Microsoft Azure Architect Design: https://docs.microsoft.com/en-us/learn/certifications/exams/az-301

Candidates for this exam are Azure Solution Architects who advise stakeholders and translate business requirements into secure, scalable, and reliable solutions. Candidates should have advanced experience and knowledge across various aspects of IT operations, including networking, virtualization, identity, security, business continuity, disaster recovery, data management, budgeting, and governance. This role requires managing how decisions in each area affect an overall solution. Candidates must be proficient in Azure administration, Azure development, and DevOps, and have expert-level skills in at least one of those domains.

Skills measured

The content of this exam was updated on December 4, 2019. Please download the Skills measured document below to see what changed.

  1. Determine workload requirements (10-15%)
  2. Design for identity and security (20-25%)
  3. Design a data platform solution (15-20%)
  4. Design a business continuity strategy (15-20%)
  5. Design for deployment, migration, and integration (10-15%)
  6. Design an infrastructure strategy (15-20%)

Latest updates Microsoft Azure AZ-301 exam practice questions

You have an on premises Active Directory forest and an Azure Active Directory Azure AD) tenant. All Azure AD users
are assigned a Premium P1 license.
You deploy Azure AD Conned
Which two features ate available m this environment that can reduce operational overhead tot your company\\’s help
desk? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point
A. sell- service password reset
B. access review
C. password writeback
D. Azure AD Privileged Identity Management policies
E. Microsoft Cloud App Security Conditional At access App Control
Correct Answer: AD

You plan to deploy an API by using Azure API Management.
You need to recommend a solution to protect the API from a distributed denial of service (DDoS) attack.
What should you recommend?
A. Create network security groups (NSGs).
B. Enable quotas.
C. Enable rate limiting.
D. Strip the Powered-By responsible header.
Correct Answer: C

You deploy several Azure SQL Database instances.
You plan to configure the Diagnostics settings on the databases as shown in the following exhibit.lead4pass az-301 exam question q3

Use the drop-down menus to select the answer choice that completes each statement based on the information
presented in the graphic. NOTE: Each correct selection is worth one point.
Hot Area:

lead4pass az-301 exam question q3-1

Correct Answer:

lead4pass az-301 exam question q3-2

In the exhibit, the SQLInsights data is configured to be stored in Azure Log Analytics for 90 days.
However, the question is asking for the “maximum” amount of time that the data can be stored which is 730 days.

You need to recommend a data storage strategy for WebApp1. What should you include in in the recommendation?
A. an Azure SQL Database elastic pool
B. a vCore-baswl A/we SQL database
C. an Azure virtual machine that runs SQL Server
D. a fixed-size DTU AzureSQL database.
Correct Answer: B

Your company has 20 web APIs that were developed in-house.
The company is developing 10 web apps that will use the web APIs. The web apps and the APIs are registered in the
company’s Azure Active Directory (Azure AD) tenant. The web APIs are published by using Azure API Management.
You need to recommend a solution to block unauthorized requests originating from the web apps from reaching the web
APIs. The solution must meet the following requirements:
Use Azure AD-generated claims.
Minimize configuration and management effort.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:lead4pass az-301 exam question q5

Correct Answer:

lead4pass az-301 exam question q5-1


You need to recommend a solution for implementing the back-end tier of the payment processing system in Azure.
What should you include in the recommendation?
A. an Azure SQL Database managed instance
B. a SQL Server database on an Azure virtual machine
C. an Azure SQL Database single database
D. an Azure SQL Database elastic pool
Correct Answer: C

You have standard Load balancer configured to support three virtual machines on the same subnet.
You need to recommend a solution to notify administrators when the load balancer fails.
Which metrics should you recommend using to test the load balancer? To answer, drag the appropriate metrics to the
correct conditions. Each metric may be used once, more than once, or not at all. You may need to drag the split bar
between panes or scroll to view content.
NOT: Each correct selection is worth one point.
Select and Place:lead4pass az-301 exam question q7

Correct Answer:

lead4pass az-301 exam question q7-1


You need to recommend a notification solution for the IT Support distribution group. What should you include in the
A. Azure Network Watcher
B. an action group
C. a SendGrid account with advanced reporting
D. Azure AD Connect Health
Correct Answer: D
References: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-healthoperations

You store web access logs data in Azure Blob storage.
You plan to generate monthly reports from the access logs.
You need to recommend an automated process to upload the data to Azure SQL Database every month.
What should you include in the recommendation?
A. Microsoft SQL Server Migration Assistant (SSMA)
B. Azure Data Factory
C. Data Migration Assistant
D. AzCopy
Correct Answer: C

You are designing an Azure solution for a company that wants to move a .NET Core web application an on-premises
data center to Azure. The web application relies on a Microsoft SQL Server 2016 database on Windows Server 2016.
database server will not move to Azure.
A separate networking team is responsible for configuring network permissions.
The company uses Azure ExpressRoute and has an ExpressRoute gateway connected to an Azure virtual network
named VNET1.
You need to recommend a solution for deploying the web application.
Solution: Solution: Deploy the web application by using an Azure Kubernetes Service (AKS) container on VNET1
Does this meet the goal?
A. Yes
B. No
Correct Answer: B

Your company has two on-premises sites in New York and Los Angeles and Azure virtual networks in the East US
Azure region and the West US Azure region. Each on-premises site has Azure ExpressRoute circuits to both regions.
You need to recommend a solution that meets the following requirements:
Outbound traffic to the Internet from workloads hosted on the virtual networks must be routed through the closest
available on-premises site.
If an on-premises site fails, traffic from the workloads on the virtual networks to the Internet must reroute automatically
to the other site.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:lead4pass az-301 exam question q11

Correct Answer:

lead4pass az-301 exam question q11-1


You are designing a data protection strategy for Azure virtual machines. All the virtual machines are in the Standard tier
and use managed disks.
You need to recommend a solution that meets the following requirements:
The use of encryption keys is audited.
All the data is encrypted at rest always.
You manage the encryption keys, not Microsoft.
What should you include in the recommendation?
A. BitLocker Drive Encryption (BitLocker)
B. Azure Storage Service Encryption
C. client-side encryption
D. Azure Disk Encryption
Correct Answer: D
References: https://docs.microsoft.com/en-us/azure/security/azure-security-disk-encryption-overview

You use Azure virtual machines to run a custom application that uses an Azure SQL database on the back end.
The IT apartment at your company recently enabled forced tunneling,
Since the configuration change, developers have noticed degraded performance when they access the database
You need to recommend a solution to minimize latency when accessing the database. The solution must minimize
What should you include in the recommendation? .
A. Azure SQL Database Managed instance
B. Azure virtual machines that run Microsoft SQL Server servers
C. Always On availability groups
D. virtual network service endpoint
Correct Answer: D

