Microsoft AZ-900 Azure Regions Zones Datacenters Resources Subscriptions And Management Groups Practice Test

 

Skill 2.1 • 45 original questions

This Microsoft AZ-900 practice test focuses on azure regions zones datacenters resources subscriptions and management groups through original foundational scenarios aligned to the skills measured as of July 20, 2026. The complete ExamSnap AZ-900 collection covers cloud concepts, Azure architecture and services, and Azure management and governance. For broader exam preparation, review the Microsoft AZ-900 Exam Dumps page.

Instructions: Select the best answer for each question unless the stem says Select TWO. Review the explanation after answering; every option includes a reason it is or is not the best fit for that scenario.

Question 1

Adventure Works is reviewing a production configuration. The governance team must identify the feature or practice that best addresses this need: describe azure regions region pairs and sovereign regions. Which choice most directly satisfies the requirement while trying to keep the design manageable at scale? The team will validate the decision with operational evidence after rollout.

  1. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  2. Zero Trust assumes breach and requires explicit verification, least-privilege access, and continuous evaluation rather than trusting based on network location alone
  3. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  4. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  5. Microsoft Entra ID provides cloud identity and access management; Microsoft Entra Domain Services supplies managed domain capabilities such as domain join, LDAP, Kerberos, and NTLM for compatible workloads

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Zero Trust. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra ID and Microsoft Entra Domain Services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Question 2

A change request at Adventure Works has one non-negotiable requirement: identify the feature or practice that best addresses this need: describe availability zones. What should the finance team choose if the priority is to preserve least privilege? The implementation should avoid adding a control that does not address the stated constraint.

  1. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  2. Azure VMs typically depend on compute sizing, disks, networking such as NICs and virtual networks, and optionally public IP or load-balancing resources
  3. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  4. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  5. Virtual machines provide OS-level control, containers package applications with lightweight isolation, and functions provide event-driven serverless execution

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe resources required for virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Compare containers virtual machines and functions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Question 3

A change request at Fourth Coffee has one non-negotiable requirement: identify the feature or practice that best addresses this need: describe azure datacenters. What should the application team choose if the priority is to reduce user disruption? The team will validate the decision with operational evidence after rollout.

  1. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  2. Azure Migrate assesses and migrates servers, databases, and workloads, while Azure Data Box supports large offline or appliance-assisted data transfer
  3. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods
  4. Use individual VMs for server workloads, VM Scale Sets for managed groups of similar VMs, availability sets for fault/update domain distribution, and Azure Virtual Desktop for managed virtual desktops and apps
  5. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe migration options including Azure Migrate and Azure Data Box. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual machine options including VMs VM Scale Sets availability sets and Azure Virtual Desktop. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Question 4

A change request at Woodgrove Bank has one non-negotiable requirement: choose the most accurate administrative approach for this requirement: describe azure resources and resource groups. What should the governance team choose if the priority is to support repeatable administration? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  2. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  3. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  4. Defender for Cloud provides cloud security posture management and workload protection capabilities to assess risk, recommend improvements, and help protect cloud resources
  5. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Defender for Cloud. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Question 5

During an implementation review at Woodgrove Bank, the security team needs to select an implementation consistent with this objective: describe subscriptions. Which approach is the strongest fit when the organization also wants to apply the narrowest effective control? The team will validate the decision with operational evidence after rollout.

  1. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  2. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions
  3. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities
  4. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  5. An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement.

Learning point: An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Question 6

During an implementation review at Tailspin Toys, the security team needs to choose the most accurate administrative approach for this requirement: describe management groups. Which approach is the strongest fit when the organization also wants to support repeatable administration? The team will validate the decision with operational evidence after rollout.

  1. Use individual VMs for server workloads, VM Scale Sets for managed groups of similar VMs, availability sets for fault/update domain distribution, and Azure Virtual Desktop for managed virtual desktops and apps
  2. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity
  3. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  4. Use AzCopy for command-line data transfer, Storage Explorer for graphical storage management, and Azure File Sync to cache and synchronize Azure file shares with Windows Servers
  5. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual machine options including VMs VM Scale Sets availability sets and Azure Virtual Desktop. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Identify file movement options including AzCopy Storage Explorer and Azure File Sync. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Learning point: Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Question 7

A change request at Woodgrove Bank has one non-negotiable requirement: choose the most accurate administrative approach for this requirement: describe hierarchy of resource groups subscriptions and management groups. What should the security team choose if the priority is to minimize operational overhead? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Virtual machines provide OS-level control, containers package applications with lightweight isolation, and functions provide event-driven serverless execution
  2. Defender for Cloud provides cloud security posture management and workload protection capabilities to assess risk, recommend improvements, and help protect cloud resources
  3. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  4. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  5. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Compare containers virtual machines and functions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Defender for Cloud. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Question 8

Fabrikam is reviewing a production configuration. The governance team must choose the most accurate administrative approach for this requirement: describe azure regions region pairs and sovereign regions. Which choice most directly satisfies the requirement while trying to keep the design manageable at scale? The team will validate the decision with operational evidence after rollout.

  1. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  2. Zero Trust assumes breach and requires explicit verification, least-privilege access, and continuous evaluation rather than trusting based on network location alone
  3. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  4. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required
  5. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Zero Trust. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Question 9

The governance team at Adventure Works is comparing implementation options. They must select an implementation consistent with this objective: describe availability zones. Which option best matches the requirement and the goal to minimize operational overhead? The choice must be defensible in a security and governance review.

  1. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods
  2. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  3. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  4. Zero Trust assumes breach and requires explicit verification, least-privilege access, and continuous evaluation rather than trusting based on network location alone
  5. Microsoft Entra External ID capabilities support collaboration or customer identities for people outside the primary workforce directory

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Zero Trust. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe external identities. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Question 10

An administration ticket for Northwind Traders states: select an implementation consistent with this objective: describe azure datacenters. Which decision should the cloud adoption team make to improve auditability? The choice must be defensible in a security and governance review.

  1. Azure VMs typically depend on compute sizing, disks, networking such as NICs and virtual networks, and optionally public IP or load-balancing resources
  2. Zero Trust assumes breach and requires explicit verification, least-privilege access, and continuous evaluation rather than trusting based on network location alone
  3. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  4. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required
  5. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe resources required for virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Zero Trust. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Question 11

A change request at Proseware has one non-negotiable requirement: make a decision that correctly reflects this requirement: describe azure resources and resource groups. What should the cloud adoption team choose if the priority is to reduce security risk? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  2. Virtual machines provide OS-level control, containers package applications with lightweight isolation, and functions provide event-driven serverless execution
  3. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity
  4. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  5. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Compare containers virtual machines and functions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement.

Learning point: A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Question 12

A change request at Proseware has one non-negotiable requirement: identify the feature or practice that best addresses this need: describe subscriptions. What should the IT operations team choose if the priority is to keep the design manageable at scale? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities
  2. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs
  3. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  4. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  5. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Question 13

Proseware is reviewing a production configuration. The security team must identify the feature or practice that best addresses this need: describe management groups. Which choice most directly satisfies the requirement while trying to reduce security risk? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Use individual VMs for server workloads, VM Scale Sets for managed groups of similar VMs, availability sets for fault/update domain distribution, and Azure Virtual Desktop for managed virtual desktops and apps
  2. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity
  3. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions
  4. Microsoft Entra ID provides cloud identity and access management; Microsoft Entra Domain Services supplies managed domain capabilities such as domain join, LDAP, Kerberos, and NTLM for compatible workloads
  5. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual machine options including VMs VM Scale Sets availability sets and Azure Virtual Desktop. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra ID and Microsoft Entra Domain Services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Question 14

A change request at Woodgrove Bank has one non-negotiable requirement: select an implementation consistent with this objective: describe hierarchy of resource groups subscriptions and management groups. What should the governance team choose if the priority is to meet the stated compliance requirement? The team will validate the decision with operational evidence after rollout.

  1. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  2. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  3. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  4. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods
  5. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Question 15

For an upcoming rollout at Tailspin Toys, the security team needs to select an implementation consistent with this objective: describe azure regions region pairs and sovereign regions. Which response is most appropriate if the solution should also meet the stated compliance requirement? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  2. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  3. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  4. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  5. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Learning point: Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Question 16

For an upcoming rollout at Fabrikam, the IT operations team needs to make a decision that correctly reflects this requirement: describe availability zones. Which response is most appropriate if the solution should also avoid unnecessary complexity? The team will validate the decision with operational evidence after rollout.

  1. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  2. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  3. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  4. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  5. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Question 17

Tailspin Toys is reviewing a production configuration. The finance team must select an implementation consistent with this objective: describe azure datacenters. Which choice most directly satisfies the requirement while trying to reduce user disruption? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs
  2. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required
  3. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  4. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  5. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Question 18

Tailspin Toys is reviewing a production configuration. The finance team must make a decision that correctly reflects this requirement: describe azure resources and resource groups. Which choice most directly satisfies the requirement while trying to reduce user disruption? The team will validate the decision with operational evidence after rollout.

  1. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  2. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  3. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions
  4. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs
  5. An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Question 19

A change request at Adventure Works has one non-negotiable requirement: identify the feature or practice that best addresses this need: describe subscriptions. What should the finance team choose if the priority is to avoid unnecessary complexity? The implementation should avoid adding a control that does not address the stated constraint.

  1. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  2. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  3. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  4. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  5. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Question 20

For an upcoming rollout at Contoso, the application team needs to select an implementation consistent with this objective: describe management groups. Which response is most appropriate if the solution should also support repeatable administration? The implementation should avoid adding a control that does not address the stated constraint.

  1. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions
  2. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  3. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  4. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities
  5. Defender for Cloud provides cloud security posture management and workload protection capabilities to assess risk, recommend improvements, and help protect cloud resources

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Defender for Cloud. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Question 21

During an implementation review at Litware, the finance team needs to make a decision that correctly reflects this requirement: describe hierarchy of resource groups subscriptions and management groups. Which approach is the strongest fit when the organization also wants to support repeatable administration? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  2. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  3. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  4. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  5. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement.

Learning point: Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Question 22

The cloud adoption team at Contoso is comparing implementation options. They must identify the feature or practice that best addresses this need: describe azure regions region pairs and sovereign regions. Which option best matches the requirement and the goal to improve auditability? The team will validate the decision with operational evidence after rollout.

  1. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  2. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  3. Use AzCopy for command-line data transfer, Storage Explorer for graphical storage management, and Azure File Sync to cache and synchronize Azure file shares with Windows Servers
  4. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required
  5. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Identify file movement options including AzCopy Storage Explorer and Azure File Sync. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Question 23

During an implementation review at Fabrikam, the cloud adoption team needs to make a decision that correctly reflects this requirement: describe availability zones. Which approach is the strongest fit when the organization also wants to improve auditability? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Azure VMs typically depend on compute sizing, disks, networking such as NICs and virtual networks, and optionally public IP or load-balancing resources
  2. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions
  3. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities
  4. Microsoft Entra External ID capabilities support collaboration or customer identities for people outside the primary workforce directory
  5. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe resources required for virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe external identities. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Learning point: Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Question 24

A change request at Litware has one non-negotiable requirement: select an implementation consistent with this objective: describe azure datacenters. What should the application team choose if the priority is to avoid unnecessary complexity? The choice must be defensible in a security and governance review.

  1. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities
  2. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  3. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  4. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity
  5. Azure Migrate assesses and migrates servers, databases, and workloads, while Azure Data Box supports large offline or appliance-assisted data transfer

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe migration options including Azure Migrate and Azure Data Box. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Question 25

During an implementation review at Trey Research, the application team needs to select an implementation consistent with this objective: describe azure resources and resource groups. Which approach is the strongest fit when the organization also wants to reduce user disruption? The team will validate the decision with operational evidence after rollout.

  1. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  2. Microsoft Entra ID provides cloud identity and access management; Microsoft Entra Domain Services supplies managed domain capabilities such as domain join, LDAP, Kerberos, and NTLM for compatible workloads
  3. Use individual VMs for server workloads, VM Scale Sets for managed groups of similar VMs, availability sets for fault/update domain distribution, and Azure Virtual Desktop for managed virtual desktops and apps
  4. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  5. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra ID and Microsoft Entra Domain Services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual machine options including VMs VM Scale Sets availability sets and Azure Virtual Desktop. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Question 26

A change request at Woodgrove Bank has one non-negotiable requirement: select an implementation consistent with this objective: describe subscriptions. What should the IT operations team choose if the priority is to keep the design manageable at scale? The choice must be defensible in a security and governance review.

  1. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  2. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  3. Azure Migrate assesses and migrates servers, databases, and workloads, while Azure Data Box supports large offline or appliance-assisted data transfer
  4. Azure virtual networks provide private IP networking with subnets; peering connects VNets, Azure DNS resolves names, VPN Gateway provides encrypted VPN connectivity, and ExpressRoute provides private dedicated connectivity
  5. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Describe migration options including Azure Migrate and Azure Data Box. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual networking and components. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Question 27

The cloud adoption team at Adventure Works is comparing implementation options. They must identify the feature or practice that best addresses this need: describe management groups. Which option best matches the requirement and the goal to reduce security risk? The choice must be defensible in a security and governance review.

  1. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  2. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  3. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions
  4. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  5. Azure VMs typically depend on compute sizing, disks, networking such as NICs and virtual networks, and optionally public IP or load-balancing resources

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe resources required for virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Question 28

An administration ticket for Trey Research states: identify the feature or practice that best addresses this need: describe hierarchy of resource groups subscriptions and management groups. Which decision should the cloud adoption team make to minimize operational overhead? The team will validate the decision with operational evidence after rollout.

  1. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  2. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  3. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  4. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  5. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Question 29

An administration ticket for Woodgrove Bank states: make a decision that correctly reflects this requirement: describe azure regions region pairs and sovereign regions. Which decision should the application team make to improve auditability? The implementation should avoid adding a control that does not address the stated constraint.

  1. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs
  2. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  3. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  4. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  5. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Learning point: Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Question 30

During an implementation review at Proseware, the finance team needs to identify the feature or practice that best addresses this need: describe availability zones. Which approach is the strongest fit when the organization also wants to improve auditability? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  2. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  3. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  4. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  5. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Question 31

Fourth Coffee is reviewing a production configuration. The finance team must make a decision that correctly reflects this requirement: describe azure datacenters. Which choice most directly satisfies the requirement while trying to minimize operational overhead? The team will validate the decision with operational evidence after rollout.

  1. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  2. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities
  3. Zero Trust assumes breach and requires explicit verification, least-privilege access, and continuous evaluation rather than trusting based on network location alone
  4. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  5. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Zero Trust. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Question 32

During an implementation review at Fabrikam, the security team needs to select an implementation consistent with this objective: describe azure resources and resource groups. Which approach is the strongest fit when the organization also wants to reduce user disruption? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  2. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  3. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  4. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  5. Virtual machines provide OS-level control, containers package applications with lightweight isolation, and functions provide event-driven serverless execution

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Compare containers virtual machines and functions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Question 33

During an implementation review at Litware, the cloud adoption team needs to select an implementation consistent with this objective: describe subscriptions. Which approach is the strongest fit when the organization also wants to keep the design manageable at scale? The team will validate the decision with operational evidence after rollout.

  1. Zero Trust assumes breach and requires explicit verification, least-privilege access, and continuous evaluation rather than trusting based on network location alone
  2. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  3. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  4. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  5. Use individual VMs for server workloads, VM Scale Sets for managed groups of similar VMs, availability sets for fault/update domain distribution, and Azure Virtual Desktop for managed virtual desktops and apps

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Zero Trust. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure virtual machine options including VMs VM Scale Sets availability sets and Azure Virtual Desktop. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Question 34

For an upcoming rollout at Woodgrove Bank, the finance team needs to implement the skill described by describe management groups. Which response is most appropriate if the solution should also improve auditability? The team will validate the decision with operational evidence after rollout.

  1. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  2. Microsoft Entra ID provides cloud identity and access management; Microsoft Entra Domain Services supplies managed domain capabilities such as domain join, LDAP, Kerberos, and NTLM for compatible workloads
  3. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  4. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required
  5. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra ID and Microsoft Entra Domain Services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Learning point: Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Question 35

The security team at Proseware is comparing implementation options. They must identify the feature or practice that best addresses this need: describe hierarchy of resource groups subscriptions and management groups. Which option best matches the requirement and the goal to meet the stated compliance requirement? The implementation should avoid adding a control that does not address the stated constraint.

  1. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  2. A public endpoint is reachable through a public IP or public service interface, while a private endpoint exposes a supported Azure service through a private IP in a virtual network
  3. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  4. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities
  5. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Define public and private endpoints. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Question 36

Adventure Works is reviewing a production configuration. The IT operations team must make a decision that correctly reflects this requirement: describe azure regions region pairs and sovereign regions. Which choice most directly satisfies the requirement while trying to keep the design manageable at scale? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  2. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  3. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required
  4. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  5. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Question 37

During an implementation review at Adventure Works, the security team needs to implement the skill described by describe availability zones. Which approach is the strongest fit when the organization also wants to minimize operational overhead? The team will validate the decision with operational evidence after rollout.

  1. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  2. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  3. Choose App Service or another managed web platform for managed application hosting, containers for portable packaged workloads, and VMs when OS-level control is required
  4. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  5. Defender for Cloud provides cloud security posture management and workload protection capabilities to assess risk, recommend improvements, and help protect cloud resources

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Describe application hosting options including web apps containers and virtual machines. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Defender for Cloud. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Question 38

The IT operations team at Fourth Coffee is comparing implementation options. They must select an implementation consistent with this objective: describe azure datacenters. Which option best matches the requirement and the goal to apply the narrowest effective control? The choice must be defensible in a security and governance review.

  1. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  2. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods
  3. A public endpoint is reachable through a public IP or public service interface, while a private endpoint exposes a supported Azure service through a private IP in a virtual network
  4. Use AzCopy for command-line data transfer, Storage Explorer for graphical storage management, and Azure File Sync to cache and synchronize Azure file shares with Windows Servers
  5. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Define public and private endpoints. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Identify file movement options including AzCopy Storage Explorer and Azure File Sync. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Learning point: Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Question 39

A change request at Fourth Coffee has one non-negotiable requirement: identify the feature or practice that best addresses this need: describe azure resources and resource groups. What should the IT operations team choose if the priority is to improve auditability? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. A public endpoint is reachable through a public IP or public service interface, while a private endpoint exposes a supported Azure service through a private IP in a virtual network
  2. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources
  3. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  4. Use AzCopy for command-line data transfer, Storage Explorer for graphical storage management, and Azure File Sync to cache and synchronize Azure file shares with Windows Servers
  5. Microsoft Entra ID provides cloud identity and access management; Microsoft Entra Domain Services supplies managed domain capabilities such as domain join, LDAP, Kerberos, and NTLM for compatible workloads

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Define public and private endpoints. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Identify file movement options including AzCopy Storage Explorer and Azure File Sync. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra ID and Microsoft Entra Domain Services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Question 40

The security team at Proseware is comparing implementation options. They must make a decision that correctly reflects this requirement: describe subscriptions. Which option best matches the requirement and the goal to keep the design manageable at scale? The implementation should avoid adding a control that does not address the stated constraint.

  1. Virtual machines provide OS-level control, containers package applications with lightweight isolation, and functions provide event-driven serverless execution
  2. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs
  3. An Azure subscription is a billing and access-management boundary that contains resource groups and resources
  4. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  5. Storage account configuration determines supported services, performance, redundancy, access tier options, networking, and other storage capabilities

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Compare containers virtual machines and functions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe subscriptions. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe storage account options and storage types. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: An Azure subscription is a billing and access-management boundary that contains resource groups and resources

Question 41

An administration ticket for Contoso states: make a decision that correctly reflects this requirement: describe management groups. Which decision should the IT operations team make to keep the design manageable at scale? The team will validate the decision with operational evidence after rollout.

  1. Defender for Cloud provides cloud security posture management and workload protection capabilities to assess risk, recommend improvements, and help protect cloud resources
  2. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  3. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions
  4. Defense in depth uses multiple independent security layers so failure of one control does not leave the workload unprotected
  5. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Defender for Cloud. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe defense in depth. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Question 42

During an implementation review at Fourth Coffee, the security team needs to select an implementation consistent with this objective: describe hierarchy of resource groups subscriptions and management groups. Which approach is the strongest fit when the organization also wants to preserve least privilege? The implementation should avoid adding a control that does not address the stated constraint.

  1. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  2. A public endpoint is reachable through a public IP or public service interface, while a private endpoint exposes a supported Azure service through a private IP in a virtual network
  3. Microsoft Entra External ID capabilities support collaboration or customer identities for people outside the primary workforce directory
  4. Azure storage access tiers balance access frequency, performance, retrieval characteristics, and cost for hot, cool/cold, and archive-style data
  5. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Define public and private endpoints. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe external identities. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe storage tiers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups

Question 43

An administration ticket for Tailspin Toys states: identify the feature or practice that best addresses this need: describe azure regions region pairs and sovereign regions. Which decision should the application team make to preserve least privilege? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Azure RBAC assigns roles at scopes such as management groups, subscriptions, resource groups, or resources to control which Azure management actions principals can perform
  2. Blob storage is optimized for object data, Azure Files provides managed file shares, queues support messaging, tables provide NoSQL key-value style storage, and managed disks support Azure VMs
  3. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  4. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  5. A resource is a manageable Azure service instance; a resource group is a logical lifecycle and management container for related Azure resources

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe Azure role-based access control RBAC. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Compare Azure Storage services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe Azure resources and resource groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries

Question 44

The security team at Tailspin Toys is comparing implementation options. They must implement the skill described by describe availability zones. Which option best matches the requirement and the goal to apply the narrowest effective control? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures
  2. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  3. Azure regions are geographic areas containing datacenters; region pairs can support resilience planning, while sovereign regions serve specific government or regulatory boundaries
  4. Azure Storage redundancy options replicate data locally, across zones, and optionally to a secondary region to provide different durability and availability characteristics
  5. SSO reduces repeated sign-ins, MFA requires additional authentication factors, and passwordless methods replace passwords with stronger credentials such as passkeys or authenticator-based methods

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe availability zones. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Azure regions region pairs and sovereign regions. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe redundancy options. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe authentication methods including SSO MFA and passwordless. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Availability zones are physically separate datacenter locations within a supported Azure region that can improve resiliency against datacenter-level failures

Question 45

An administration ticket for Northwind Traders states: make a decision that correctly reflects this requirement: describe azure datacenters. Which decision should the application team make to support repeatable administration? The choice must be defensible in a security and governance review.

  1. Resources belong to resource groups, resource groups belong to subscriptions, and subscriptions can be organized under management groups
  2. Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services
  3. Microsoft Entra ID provides cloud identity and access management; Microsoft Entra Domain Services supplies managed domain capabilities such as domain join, LDAP, Kerberos, and NTLM for compatible workloads
  4. Conditional Access evaluates identity, device, location, application, and risk signals to enforce access controls such as MFA or blocking access
  5. Management groups provide a hierarchy above subscriptions for applying governance and access controls across multiple subscriptions

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Describe hierarchy of resource groups subscriptions and management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Describe Azure datacenters. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra ID and Microsoft Entra Domain Services. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Describe Microsoft Entra Conditional Access. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Describe management groups. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Azure datacenters house the physical compute, storage, networking, power, and cooling infrastructure that supports Azure regions and services

Popular posts

img