Microsoft Certified: Azure Solutions Architect Expert (AZ-305)

This page breaks AZ-305 (Designing Microsoft Azure Infrastructure Solutions) into 10 architect-level sections mapped to the skills measured. Work through the sections in order, then switch to mixed practice to simulate exam conditions.

Vendor: Microsoft Credential: Azure Solutions Architect Expert Exam: AZ-305 Practice: domain then mixed

AZ-305 coverage (10 sections)

Use the practice button on each card to open the quiz set for that domain in a new tab.

Architecture Fundamentals and Design Requirements (AZ-305 mindset)

S01

What you will practice: Gathering requirements • Functional vs non-functional requirements (NFRs): availability, scalability, performance, security, compliance, cost, maintainability

  • Gathering requirements
  • Functional vs non-functional requirements (NFRs): availability, scalability, performance, security, compliance, cost, maintainability
  • Workload characteristics: bursty vs steady, stateful vs stateless, latency-sensitive vs throughput-heavy
  • Constraints: region requirements, data residency, regulatory constraints, legacy dependencies, timeline and skills constraints
  • Design trade-offs
  • CAP-style tradeoffs in distributed systems (consistency vs availability vs partition tolerance) at an applied level
  • RPO/RTO targets and their cost implications
  • Performance vs cost vs operational complexity
  • Reference frameworks (commonly referenced in prep + scenarios)
  • Azure Well-Architected Framework pillars (reliability, security, cost optimization, operational excellence, performance efficiency)
  • Cloud Adoption Framework concepts (landing zones, governance, management, migration planning)

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Logging Strategy Design (what to log, where it goes, and why)

S02

What you will practice: What you need to collect • Platform logs vs resource logs vs activity logs vs audit logs

  • What you need to collect
  • Platform logs vs resource logs vs activity logs vs audit logs
  • Workload telemetry: application, OS, container, and network signals
  • Security-relevant logs: sign-in, audit, key vault access, NSG flow logs, firewall logs
  • Log destinations and routing patterns
  • Log Analytics workspace patterns (centralized vs per-subscription/per-workload)
  • Diagnostic settings routing: to Log Analytics, Storage account, Event Hub
  • Event Hub as log streaming backbone (SIEM/SOAR, third-party tools)
  • Retention and cost design
  • Retention policies, tiering (hot/cold), archive patterns
  • Data volume estimation and cost control (sampling, filtering, table selection)
  • Design for scale

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Monitoring and Observability Design (metrics, alerts, and response)

S03

What you will practice: Monitoring layers • Platform metrics (near real-time), logs (query-driven), traces (distributed)

  • Monitoring layers
  • Platform metrics (near real-time), logs (query-driven), traces (distributed)
  • Health signals: Resource Health vs Service Health design usage
  • Azure Monitor design
  • Metrics and log-based alerting strategy
  • Action Groups design (email/SMS/webhook/ITSM), alert routing
  • Workbooks/dashboards for role-based views (ops vs sec vs management)
  • Application performance monitoring design
  • Application Insights patterns (instrumentation, distributed tracing, dependency tracking)
  • SLO/SLA alerting mapped to customer impact
  • Security monitoring integration
  • Sentinel design rationale (when SIEM is required, what data sources feed it)

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Authentication Design (who signs in, how, and from where)

S04

What you will practice: Identity models • Cloud-only vs hybrid identity patterns

  • Identity models
  • Cloud-only vs hybrid identity patterns
  • Tenant strategy (single tenant vs multi-tenant) and isolation needs
  • Sign-in security design
  • MFA strategy by risk/user group
  • Conditional Access policy design patterns (location/device risk/app sensitivity)
  • Legacy authentication blocking strategy
  • External identities
  • B2B collaboration design (guest access controls, invitation governance)
  • Customer identity direction (when a separate identity system is required conceptually)

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Authorization Design (who can do what, at what scope)

S05

What you will practice: Azure authorization (RBAC) • Role assignment strategy by scope: management group vs subscription vs resource group vs resource

  • Azure authorization (RBAC)
  • Role assignment strategy by scope: management group vs subscription vs resource group vs resource
  • Custom roles vs built-in roles (when each is appropriate)
  • Least privilege models for platform teams, app teams, and auditors
  • Privileged access design
  • Privileged Identity Management (JIT activation, approval, access reviews conceptually)
  • Break-glass admin account strategy
  • On-premises authorization considerations
  • Access patterns for hybrid resources (identity source, trust boundaries, secure access paths)
  • When to use managed identities/service principals vs shared credentials (design-level reasoning)

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Secrets, Certificates, and Key Management Design

S06

What you will practice: Key Vault architecture • Vault design: separation by environment (dev/test/prod), region, and application boundary

  • Key Vault architecture
  • Vault design: separation by environment (dev/test/prod), region, and application boundary
  • Access control model: RBAC vs vault access policies (design decision rationale)
  • Key and certificate lifecycle
  • Rotation strategy, expiration management, automated renewal patterns
  • HSM-backed keys vs software keys (when required)
  • Using secrets safely
  • App configuration patterns: managed identity + Key Vault references
  • Avoiding secrets in code and pipelines; secure deployment patterns

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Governance, Compliance, and Identity Governance Design

S07

What you will practice: Management group/subscription/resource group design • Enterprise-scale hierarchy patterns

  • Management group/subscription/resource group design
  • Enterprise-scale hierarchy patterns
  • Subscription strategy by environment, business unit, workload, or compliance boundary
  • Resource group strategy by lifecycle and ownership
  • Tagging and cost governance
  • Tag taxonomy: owner, cost center, environment, data classification, criticality
  • Enforcement approach (policy-driven tagging)
  • Compliance management design
  • Azure Policy: initiatives, assignments, effects (deny/audit/append/deployIfNotExists)
  • Blueprint-style governance thinking (even if implementation uses policy + templates)
  • Identity governance
  • Access reviews and lifecycle controls (high-level)

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Data Storage Design: Relational Data (SQL and managed relational services)

S08

What you will practice: Selecting the right relational service • Azure SQL Database vs SQL Managed Instance vs SQL Server on Azure VMs (decision criteria)

  • Selecting the right relational service
  • Azure SQL Database vs SQL Managed Instance vs SQL Server on Azure VMs (decision criteria)
  • Managed PostgreSQL/MySQL (when appropriate)
  • Service tier and compute tier design
  • Provisioned vs serverless patterns (where applicable)
  • Compute sizing and cost model considerations
  • Scalability design
  • Vertical vs horizontal scale approaches (read replicas, sharding patterns conceptually)
  • Elastic pools patterns (multi-DB cost optimization concept)
  • Data protection
  • Backup strategy and retention requirements
  • Encryption at rest and in transit

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Data Storage Design: Semi-Structured/Unstructured + Data Integration/Analytics

S09

What you will practice: Semi-structured storage choices • Cosmos DB-style patterns (global distribution, partitioning, consistency choices at a high level)

  • Semi-structured storage choices
  • Cosmos DB-style patterns (global distribution, partitioning, consistency choices at a high level)
  • Document vs key-value vs wide-column style reasoning
  • Unstructured storage choices
  • Blob Storage vs Data Lake Storage Gen2 (analytics + hierarchical namespace use cases)
  • Azure Files for SMB-style lifts and shared storage requirements
  • Storage redundancy selection (LRS/ZRS/GRS/GZRS) tied to durability and recovery needs
  • Balancing features, performance, and costs
  • Hot/cool/archive tiering strategy and lifecycle policies
  • Throughput and latency considerations (IOPS vs bandwidth vs request rate)
  • Protection and durability
  • Soft delete, versioning, immutability concepts

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

Business Continuity + Infrastructure: HA/DR, Compute, App Architecture, Network, Migration

S10

What you will practice: This section consolidates the remaining two official areas: business continuity and infrastructure solutions (compute/app architecture/migrations/network).

  • This section consolidates the remaining two official areas: business continuity and infrastructure solutions (compute/app architecture/migrations/network).
  • A) Business continuity design (backup, DR, high availability)
  • Backup and disaster recovery
  • Design to meet RPO/RTO (translate objectives into architecture)
  • Backup strategy by workload type: compute, databases, unstructured data
  • Hybrid recovery patterns (on-prem + Azure recovery alignment)
  • High availability
  • Compute HA patterns (zones, sets, scale-out)
  • Relational HA patterns (replication/failover designs)
  • Semi/unstructured durability designs (ZRS/GZRS, multi-region patterns)
  • B) Compute solutions design
  • VM-based solutions, container-based solutions, serverless solutions, batch processing compute
  • Selection criteria: operational control vs velocity vs scaling needs
  • Stateless vs stateful placement decisions

Tip: After topic practice, do mixed sets under time pressure and review missed questions immediately.

FAQ

How should I use the 10 sections on this page?

Start with one section at a time, complete the practice set for that section, then review the explanations and repeat missed concepts. After you cover all sections, switch to mixed practice under time pressure.

Do the practice buttons open in a new tab?

Yes. Each section includes a button that opens the quiz set for that section in a new tab.

Is this outline aligned to the real AZ-305 skills measured?

Yes. The sections are organized to match the official AZ-305 skills measured: design identity, governance, and monitoring solutions; design data storage solutions; design business continuity solutions; and design infrastructure solutions.

Does passing AZ-305 alone earn the Azure Solutions Architect Expert certification?

AZ-305 is the required expert exam for the Azure Solutions Architect Expert credential. To earn the certification badge, Microsoft also requires you to hold an active Azure Administrator Associate certification.