
Prepare for the AZ-305 Designing Microsoft Azure Infrastructure Solutions Exam
Design cloud and hybrid solutions that run on Azure, including compute, network, storage, monitoring, and security.
A complete prep system — free study guide, adaptive practice exams, spaced-repetition flashcards, and a personalized learning journey that tracks when you're ready.
For architects designing cloud and hybrid infrastructure solutions on Azure.
Content last updated
Try Free Practice Questions & Flashcards
Get 40 exam-style questions and 40 flashcards with detailed explanations — free, no credit card required.
Every answer counts toward your progress. Enroll to access 546 practice questions, 494 flashcards, and a learning journey that targets your weaknesses.
Free AZ-305 Practice Questions (With Answers)
5 real questions from the AZ-305 bank, with the full explanation for each answer. No sign-up needed to read them.
- Question 1Design identity, governance, and monitoring solutions [Azure Design Tools]
Your organization has a policy to manage all infrastructure using Infrastructure as Code (IaC). They have an existing Azure environment where they primarily use ARM Templates, but a new project needs to be deployed across both Azure and AWS. Which Infrastructure as Code tool is the most appropriate for this new project, considering its multi-cloud requirement?
- A.Azure CLI and PowerShell scripts checked into the repository and executed by the pipeline
- B.ARM Templates
- C.Bicep
- D.Terraform
Show answer and explanation
Correct answer: D
Correct. Terraform is an open-source IaC tool by HashiCorp that supports multiple cloud providers, including Azure and AWS. Its multi-cloud portability makes it the most appropriate choice for managing infrastructure across both Azure and AWS from a single codebase.
Why the other options are wrong
A. Incorrect. Scripts in source control are versioned, but they are IMPERATIVE — they describe steps, not the desired end state, so re-running one against a drifted environment does not reliably converge it, and nothing tracks what the script created. That state tracking is the property the team is choosing a declarative tool for.
B. Incorrect. ARM Templates are Azure-native IaC, meaning they are specific to Azure and do not support deployments to other cloud providers like AWS.
C. Incorrect. Bicep is a domain-specific language that compiles to ARM JSON, making it an Azure-native IaC tool. It does not support multi-cloud deployments.
- Question 2Design identity, governance, and monitoring solutions [Microsoft Entra Connect]
An organization uses on-premises Active Directory Domain Services (AD DS) as the authoritative identity source. They want users to sign in to Microsoft Entra ID with their corporate credentials without passwords being synchronized, and without deploying or maintaining any additional on-premises server farm to the cloud. The solution must support seamless SSO from domain-joined machines on the corporate network. Which Microsoft Entra Connect authentication method meets these requirements?
- A.Pass-through Authentication (PTA) with seamless SSO enabled
- B.Password Hash Synchronization (PHS) with seamless SSO enabled.
- C.Active Directory Federation Services (AD FS) with Microsoft Entra Connect configured for federation, requiring additional on-premises servers, load balancers, and certificates.
- D.Microsoft Entra Connect cloud sync with password writeback enabled
Show answer and explanation
Correct answer: A
Correct. Pass-through Authentication redirects authentication requests from Microsoft Entra ID to on-premises Active Directory via lightweight PTA agents installed on-premises servers. Passwords and password hashes never leave the corporate network or get stored in Microsoft Entra ID — authentication is always performed by on-premises AD. Combined with seamless SSO (which uses Kerberos tickets on domain-joined machines), users on the corporate network sign in without entering credentials at all.
Why the other options are wrong
B. Incorrect. Password Hash Synchronization synchronizes a hash of the user's on-premises password hash to Microsoft Entra ID, enabling cloud-based authentication. While PHS with seamless SSO provides a good user experience, it does require password hashes to be stored in Microsoft Entra ID — violating the explicit requirement that passwords must not be synchronized to the cloud. Some organizations with strict on-premises authentication requirements reject PHS for this reason.
C. Incorrect. AD FS federation also validates credentials against on-premises AD without syncing passwords to Microsoft Entra ID, making it technically compliant with the requirement. However, AD FS requires significant additional infrastructure (AD FS servers, WAP servers, load balancers, certificates) compared to PTA's lightweight agent model. For organizations without an existing AD FS deployment, PTA provides the same security posture with dramatically lower operational complexity.
D. Incorrect. Microsoft Entra Connect cloud sync is a lightweight alternative to the full Microsoft Entra Connect client for synchronizing identities. Password writeback allows passwords changed in Microsoft Entra ID to be written back to on-premises AD — it is a direction of synchronization (cloud-to-on-premises), not an authentication method. It does not address how authentication is performed or prevent passwords from being stored in Microsoft Entra ID.
- Question 3Design identity, governance, and monitoring solutions [Conditional Access]
A Conditional Access policy is configured to require MFA for all users accessing the Azure portal. A new Global Administrator account needs to be exempted from this policy during initial setup, as MFA hasn't been configured for the account yet. What is the safest way to implement this temporary exemption?
- A.Add the new Global Administrator account to the policy's exclusion list temporarily
- B.Disable the Conditional Access policy entirely while the new admin account is being configured, then re-enable it after setup.
- C.Create a separate Conditional Access policy that applies only to the new admin account and sets enforcement mode to 'Disabled'.
- D.Temporarily assign the new admin account the Global Administrator role using PIM eligible assignment
Show answer and explanation
Correct answer: A
Correct. Conditional Access policies support exclusions for specific users or groups. Temporarily adding the new admin account to the exclusion list exempts only that account while all other users remain protected by the MFA requirement. After MFA registration is complete, removing the account from the exclusion list immediately re-applies the policy to that account. This is the recommended approach for managing bootstrap scenarios in Conditional Access.
Why the other options are wrong
B. Incorrect. Disabling the Conditional Access policy removes MFA requirements for all users in its scope during the disable window — a significant security exposure. If the disable window extends beyond a few minutes, or if it's forgotten, all Azure portal access is unprotected. The exemption should be surgical, not a policy-wide disable.
C. Incorrect. A policy with enforcement mode 'Disabled' in the new Conditional Access experience means the policy is off — it neither evaluates nor applies. However, the existing MFA policy still applies to the admin account unless they're excluded from it. Creating a disabled policy doesn't exempt the user from other policies. The correct mechanism is adding the user to the existing policy's exclusion list.
D. Incorrect. PIM-activated role assignments do not bypass Conditional Access policies. Conditional Access evaluates every sign-in regardless of how permissions were obtained. PIM activation itself may require MFA as part of the activation workflow, but even after activation, sign-ins to the Azure portal are still subject to the MFA Conditional Access policy.
- Question 4Design data storage solutions [Azure Data Factory]
You are designing a daily ETL process for a large enterprise. This process needs to pull data from an on-premises SQL Server, perform complex transformations (joins, aggregations) that require a Spark engine, and then load the transformed data into Azure Synapse Analytics. You need a fully managed service to orchestrate this entire workflow. Which Azure service should you use?
- A.Azure Data Factory (ADF)
- B.Azure Logic Apps
- C.Azure Functions
- D.Azure Databricks
Show answer and explanation
Correct answer: A
Correct. Azure Data Factory is a cloud-based, fully managed, serverless data integration service specifically designed for orchestrating, moving, and transforming data across diverse on-premises and cloud sources. It can connect to on-premises SQL Server, orchestrate transformations using Mapping Data Flows (which can leverage Spark-backed compute) or integrate with Azure Synapse Spark pools, and load data into Synapse Analytics. This perfectly matches the requirements for a scalable ETL/ELT workflow.
Why the other options are wrong
B. Incorrect. Azure Logic Apps is a serverless workflow service suitable for integrating applications and services, but it's not optimized for large-scale data movement and complex ETL/ELT transformations, especially those requiring a Spark engine.
C. Incorrect. Azure Functions is a serverless compute service for event-driven, small pieces of code. It's not designed for orchestrating complex, large-scale ETL pipelines involving on-premises data sources and Spark transformations.
D. Incorrect. Azure Databricks provides a powerful Spark-based analytics platform for data engineering, machine learning, and data science. While it can perform the transformations, it's not an orchestration service for the entire ETL workflow, nor does it natively handle connecting to on-premises SQL Server for data ingress in the same managed way as ADF.
- Question 5Design business continuity solutions [High Availability]
A company runs a business-critical API hosted on Azure App Service. They need to ensure the API remains available even if the entire East US Azure region experiences an outage. The solution must automatically redirect traffic to a healthy region without manual intervention. Which combination of services achieves active-active geo-redundancy for the API?
- A.Deploy the API to East US only and configure Azure Availability Zones to protect the application against datacenter-level failures
- B.Deploy the API to App Service in East US and West US, fronted by Azure Front Door with health probes for automatic failover
- C.Configure Azure Traffic Manager with a geographic routing policy to route East US users to the East US endpoint.
- D.Enable Auto-scaling on the East US App Service to automatically add instances when load increases due to regional issues.
Show answer and explanation
Correct answer: B
Correct. Azure Front Door is a global Layer 7 load balancer with built-in health probing capabilities. By deploying the API to App Service in two regions and configuring Front Door with health probes and priority routing (or latency-based routing for active-active), Front Door automatically detects East US failures and reroutes traffic to West US within seconds — achieving geo-redundancy with automatic failover and no manual intervention required.
Why the other options are wrong
A. Incorrect. Availability Zones protect against datacenter-level failures within a single region by distributing resources across physically separate facilities in the same metro area. However, they cannot protect against a full regional outage — if all zones in East US become unavailable, the API would be inaccessible. Cross-regional redundancy requires deploying to multiple Azure regions.
C. Incorrect. Geographic routing in Traffic Manager routes requests based on the DNS query origin, not on endpoint health for automatic failover. In a geo-redundancy scenario, priority or performance routing policies are appropriate. Furthermore, Traffic Manager operates at DNS level (not HTTP level), so failover depends on DNS TTL expiration, which can be slow. Azure Front Door provides faster failover at the HTTP/connection level.
D. Incorrect. Auto-scaling adds or removes App Service instances within a single deployment, responding to load changes such as increased CPU or request rates. It operates within a single region and cannot redirect traffic to another region during an outage. If East US is completely unavailable, adding more instances in East US is impossible — the region is offline.
Those are 5 of the 40 questions in the free sample exam. Sign up to take the remaining 35 under exam conditions, get scored, and see which topics are holding you back.
Exam Topics Covered
- Design identity, governance, and monitoring solutions
- Design data storage solutions
- Design business continuity solutions
- Design infrastructure solutions
What's Included with Enrollment
- Personalized Learning Journey – a guided path built around your weak spots
- Readiness Score & Weakness Analytics – know exactly when you're ready
- Unlimited Practice Exams – build confidence with real test conditions
- Memory-First Flashcards – lock in knowledge that lasts
- Integrated Study Guide – streamline your prep in one place
Your free practice progress carries over. Enroll for full access for $49.99.
Start Free. Upgrade When You're Ready.
Stay on your structured path while adding targeted practice with the full set of exam-like questions, expanded flashcards to reinforce concepts, and readiness tracking to identify and address weaknesses when needed.
Frequently Asked Questions

Written by
Alvin Varughese
Founder, MindMesh Academy
Alvin Varughese is the founder of MindMesh Academy and holds 20 professional certifications including Microsoft Agentic AI Business Solutions Architect, AWS Solutions Architect Professional, and Azure DevOps Engineer Expert. He's held senior engineering and architecture roles at Humana (Fortune 50) and GE Appliances. He built MindMesh Academy to share the study methods and first-principles approach that helped him pass each exam.
Start Your Certification Journey Today
Join thousands of students who have successfully prepared for their certifications with MindMesh Academy's comprehensive practice exams and study materials.