Azure Lesson 137 of 137

Azure Interview & Certification Prep: Scenarios + AZ-104/AZ-305 Roadmap

You finished the course. You can build a landing zone, wire up identity, route traffic through a firewall, and reason about cost. Now you need to prove it — in an interview room and in an exam centre. Those are two different games with one shared foundation: the ability to explain a sound decision, out loud, under mild pressure. This capstone lesson turns everything you’ve learned into that ability.

We’ll lay out the certification ladder (which exam, in what order, and who each is for), map every course module to the exam objectives and interview themes it serves, then drill the part most people fluff — scenario and system-design questions, with model answers you can adapt rather than memorise. We finish with behavioural prompts, a “explain it to a non-technical stakeholder” exercise, and a study plan that fits around a job.

In a nutshell

Finishing the course taught you to drive. This capstone is about passing the test — two tests, really, that look different but share one engine. A certification exam is the driving test: it proves you know the rules of the road, the signs, the theory, under timed conditions. A technical interview is being handed the keys and told “get us to the airport in rush hour” — it proves you can apply those rules in messy, real traffic while someone watches. You need both: the cert gets your CV past the filter, the interview earns the offer.

The good news is that the same preparation serves both. Azure’s associate and expert exams are increasingly built on case studies — “here are the constraints, choose and justify” — which is exactly what an interviewer asks out loud. So every hour spent learning to reason about a landing zone, an identity model, or a DR target counts twice. This lesson is the map: which exam to sit and when, how the exam machine really works, a bank of interview scenarios with model answers, and a study plan that survives a full-time job.

Level: Advanced · Time: ~30 min

Best if you’ve worked through the rest of the Azure Zero-to-Hero path (or can hold your own on identity, networking, compute, storage, governance, resilience, and cost). No new tooling — a free Azure account and a willing rubber duck are enough. By the end you can choose your certification path, decode the exam format before you sit it, structure a scenario answer under pressure, and run a realistic multi-week study plan.

Learning objectives

By the end of this lesson you can:

Prerequisites & where this fits

This is the final lesson of Module 10 — Resilience, Cost & Capstone and the capstone after the capstone: it assumes you have worked through the whole Azure Zero-to-Hero path, or have equivalent hands-on experience. You don’t need new tooling — you need the course content, a free Azure account to keep practising in, and a study partner or rubber duck for the mock-interview drill. If a term here is unfamiliar, the topic map below points you straight back to the lesson that teaches it.

The certification ladder

Microsoft’s role-based certifications are designed to be climbed in order. Each rung assumes the one below it, even when it isn’t a formal prerequisite. Start where your current knowledge sits, not where your ambition is.

The Azure certification ladder and topic map: AZ-900 to AZ-104 to AZ-305 plus specialties

The diagram shows the main trunk — AZ-900 → AZ-104 → AZ-305 — with specialty branches hanging off the AZ-104 level, and a column linking each rung to the course modules that prepare you for it. Read it top to bottom as a route, left to right as “what feeds what”.

Exam Certification Level What it covers Who it’s for
AZ-900 Azure Fundamentals Foundational Cloud concepts (IaaS/PaaS/SaaS, shared responsibility), core Azure services, the account model, pricing/SLAs, basic governance and security. No hands-on required. Career-changers, salespeople, managers, anyone new to Azure who needs the vocabulary and the mental model.
AZ-104 Azure Administrator Associate Associate Managing identities & governance, storage, compute (VMs, App Service, containers), virtual networking, and monitoring/backup. Heavy on doing, not designing. Sysadmins, ops engineers, anyone who operates an Azure estate day to day. The single most useful Azure cert for most jobs.
AZ-305 Solutions Architect Expert Expert Designing solutions: identity/governance, data storage, business continuity (HA/DR), and infrastructure — choosing services and trade-offs, not clicking buttons. Architects and senior engineers who make design decisions. Requires AZ-104-level operational knowledge as a foundation.

A few honest notes on the trunk:

Specialty options (the branches)

Once you’re at AZ-104 level, you can branch sideways into a specialty that matches your work. These are not “higher” than AZ-305 — they’re deeper in one domain:

Exam Focus Who it’s for
AZ-500 Azure Security Engineer — identity hardening, platform protection, Defender for Cloud, Sentinel, data/app security. Security engineers; anyone owning the controls auditors ask about. Pairs naturally with Modules 2 and 6.
AZ-700 Azure Network Engineer — hybrid connectivity, core networking, routing, private access, load balancing. Network specialists; the natural deepening of Module 3.
AZ-140 Azure Virtual Desktop — designing and operating AVD at scale. End-user-computing and VDI specialists.
DP-203 / DP-300 Data engineering / database administration on Azure. Data engineers and DBAs deepening Module 5.
AZ-400 DevOps Engineer Expert — CI/CD, IaC, release strategy (builds on AZ-104 or the Developer cert AZ-204). Platform/DevOps engineers; the deepening of Modules 8 and 9.

The sensible majority path for an infrastructure-leaning engineer is AZ-900 (optional) → AZ-104 → AZ-305, with AZ-500 or AZ-700 added when your day job pulls you toward security or networking. Pick the branch you already work in — a cert you can back with stories beats a cert you crammed.

Topic-to-lesson map

Targeted revision beats re-reading everything. Use this table to jump from an interview theme or exam objective straight to the course lesson that owns it. Every linked lesson is part of the Azure Zero-to-Hero path.

Theme / exam domain Mostly tested in Course lessons to revise
Cloud & account model — IaaS/PaaS/SaaS, subscriptions, RGs, regions, ARM AZ-900, AZ-104 What Is Azure?; Working with Azure: Portal, CLI, PowerShell & Cloud Shell
Identity & access — Entra ID, RBAC, PIM, Conditional Access AZ-104, AZ-305, AZ-500 Entra ID Fundamentals; Landing Zone Identity; PIM for Azure roles; Conditional Access token protection
Networking — VNets, NSGs, peering, hub-spoke, egress, private access AZ-104, AZ-305, AZ-700 VNet basics; NAT Gateway egress; Private Endpoints & DNS; Virtual WAN
Compute & hosting — VMs/VMSS, App Service, Functions, Container Apps AZ-104, AZ-305 App Service hardening; Functions Flex Consumption; Container Apps
Storage & data — Blob, Files, SQL, Cosmos DB, Redis AZ-104, AZ-305, DP-* Blob data protection; Azure SQL Hyperscale; Cosmos DB partition keys
Security & secrets — Key Vault, encryption/CMK, Defender, Policy AZ-500, AZ-305 Key Vault & workload identity; Policy as Code
Governance & landing zones — management groups, CAF, guardrails AZ-305 Landing Zone with the CAF; Resource organization; Governance & cost guardrails
HA/DR & resilience — zones, region pairs, RTO/RPO, failover AZ-305 Active-Active Multi-Region; Site Recovery runbooks; Backup hardening
Cost / FinOps — tagging, budgets, Reservations, Savings Plans AZ-900, AZ-305 FinOps on Azure; Commitment strategy
Operations & IaC — monitoring, patching, Bicep/Terraform, pipelines AZ-104, AZ-400 Azure Monitor end to end; AVM & Terraform platform; Capstone landing zone

How to answer a scenario question

Before the question bank, internalise the shape of a good answer. Interviewers aren’t checking whether you memorised a service list — they’re checking whether you think like an engineer. Use this five-beat structure for any open-ended scenario:

  1. Clarify. Ask one or two sharp questions. “Is this internet-facing or internal? What’s the RTO target? Is there a compliance regime in play?” This alone separates seniors from juniors.
  2. State constraints & assumptions. Make the unstated explicit: “I’ll assume a single tenant, prod workload, and a tolerance for a few minutes of downtime.”
  3. Propose a design. Name specific Azure services and how they connect. Be concrete.
  4. Surface trade-offs. Every choice costs something — money, complexity, latency. Naming the downside of your own answer is the strongest signal you can send.
  5. Address day-2 / operate. How is it monitored, secured, patched, and paid for? Architecture that can’t be operated isn’t a finished answer.

The “Common mistakes” section later lists the anti-patterns of this structure. Practise saying these beats out loud — the goal is for them to feel automatic.

Interview questions (with model answers)

These are realistic mid-to-senior Azure questions, grouped by theme. The model answers are reference shapes, not scripts — adapt them to the role and to your own experience. Where a question maps to a course lesson, revise that lesson if the answer doesn’t yet feel like yours.

Identity & access

Q1. A developer needs to read secrets from Key Vault from an Azure Function. How do you grant access without storing any credentials?

Model answer: Enable a managed identity on the Function (system-assigned is simplest for a 1:1 mapping). Grant that identity the minimum it needs on the vault — with the RBAC data-plane model, the Key Vault Secrets User role scoped to the specific vault, not the subscription. The Function’s SDK then acquires a token from the Entra ID instance metadata endpoint at runtime; there is no secret in app settings, in code, or in a pipeline. The trade-off versus a connection string is that managed identities only work for Azure-hosted compute, so local development uses the developer’s own Entra identity via the Azure CLI credential. This is the pattern from Key Vault & workload identity.

Q2. What’s the difference between Entra ID roles and Azure RBAC roles? Give an example of each.

Model answer: They govern different planes. Entra ID roles (e.g. Global Administrator, User Administrator) manage the directory — users, groups, app registrations, tenant settings. Azure RBAC roles (e.g. Owner, Contributor, Reader) manage Azure resources — subscriptions, resource groups, VMs, storage. A User Administrator can create accounts but can’t deploy a VM; a Contributor can deploy a VM but can’t reset a user’s password. The classic mistake is assuming Owner on a subscription lets you manage Entra — it doesn’t. Scope RBAC at the lowest level that works (resource group over subscription) and prefer just-in-time elevation with PIM over standing Owner access.

Networking

Q3. Design connectivity for three application teams that must share central network services (firewall, DNS) but stay isolated from each other.

Model answer (using the five-beat structure): I’d clarify the scale and whether on-prem connectivity is needed. Assuming a handful of spokes and a single region, I’d use a hub-and-spoke topology: one hub VNet holding Azure Firewall and Private DNS, and one spoke VNet per team, each peered to the hub but not to each other. Default routes (UDRs) in each spoke send egress through the firewall for inspection and logging. Teams are isolated because peering is non-transitive — spoke-to-spoke traffic has no path unless I explicitly create one. Trade-offs: the hub is a shared blast radius and a cost centre, and at large scale I’d switch to Azure Virtual WAN to avoid managing peering and route tables by hand. Operate: NSG flow logs and firewall logs into Log Analytics. This is VNet basics plus Virtual WAN.

Q4. An app behind a NAT Gateway is intermittently failing outbound connections under load. What’s happening and how do you fix it?

Model answer: That’s classic SNAT port exhaustion. Every outbound flow to the same destination IP:port consumes a SNAT port from a finite pool; under load, or with chatty connections that aren’t reused, the pool drains and new connections fail. The fixes, in order: ensure the application reuses connections (HTTP keep-alive, pooled DB connections) so it isn’t burning a port per request; add more public IPs to the NAT Gateway to multiply the port pool; and reduce the TCP idle timeout so ports are reclaimed faster. NAT Gateway is the right tool precisely because it scales SNAT ports far beyond default outbound or a load balancer’s outbound rules. This is the NAT Gateway lesson.

HA / DR

Q5. The business wants an RTO of a few minutes and an RPO near zero for a customer-facing web app. Walk me through an architecture.

Model answer: Clarify: “near zero” RPO means I cannot lose committed data, which pushes me toward synchronous or multi-write data, and a few-minute RTO rules out manual rebuilds. I’d run active-active across two regions: identical per-region “stamps” (compute + regional data), fronted by Azure Front Door for global ingress and health-probe-based failover. For data, the choice drives everything — Cosmos DB with multi-region writes gives near-zero RPO with conflict resolution; if it’s relational, Azure SQL with auto-failover groups gives a fast, near-synchronous failover with a small RPO. Trade-offs: active-active roughly doubles cost and forces me to handle data conflicts and “split-brain”, so if the business could tolerate a larger RTO I’d offer active-passive as the cheaper option and let them choose. Operate: automated failover with tested runbooks, plus regular failover drills — an untested DR plan is a hope, not a plan. This maps to Active-Active Multi-Region and Site Recovery runbooks.

Q6. What’s the difference between availability zones and region pairs, and when do you use each?

Model answer: Availability zones are physically separate datacentres within one region, with independent power/cooling/network. Spreading instances across zones protects against a datacentre-level failure with no added latency to speak of and no data-residency change — it’s the default for production HA. Region pairs are two regions in the same geography that Microsoft updates sequentially and uses for paired services; you fail over to the paired region to survive a whole-region outage or for data residency. Rule of thumb: use zones for HA (the common case) and a second region for DR (the rarer, bigger event). They compose — a serious design is zone-redundant within each region and multi-region across them.

Cost

Q7. Leadership says the Azure bill is “too high” and growing. How do you investigate and bring it down without breaking anything?

Model answer: I treat cost as an engineering signal, not a finance complaint, in three moves. Inform: get visibility and attribution first — a mandatory tag taxonomy (CostCenter, Owner, Environment, Application) enforced with Azure Policy, and Cost Analysis grouped by those tags to find where the money goes. You can’t optimise what you can’t attribute. Optimise: act on Azure Advisor rightsizing recommendations, delete orphaned disks/IPs/old snapshots, move non-prod to auto-shutdown schedules, and — only for steady, predictable baseline load — buy Reservations or Savings Plans for 1–3 year commitment discounts. Operate: set Budgets with alerts so it never silently creeps again. Trade-off: commitments save the most but reduce flexibility, so I’d only commit the portion of spend I’m confident is permanent. This is the FinOps and Commitment strategy lessons.

Governance

Q8. A new team is onboarding. How do you give them a subscription that’s productive but can’t drift out of compliance?

Model answer: This is a landing zone question. I’d place their subscription under the right management group in the CAF hierarchy so it inherits the platform’s guardrails automatically. Those guardrails are Azure Policy initiatives assigned at the management-group scope — e.g. deny disallowed regions, require tags, enforce diagnostic settings, deny public IPs on certain resources. Identity and networking come pre-wired (RBAC groups, a spoke VNet peered to the hub). The team gets Contributor on their subscription but never Owner at a higher scope, and elevation is just-in-time via PIM. Trade-off: heavy-handed Deny policies frustrate teams, so I’d lean on Audit/Deploy-if-not-exists for things I can auto-remediate and reserve Deny for genuine non-negotiables. This is Landing Zone with the CAF, Resource organization, and Governance.

Security

Q9. How would you secure traffic to a PaaS service like Azure SQL or Storage so it never traverses the public internet?

Model answer: Use a Private Endpoint — it projects the PaaS service into your VNet as a private IP, so clients reach it over the Microsoft backbone, not its public endpoint. Critically, you must also fix DNS: the service’s public FQDN has to resolve to the private IP, which means a Private DNS zone (e.g. privatelink.database.windows.net) linked to the VNet, ideally centralised in the hub. Then disable public network access on the service itself so the public endpoint is genuinely closed. Trade-off: private endpoints add per-endpoint cost and DNS complexity at scale, which is exactly why the Private Endpoints & DNS at scale lesson centralises the zones and automates the records. Pair this with managed identity for auth and you’ve removed both the network and the credential attack surface.

Behavioural & stakeholder questions

Technical depth gets you shortlisted; communication gets you hired. Two flavours come up constantly.

Behavioural (“tell me about a time…”). Use the STAR structure — Situation, Task, Action, Result — and keep it to a tight ninety seconds. Have two or three stories ready that you can flex to most prompts:

“Explain this to a non-technical stakeholder.” This tests whether you actually understand something — you can only simplify what you’ve truly internalised. The rules: drop the jargon, reach for an analogy, and lead with the business impact, not the mechanism.

Example — explaining a landing zone to a finance director: “Think of it like building out an office floor before staff move in — we’ve already put in the locks, the wiring, the fire alarms, and the signage to each department. So when a new team needs space, they move in the same day and the safety and budget controls are already there. Without it, every team builds their own floor from scratch, and that’s where overspend and security gaps creep in.”

Notice what the analogy does: no mention of management groups or Policy, but the value (speed, safety, cost control) lands. Practise this for three or four core concepts — identity, networking, DR, and cost are the usual suspects.

Going deeper

The ladder earlier showed the trunk you’ll actually climb. This section is the whole map — every rung, the machine that runs the exams, and the deeper judgement the architect track and senior interviews are really testing.

The full Azure certification roadmap

Microsoft’s portfolio has three tiers. The course prepares you best for the infrastructure spine (AZ-900 → AZ-104 → AZ-305), but knowing the neighbours helps you choose deliberately rather than by default.

Tier Exams Expires? What the tier signals
Fundamentals AZ-900 (Azure), AI-900 (AI), DP-900 (Data), SC-900 (Security, Compliance & Identity) Never Vocabulary and mental models. One afternoon each; pick the one that matches the conversations you want to be in.
Associate AZ-104 (Administrator), AZ-204 (Developer), AZ-500 (Security Engineer), AZ-700 (Network Engineer), DP-100 (Data Scientist), plus AZ-140 / DP-300 specialties 1 year “I can operate/build this hands-on.” The tier employers screen for.
Expert AZ-305 (Solutions Architect), AZ-400 (DevOps Engineer) 1 year “I can design/deliver across teams.” AZ-400 builds on AZ-104 or AZ-204; AZ-305 assumes AZ-104-level ops.

Three facts most people learn the expensive way:

Pick a path by role

Sequence to your current job first, then to the next one:

If your role is… Sensible sequence Why
Cloud/Sysadmin, Ops AZ-900 (optional) → AZ-104 → AZ-305 The operate-then-design spine; AZ-104 is the one employers ask for.
Developer AZ-900 → AZ-204 → AZ-400 or AZ-305 AZ-204 proves you build on PaaS; branch to DevOps or design.
Security / GRC SC-900 → AZ-500 (AZ-104 first helps) SC-900 frames identity + compliance; AZ-500 is the hands-on control set.
Network specialist AZ-104 → AZ-700 AZ-700 is the deep networking layer on an admin base.
Platform / DevOps AZ-104 or AZ-204 → AZ-400 AZ-400 is process + tooling on a proven hands-on base.
Aspiring architect AZ-104 → AZ-305 Don’t skip AZ-104 — AZ-305 quietly assumes you can already administer.

How the exam machine actually works

Walking in knowing the format is worth a handful of marks. The following is representative of current role-based exams — details vary per exam, so always check the exam’s own page:

Study strategy that matches the machine: start from Microsoft’s official “skills measured” outline — the authoritative blueprint, and Microsoft publishes a change-log when it updates one. RAG-rate each line against the topic map above, close the reds with labs not videos, then drill the free official practice assessment until you’re consistently clear of the bar. Because AZ-104 and AZ-305 lean on case studies, your interview scenario drills are exam revision.

The highest-yield architect topics

For AZ-305 and any senior interview, five domains repay study out of all proportion. They’re also the lenses an interviewer uses when they ask “would this survive production?” — map them onto the Azure Well-Architected Framework (WAF) pillars: Reliability, Security, Cost Optimisation, Operational Excellence, Performance Efficiency.

Domain The judgement being tested Revise
Landing zones & governance Do new workloads inherit guardrails, or drift? Management groups, Policy, CAF. Landing Zone with the CAF
Identity Least privilege, managed identity over secrets, PIM, Conditional Access. Entra ID Fundamentals
Networking Segmentation, private access, deterministic egress, hub-spoke vs Virtual WAN. VNet basics
Cost / FinOps Attribution, rightsizing, commitment discounts tied to steady load. FinOps on Azure
Well-Architected trade-offs Naming what you optimised for and what you traded away. Well-Architected Framework

The through-line: architects are paid for trade-offs, and WAF is the shared vocabulary for them. “I chose zone-redundant over multi-region because the RTO allowed it, it halves the cost, and it cuts the operational load” is a WAF answer — reliability weighed against cost and operational excellence, out loud.

Framing an Azure system-design answer

The five-beat structure earlier is the skeleton. For Azure system design specifically, hang these organs on it — interviewers listen for whether you reach for the platform’s building blocks in the right order:

  1. Front door first. Global ingress and edge: Front Door / Traffic Manager / Application Gateway. State whether traffic is internet-facing and how it fails over.
  2. Then the compute tier and its scaling unit: App Service, Container Apps, AKS, Functions, or VMSS — and why that one (managed vs control, cold-start tolerance, scale shape).
  3. Then data — the choice that dominates cost and DR: SQL vs Cosmos DB vs Storage, and the consistency/replication model that meets the RPO.
  4. Cross-cut with identity and network: managed identity for auth, private endpoints for data, a deliberate egress story.
  5. Close with day-2: Azure Monitor + Log Analytics, alerts, backup, and the bill.

Name the WAF trade-off at each layer and you’re answering at architect level, not admin level.

Behavioural depth — a worked STAR

The behavioural section earlier gave you the prompts; here’s the shape of a strong answer so yours isn’t a shapeless story. STAR keeps you to ~90 seconds and forces a result:

Situation: “Our nightly batch was breaching its window and paging on-call twice a week.” Task: “I owned reliability for that service and had to stop the pages without a rewrite.” Action: “I profiled it, found SNAT exhaustion under load, moved outbound through a NAT Gateway with extra public IPs, and added connection pooling.” Result: “Pages went to zero, the batch window halved, and I wrote the runbook so the next person wouldn’t rediscover it.”

Notice the result is quantified and includes what you changed so it can’t recur — interviewers weight the “what did you learn / prevent” beat heavily. Prepare three such stories (an incident, a disagreement, a trade-off) and flex them to the prompt.

A portfolio that proves it

Certs and stories open the door; evidence closes it. You don’t need a big-bang project — you need something you can screen-share and narrate:

A candidate who says “here’s the repo, here’s the design doc, ask me anything” has already won most of the interview.

Quick check

  1. You’re new to cloud and want one credential before job-hunting for an Azure admin role. Which exam, and is AZ-900 required first?
  2. In a scenario question, what should you almost always do before proposing a design?
  3. Name the planes that Entra ID roles and Azure RBAC roles each govern.
  4. An app’s outbound connections fail under heavy load behind a NAT Gateway. What’s the most likely cause?
  5. When would you use availability zones versus a second region?

Answers

  1. Target AZ-104 (Azure Administrator) — it’s the cert employers ask for. AZ-900 is not a prerequisite; take it first only if cloud is genuinely new to you and you want a confidence builder, otherwise go straight to AZ-104.
  2. Clarify the requirements — ask one or two sharp questions (internet-facing or internal? RTO/RPO? compliance?). Jumping to a design without clarifying is the most common junior tell.
  3. Entra ID roles govern the directory (users, groups, app registrations, tenant settings). Azure RBAC roles govern Azure resources (subscriptions, resource groups, and the resources in them).
  4. SNAT port exhaustion — the finite SNAT port pool drains under load. Fix with connection reuse, more public IPs on the NAT Gateway, and a shorter idle timeout.
  5. Use availability zones for high availability within a region (the default for production); use a second region for disaster recovery or data residency. Strong designs do both.

Exercise

Run a 30-minute mock-interview drill. Pair up with someone (or record yourself answering aloud — talking to a wall counts).

  1. Pick three questions from the bank above, one each from a different theme (e.g. one networking, one HA/DR, one governance).
  2. Answer each out loud, without notes, deliberately walking the five beats: clarify → constraints → design → trade-offs → operate. Time yourself; aim for two to three minutes per answer.
  3. For one of the three, also do the stakeholder version — re-explain your design to an imaginary non-technical manager using an analogy and business impact.
  4. Self-score against the rubric below, then redo your weakest answer once more.
Signal Weak (1) Strong (3)
Clarified first Jumped straight to services Asked 1–2 sharp scoping questions
Named trade-offs Presented one option as obviously correct Named the downside of own design and an alternative
Concrete services Vague (“some load balancer”) Specific and correct (“Front Door for global ingress”)
Day-2 thinking Stopped at architecture Covered monitoring, security, and cost
Communication Rambled / jargon wall Structured, calm, jargon adjusted to audience

If you score below 2 on any row, the topic map tells you which lesson to revisit. Do this drill weekly in the run-up to interviews and the structure becomes muscle memory.

Practice challenges

Six graded challenges, escalating from exam-recall to open architecture. Try each before opening the answer — say design answers out loud, walking the five beats. Answers are original to this lesson.

1 — Exam MCQ (beginner): the renewal clock. You passed AZ-104 on 1 March. What must you do to keep it, by when, and what does it cost?

<details> <summary>Answer</summary>

Role-based certs expire 12 months after you earn them, so this one lapses the following 1 March. Renew it free via the online, unproctored renewal assessment on Microsoft Learn — available from six months before expiry (so from ~1 September). Why: Microsoft replaced paid re-sits with yearly free online renewals to keep certs current; miss the window and the cert drops off your transcript and you re-sit the full paid exam. (Fundamentals like AZ-900 never expire.) </details>

2 — Exam MCQ (beginner→intermediate): the no-return trap. Midway through an AZ-305 case study you realise your answer to an earlier case study was wrong — but you’ve already moved on. Can you fix it, and what’s the takeaway?

<details> <summary>Answer</summary>

No. Case studies typically sit in their own section, and once you pass the section boundary you can’t return; the exam warns you first. Takeaway: answer and review everything inside a case (and every flagged item) before clicking past the no-return screen. The flag-and-review feature only works within the current section. Why: sectioned exams lock behind you by design — treat each boundary as final. </details>

3 — Design scenario (intermediate): credentials-free access. A container on Azure Container Apps must pull its image from Azure Container Registry and read a secret from Key Vault, with zero secrets in configuration. Name the mechanism and the two role assignments.

<details> <summary>Answer</summary>

Enable a managed identity on the Container App (system- or user-assigned), then grant it two RBAC roles scoped to the specific resources: AcrPull on the registry and Key Vault Secrets User on the vault (RBAC data-plane model). Why: managed identity + tightly scoped RBAC removes stored credentials entirely; scope to the resource, never the subscription. The interviewer is checking you reach for identity-based auth by default, not connection strings. </details>

4 — Design scenario (intermediate→advanced): two-option HA/DR. A stakeholder wants “99.99% availability and survive a full region outage” but is cost-sensitive. Give the two-option answer an architect would present.

<details> <summary>Answer</summary>

Present both, name the trade-off, and let the business pick the RTO/RPO they’ll pay for. Why: the test is whether you translate a vague ask into RTO/RPO and price the trade-off — not whether you can name the fanciest option. </details>

5 — Exam MCQ (advanced): the right Policy effect. You must guarantee no new storage account is created with public blob access, while flagging existing non-compliant ones without breaking them. Which Azure Policy effect(s)?

<details> <summary>Answer</summary>

Deny for creation of new non-compliant resources; Audit (or AuditIfNotExists) to flag the existing estate without changing it; optionally Modify / DeployIfNotExists to auto-remediate over time. Why: Deny stops drift at the gate, Audit gives visibility on what’s already there, and DINE/Modify remediates — which is exactly the “guarantee new, flag old” split the stem asks for. Reaching only for Deny would (incorrectly) leave the existing estate invisible. </details>

6 — Design scenario (advanced): whole system + a WAF trade-off. Design ingress-to-data for a global, internet-facing web app with an RPO near zero, then name one Well-Architected trade-off you consciously accepted.

<details> <summary>Answer</summary>

Edge → compute → data → identity/network → day-2: Front Door for global ingress (WAF policy, health-probe failover) → regional stamps of Container Apps / App ServiceCosmos DB multi-region writes (near-zero RPO) or Azure SQL auto-failover groups; managed identity for auth, private endpoints for data, Azure Monitor + Log Analytics for day-2. Trade-off example: I chose active-active (Reliability) at the cost of roughly double spend and conflict-resolution complexity (Cost + Operational Excellence). Why: senior answers name the building blocks in order and state the pillar they traded — that ordering-plus-trade-off is the whole signal. </details>

Study plan & exam-day tips

A realistic plan around a job (per exam, 6–10 weeks).

Phase Weeks What you do
Map the gap 1 Read Microsoft’s official skills measured outline for your target exam. RAG-rate each line (red/amber/green) against the topic map above.
Close the reds 2–4 Work the linked course lessons for every red line — do the labs, don’t just read. Hands-on memory outlasts crammed memory.
Active recall 4–7 Take Microsoft’s free official practice assessment for the exam. For every wrong answer, go back to the source and re-do the relevant lab. Repeat until you’re consistently above ~80%.
Mock & polish last 1–2 Run the mock-interview drill (it doubles as scenario revision), re-take the practice assessment cold, and skim your weakest two domains.

A few principles that matter more than any single resource:

Exam-day tips.

Certification mapping

This lesson is meta — it maps to the exams rather than teaching a single objective — but it directly serves:

Use the topic-to-lesson map above as your personal objective tracker for both.

Common beginner mistakes

These are the traps that cost people the exam or the offer — the misconception first, then the mental model that fixes it. (The troubleshooting-style “how to answer” anti-patterns are earlier; these are the belief-level errors.)

On the exam

In the interview

Glossary

Next steps

You’ve reached the end of the Azure Zero-to-Hero path — the next step is the real one: book an exam, or walk into an interview. To keep sharpening the design judgement these scenarios depend on, go deeper on the three domains interviewers probe hardest:

AzureCertificationAZ-104AZ-305Interview PrepCareer
Need this built for real?

Vinod is a Senior Cloud Architect (22+ yrs) — available for Azure / AWS / GCP architecture, landing zones, and migrations.

Work with me

Comments