AZ-305 Practice Exam: Azure Solutions Architect Expert
Design Azure solutions end to end: governance, storage, DR, and infrastructure that survives reality.
What you'll be tested on
- Identity and Governance
- Data Storage
- Business Continuity
- Infrastructure
Sample AZ-305 questions
You have an Azure subscription that contains a custom application named Application1. Application1 was developed by an external company named Fabrikam, Ltd. Developers at Fabrikam were assigned role-based access control (RBAC) permissions to the Application1 components. All users are licensed for the Microsoft 365 E5 plan. You need to recommend a solution to verify whether the Fabrikam developers still require permissions to Application1. The solution must meet the following requirements: ✑ To the manager of the developers, send a monthly email message that lists the access permissions to Application1. ✑ If the manager does not verify an access permission, automatically revoke that permission. ✑ Minimize development effort. What should you recommend?
- In Azure Active Directory (Azure AD), create an access review of Application1.
- Create an Azure Automation runbook that runs the Get-AzRoleAssignment cmdlet.
- In Azure Active Directory (Azure AD) Privileged Identity Management, create a custom role assignment for the Application1 resources.
- Create an Azure Automation runbook that runs the Get-AzureADUserAppRoleAssignment cmdlet.
Show answer
A — In Azure Active Directory (Azure AD), create an access review of Application1.Azure AD access reviews are the built-in governance feature for exactly this scenario. An access review of Application1 can be scheduled to recur monthly, email reviewers (in this case the developers' manager) a list of users who still have access, and automatically apply results so that unapproved access is removed. Microsoft 365 E5 includes Azure AD Premium P2, which licenses access reviews, and no code is needed. The Automation runbook options require custom development and cannot natively email reviewers or auto-revoke. PIM manages privileged role activation, not periodic recertification of app permissions.
You have an Azure subscription. The subscription has a blob container that contains multiple blobs. Ten users in the finance department of your company plan to access the blobs during the month of April. You need to recommend a solution to enable access to the blobs during the month of April only. Which security solution should you include in the recommendation?
- shared access signatures (SAS)
- Conditional Access policies
- certificates
- access keys
Show answer
A — shared access signatures (SAS)A shared access signature (SAS) is the correct choice because it grants delegated, time-limited access to blob storage. You can set explicit start and expiry times (for example, April 1 through April 30) so the token simply stops working after the month ends. Access keys grant full, indefinite control of the entire storage account and cannot expire on their own, making them unsuitable. Certificates are not used to authorize blob data access. Conditional Access policies govern user sign-in conditions to Azure AD-integrated apps, not time-boxed authorization to specific blobs, which is what SAS provides.
You have an Azure Active Directory (Azure AD) tenant named contoso.com that has a security group named Group1. Group1 is configured for assigned membership. Group1 has 50 members, including 20 guest users. You need to recommend a solution for evaluating the membership of Group1. The solution must meet the following requirements: ✑ The evaluation must be repeated automatically every three months. ✑ Every member must be able to report whether they need to be in Group1. ✑ Users who report that they do not need to be in Group1 must be removed from Group1 automatically. ✑ Users who do not report whether they need to be in Group1 must be removed from Group1 automatically. What should you include in the recommendation?
- Implement Azure AD Identity Protection.
- Change the Membership type of Group1 to Dynamic User.
- Create an access review.
- Implement Azure AD Privileged Identity Management (PIM).
Show answer
C — Create an access review.Azure AD access reviews are designed for periodic recertification of group membership. You can create a review of Group1 that recurs automatically every three months, designate reviewers (members themselves or group owners), and have unapproved members, including guests, removed automatically. This meets all requirements with no development. Dynamic membership changes how users join the group based on attributes but does not evaluate whether existing members should remain. Identity Protection detects risky sign-ins and users, not membership validity, and PIM governs just-in-time privileged role assignments rather than recurring membership reviews.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this AZ-305 bank?
220 questions covering the current AZ-305 Azure Solutions Architect Expert syllabus, every one with the correct answer and an explanation.How long is the real AZ-305 exam?
The official AZ-305 exam gives you 120 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does AZ-305 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.