted with a key the contractor generates and can revoke, and that the pooled daily volume earns a single volume discount. Which two components should you include in the recommendation? (Choose TWO.)

Choose 2.

  1. A.

    An Azure Monitor Private Link Scope that associates the eight workspaces with the contractor's virtual network

  2. B.

    A customer-managed key configured on the dedicated cluster and held in an Azure Key Vault that has soft delete and purge protection enabled

  3. C.

    A Log Analytics dedicated cluster with the eight workspaces linked to it

  4. D.

    The Basic table plan applied to every table in each of the eight workspaces so that stored data is billed at a lower rate

  5. E.

    A customer-managed key configured separately on each of the eight workspaces from the workspace Encryption pane

Show answer

Answer: B, C

A dedicated cluster is the only object that both pools workspace volume for one commitment and carries a customer-managed key for the data at rest.

  • A. A Private Link Scope secures the network path for ingestion and query; it does not encrypt data at rest or pool billing volume.
  • B. The customer-managed key lives in Key Vault with soft delete and purge protection and is bound to the cluster identity, giving the contractor generation and revocation control.
  • C. A dedicated cluster pools the linked workspaces' ingestion into one commitment tier and is the object that customer-managed keys attach to.
  • D. The Basic plan changes ingestion price and query capability; it has nothing to do with encryption keys or with pooling volume.
  • E. Customer-managed keys are configured at the dedicated cluster, not per workspace, so this configuration does not exist.
Question 4Design identity, governance, and monitoring solutions

An audit finds 18 permanent Owner assignments on production subscriptions. Nobody may hold Owner permanently, each elevation must be approved by a named manager and justified, and an elevation must expire automatically after at most four hours. Which two should you include in the recommendation? (Choose TWO.)

Choose 2.

  1. A.

    Replace the Owner assignments with Contributor assignments that remain permanently active on each subscription

  2. B.

    Create a quarterly Microsoft Entra access review of the Owner assignments so that reviewers recertify each of the 18 holders

  3. C.

    Apply a CanNotDelete resource lock to each production subscription's resource groups to limit the damage an Owner can do

  4. D.

    In the Privileged Identity Management role settings for Owner, require approval and set the maximum activation duration to four hours

  5. E.

    Convert the 18 Owner assignments to eligible assignments in Microsoft Entra Privileged Identity Management

Show answer

Answer: D, E

Eligibility removes the standing assignment and the role settings impose approval, justification and a four-hour maximum activation.

  • A. A permanent Contributor assignment is still standing privilege and does not provide the Owner capability the holders need.
  • B. Access reviews recertify who should be entitled but leave standing privilege in place between reviews.
  • C. Resource locks reduce accidental deletion; they have no bearing on who holds a role or for how long.
  • D. The role settings are where approval, justification and the maximum four-hour activation duration are configured.
  • E. Eligible assignments confer no permission until activated, which eliminates the permanent Owner holdings the audit found.
Question 5Design identity, governance, and monitoring solutions

Fourth Coffee engages about 900 external consultants who need access to specific Azure resources and Microsoft 365 groups. A business owner must approve each request, access must expire automatically after 90 days unless it is extended, and the compliance team must recertify the external accounts that remain every quarter. Which two features should you include in the identity governance recommendation? (Choose TWO.)

Choose 2.

  1. A.

    Dynamic security groups populated from the department attribute

  2. B.

    Microsoft Entra entitlement management access packages with an expiring assignment policy and approval workflow

  3. C.

    Microsoft Entra Domain Services deployed into the consultants' virtual network

  4. D.

    Microsoft Entra access reviews scoped to the guest users of the tenant

  5. E.

    A Conditional Access policy that requires multifactor authentication for guests

  6. F.

    An Azure Policy assignment that denies the creation of guest accounts

Show answer

Answer: B, D

Access packages deliver approved, time-limited bundles of access to external users, and access reviews perform the quarterly recertification of the guests who remain.

  • A. Dynamic group rules rely on directory attributes that guests usually lack and offer neither approval nor automatic expiry.
  • B. Access packages provide requestable bundles with approval workflows and expiring assignments, which satisfies both the approval and the 90-day lifetime.
  • C. Entra Domain Services provides legacy Kerberos and LDAP authentication for lift-and-shift workloads and has no governance features.
  • D. Access reviews recertify guest access on a recurring schedule and remove access that reviewers do not approve, meeting the quarterly requirement.
  • E. Conditional Access strengthens authentication for a session but grants no access, approves nothing, and cannot expire an assignment.
  • F. Blocking guest creation would prevent the consultants from being onboarded at all, and Azure Policy does not govern directory objects.
Question 6Design identity, governance, and monitoring solutions

Two companies have merged and will keep both Microsoft Entra tenants for at least three years. Staff from each tenant must appear in the other so that they can be added to teams and assigned applications, and a leaver in the home tenant must lose access in both. Which two components should you include? (Choose TWO.)

Choose 2.

  1. A.

    Microsoft Entra Connect Sync installed in one tenant and configured to read the other tenant's directory

  2. B.

    An access package in entitlement management that each employee of the other company requests individually

  3. C.

    Cross-tenant access settings that establish an organizational relationship and trust the partner tenant's multifactor authentication claims

  4. D.

    Cross-tenant synchronization configured in each direction between the two tenants

  5. E.

    A full tenant-to-tenant migration that consolidates all users into one of the two tenants within 90 days

Show answer

Answer: C, D

Cross-tenant synchronization populates each tenant with the other's staff automatically, and cross-tenant access settings define the trust relationship that makes those guest identities usable without re-registering multifactor authentication.

  • A. Microsoft Entra Connect Sync synchronises from Active Directory; it cannot read another Microsoft Entra tenant as a source.
  • B. Individual access package requests do not scale to two entire workforces and leave no automatic de-provisioning path from the home tenant.
  • C. Cross-tenant access settings define the organizational relationship and let each tenant trust the partner's multifactor authentication claims, avoiding duplicate registration.
  • D. Cross-tenant synchronization automatically provisions and de-provisions the partner's staff as B2B users, which also satisfies the leaver requirement.
  • E. The scenario states both tenants persist for at least three years, so a consolidation is explicitly out of scope.
Question 7Design identity, governance, and monitoring solutions

A managed service provider operates Azure estates for 40 customers, each in its own Microsoft Entra tenant. Its engineers must work in customer subscriptions from the provider's own tenant, without holding an account in any customer tenant and without switching directories. What should you recommend?

  1. A.

    A service principal in each customer tenant, whose client secret the engineers retrieve on demand from the provider's key vault

  2. B.

    Azure Lighthouse, onboarding each customer subscription so that the provider's own groups receive role assignments there

  3. C.

    A management group in the provider's tenant containing each customer's subscription, with Contributor assigned once

  4. D.

    A guest account for every engineer in every customer tenant, with Azure roles assigned to those guest accounts

Show answer

Answer: B

Azure Lighthouse projects role assignments from a customer's subscription onto identities in the provider's tenant, which is the only design that avoids customer accounts and directory switching.

  • A. Shared service principal secrets remove individual attribution and create 40 credentials that must be rotated and protected.
  • B. Lighthouse grants provider-tenant principals roles over customer scopes, with no customer accounts, no directory switching and full attribution in the customer's activity log.
  • C. A management group hierarchy cannot span Microsoft Entra tenants, so customer subscriptions cannot be placed under the provider's management group.
  • D. Guest accounts put an object for every engineer in every customer tenant and force directory switching, which the requirement forbids.
Question 8Design identity, governance, and monitoring solutions

A clearing house must keep the audit category of its key vault and Azure SQL platform logs for ten years. A regulator requires that nobody, not even a subscription owner, can alter or delete a record before the ten years elapse. Cost must be kept as low as possible. What should you recommend?

  1. A.

    A data export rule that writes the audit logs to a storage account that is protected by a CanNotDelete resource lock

  2. B.

    A diagnostic setting that sends the audit logs to a general-purpose v2 storage account that has a locked time-based immutability policy

  3. C.

    A diagnostic setting that sends the audit logs to a Log Analytics workspace that has total retention set to ten years and a CanNotDelete resource lock on the workspace

  4. D.

    A diagnostic setting that sends the audit logs to an Event Hubs namespace whose message retention period is set to the maximum value

Show answer

Answer: B

Only immutable blob storage with a locked time-based retention policy makes the records unalterable by anyone, including the subscription owner, and it is the cheapest of the four destinations.

  • A. A CanNotDelete lock is a control-plane guard that a privileged user can remove, and it does not prevent data-plane overwrites of the blobs.
  • B. A locked time-based immutability policy places the blobs in WORM state so that no identity can alter or delete them before the interval expires, and blob storage is the lowest-cost destination.
  • C. A workspace has no write-once mode and a resource lock can be removed by an Owner, so the records are not tamper-proof.
  • D. Event Hubs retention is a short-lived streaming buffer measured in days; it is not an archive.
Question 9Design identity, governance, and monitoring solutions

Remote engineers at Tailspin Toys must reach on-premises servers over RDP and SSH and open internal file shares over SMB. The company is retiring its virtual private network, wants Conditional Access to apply to each of those connections, and will not open inbound ports on the datacentre firewall. What should you recommend?

  1. A.

    Microsoft Entra application proxy, publishing each server through its own enterprise application

  2. B.

    An Azure point-to-site VPN gateway that the engineers connect to before reaching the datacentre

  3. C.

    Microsoft Entra Private Access, with the Global Secure Access client installed on the engineers' devices

  4. D.

    Azure Bastion deployed in a hub virtual network that is peered to the on-premises network

Show answer

Answer: C

Private Access tunnels arbitrary TCP and UDP protocols to private resources through outbound-only connectors, with Conditional Access applied per application.

  • A. Application proxy publishes HTTP and HTTPS applications only and cannot carry RDP, SSH or SMB.
  • B. A point-to-site VPN reproduces the flat network access the company is retiring and cannot apply Conditional Access per resource.
  • C. Private Access tunnels any TCP or UDP protocol to private resources through outbound-only connectors and applies Conditional Access per application.
  • D. Azure Bastion reaches Azure virtual machines inside a virtual network; on-premises networks are connected by VPN or ExpressRoute, not peering.
Question 10Design identity, governance, and monitoring solutions

After a credential-phishing incident, Woodgrove Bank requires that anyone activating a privileged Azure or Microsoft Entra role authenticates with a phishing-resistant method. Push notifications and one-time codes must no longer be accepted for those activations. What should you recommend?

  1. A.

    A Microsoft Entra Password Protection policy with a custom banned password list covering the bank's brand terms

  2. B.

    A per-user multifactor authentication enforcement state of Enforced applied to every account that holds a privileged role

  3. C.

    A Conditional Access policy with the Require multifactor authentication grant control selected for all privileged role administrators

  4. D.

    A Conditional Access policy that grants access only when the phishing-resistant multifactor authentication strength is satisfied

Show answer

Answer: D

Authentication strengths let a Conditional Access policy demand a specific set of methods, which is the only way to require phishing-resistant factors and exclude push and one-time codes.

  • A. Password Protection improves password quality; it has no effect on which authentication factors a privileged sign-in must use.
  • B. Legacy per-user multifactor authentication cannot specify which methods are acceptable and cannot be scoped to a role activation.
  • C. The generic multifactor grant control accepts any permitted second factor, including the push notifications and one-time codes the bank has banned.
  • D. An authentication strength names the exact methods that satisfy the policy, so phishing-resistant factors can be required and push or one-time codes excluded.

Keep going with 526 more AZ-305 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.