Azure AZ-305: Designing Microsoft Azure Infrastructure Solutions - Fact Sheet¶
Quick Reference¶
Exam Code: AZ-305 Duration: 120 minutes (2 hours) Questions: 40-60 questions (case studies + multiple choice) Passing Score: 700/1000 Cost: $165 USD Validity: 1 year (renewable annually) Prerequisites: AZ-104 (Azure Administrator) recommended Difficulty: βββββ (Expert-level certification) Experience: 3+ years of IT experience, including advanced Azure design skills
Exam Domains¶
| Domain | Weight | Key Focus |
|---|---|---|
| Design Identity, Governance, and Monitoring Solutions | 25-30% | Azure AD, RBAC, governance, policy, monitoring |
| Design Data Storage Solutions | 25-30% | Storage accounts, databases, caching, data integration |
| Design Business Continuity Solutions | 10-15% | Backup, disaster recovery, high availability |
| Design Infrastructure Solutions | 25-30% | Compute, networking, containers, migration |
Azure Well-Architected Framework¶
π Azure Well-Architected Framework - Complete architecture framework π Well-Architected Review - Assessment tool and guidance
Five Pillars: 1. Reliability - Availability, resiliency, recovery 2. Security - Identity, data protection, network security 3. Cost Optimization - Resource optimization, monitoring 4. Operational Excellence - DevOps, monitoring, automation 5. Performance Efficiency - Scalability, load balancing
Key Resources: - π Azure Architecture Center - Reference architectures - π Cloud Design Patterns - Common architecture patterns - π Best Practices for Cloud Applications - Design guidance - π Design Principles - Architecture principles
Identity and Governance Architecture¶
Azure Active Directory (Azure AD / Entra ID)¶
Identity Foundation: - Cloud-based identity and access management - Single sign-on (SSO) across applications - Multi-factor authentication (MFA) - Conditional Access policies - π Azure Active Directory Overview - Core concepts - π Azure AD Architecture - Design patterns - π Azure AD Editions - Free, P1, P2 comparison - π Azure AD Licensing - Feature comparison
Advanced Identity Features: - Azure AD B2B - Guest user access and collaboration - π Azure AD B2B - Business-to-business identity - Azure AD B2C - Customer identity and access management - π Azure AD B2C - Consumer identity platform - Azure AD Domain Services - Managed domain services (LDAP, Kerberos) - π Azure AD Domain Services - Managed domain controllers - Privileged Identity Management (PIM) - Just-in-time privileged access - π Azure AD PIM - Privileged access management - Identity Protection - Risk-based conditional access - π Azure AD Identity Protection - Risk detection
Authentication and Authorization¶
Authentication Methods: - Password Hash Synchronization (PHS) - Pass-through Authentication (PTA) - Federated Authentication (ADFS) - Seamless SSO - π Azure AD Authentication Methods - Choosing authentication - π Azure AD Connect - Hybrid identity integration - π Azure AD Connect Health - Monitoring hybrid identity
Conditional Access: - User and group-based policies - Location-based access - Device compliance requirements - Risk-based access control - π Conditional Access Overview - Policy framework - π Conditional Access Policies - Policy design - π Common Conditional Access Policies - Best practices
Multi-Factor Authentication: - π Azure AD MFA - How MFA works - π MFA Deployment Guide - Implementation - π MFA Methods - Available methods
Role-Based Access Control (RBAC)¶
Authorization Model: - Management group, subscription, resource group, resource scopes - Built-in roles vs custom roles - Role assignments (security principal + role + scope) - Deny assignments for Azure Blueprints - π Azure RBAC Overview - Core concepts - π Azure Built-in Roles - Complete role list - π Custom Roles - Creating custom roles - π RBAC Best Practices - Security guidelines
Key Built-in Roles: - Owner - Full access including access management - Contributor - Full access except access management - Reader - View all resources - User Access Administrator - Manage user access only
Governance and Compliance¶
Management Groups: - Hierarchical organization structure - Policy and RBAC inheritance - Up to 6 levels deep (excluding root and subscription) - π Management Groups - Organizational hierarchy - π Management Group Design - Design patterns
Azure Policy: - Enforce organizational standards - Assess compliance at scale - Built-in and custom policy definitions - Policy initiatives (policy sets) - Remediation tasks for non-compliant resources - π Azure Policy Overview - Policy framework - π Policy Definitions - Policy structure - π Policy Assignment Structure - Assignment design - π Built-in Policies - Policy library - π Remediation Tasks - Fixing non-compliance
Azure Blueprints: - Repeatable environment deployment - Artifacts: Resource groups, ARM templates, policies, role assignments - Blueprint versioning and lifecycle - π Azure Blueprints - Environment orchestration - π Blueprint Lifecycle - Version management
Resource Organization: - π Resource Naming Conventions - Naming standards - π Resource Tagging - Tag strategy - π Subscription Organization - Subscription design
Data Storage Architecture¶
Storage Accounts¶
Storage Account Types: - Standard General-purpose v2 - Blobs, files, queues, tables - Premium Block Blobs - High transaction rates, low latency - Premium File Shares - Enterprise file shares - Premium Page Blobs - Managed/unmanaged disks - π Storage Account Overview - Account types - π Storage Account Performance - Standard vs Premium - π Storage Replication - Redundancy options
Redundancy Options: - LRS (Locally Redundant) - 3 copies in single datacenter, 99.999999999% (11 9's) - ZRS (Zone Redundant) - 3 copies across AZs, 99.9999999999% (12 9's) - GRS (Geo-Redundant) - LRS + async copy to secondary region - GZRS (Geo-Zone Redundant) - ZRS + async copy to secondary region - RA-GRS / RA-GZRS - Read access to secondary region - π Azure Storage Redundancy - Complete comparison
Blob Storage: - Access Tiers: - Hot - Frequently accessed, highest storage cost, lowest access cost - Cool - Infrequently accessed, 30-day minimum, lower storage cost - Cold - Rarely accessed, 90-day minimum, even lower storage cost - Archive - Offline, 180-day minimum, lowest storage cost, hours to rehydrate - π Blob Storage Overview - Architecture - π Blob Access Tiers - Tier comparison - π Blob Lifecycle Management - Automated tiering - π Blob Versioning - Version control - π Blob Soft Delete - Data protection - π Blob Immutable Storage - Compliance storage
Azure Files: - SMB and NFS file shares - Lift-and-shift scenarios - Azure File Sync for hybrid scenarios - π Azure Files Overview - Managed file shares - π Azure File Sync - Hybrid file sync - π Azure Files Networking - Private endpoints
Data Lake Storage Gen2: - Hierarchical namespace for big data analytics - Compatible with Hadoop and Spark - POSIX permissions - π Data Lake Storage Gen2 - Big data storage - π Data Lake Access Control - POSIX ACLs
Azure Databases¶
Azure SQL Database: - Fully managed PaaS database - Purchasing models: vCore (predictable) vs DTU (simplified) - Service tiers: General Purpose, Business Critical, Hyperscale - π Azure SQL Database Overview - PaaS database - π SQL Database Purchasing Models - vCore vs DTU - π SQL Database Service Tiers - Tier comparison - π Hyperscale Service Tier - 100TB+ databases - π Elastic Pools - Shared resources
High Availability for Azure SQL: - π SQL Database High Availability - Built-in HA - π Active Geo-Replication - Multi-region read replicas - π Auto-Failover Groups - Automatic failover - π SQL Database Backup - Automated backups
Azure SQL Managed Instance: - Near 100% compatibility with SQL Server - VNet integration, private IP addresses - Instance-level features (SQL Agent, CLR, etc.) - π SQL Managed Instance Overview - Instance features - π SQL MI Connectivity - Network architecture
Azure Cosmos DB: - Globally distributed, multi-model database - Multiple consistency levels - Automatic and manual failover - APIs: Core (SQL), MongoDB, Cassandra, Gremlin, Table - π Azure Cosmos DB Overview - Multi-model database - π Cosmos DB Consistency Levels - Consistency trade-offs - π Cosmos DB Global Distribution - Multi-region replication - π Cosmos DB Partitioning - Partition key design - π Cosmos DB Request Units - Throughput management - π Cosmos DB Pricing - Cost optimization
Azure Database Services: - Azure Database for PostgreSQL - Managed PostgreSQL - π Azure Database for PostgreSQL - PostgreSQL on Azure - Azure Database for MySQL - Managed MySQL - π Azure Database for MySQL - MySQL on Azure - Azure Database for MariaDB - Managed MariaDB - π Azure Database for MariaDB - MariaDB on Azure
Azure Cache for Redis: - In-memory data store - Enterprise, Premium, Basic, Standard tiers - Clustering and geo-replication - π Azure Cache for Redis - Managed Redis - π Redis Cache Tiers - Tier comparison - π Redis Clustering - Scale-out architecture
Data Integration and Analytics¶
Azure Synapse Analytics: - Unified analytics platform - Dedicated SQL pools (data warehouse) - Serverless SQL pools (query on data lake) - Spark pools for big data processing - π Azure Synapse Analytics - Unified analytics - π Synapse SQL Architecture - SQL architecture - π Synapse Spark Pools - Spark processing
Azure Data Factory: - ETL/ELT orchestration - Data integration pipelines - SSIS integration runtime - π Azure Data Factory - Data integration - π Data Factory Pipelines - Pipeline architecture - π Data Factory Mapping Data Flows - Visual ETL
Azure Databricks: - Apache Spark-based analytics platform - Interactive notebooks - MLflow integration - π Azure Databricks - Spark platform
Business Continuity Solutions¶
Backup Solutions¶
Azure Backup: - Centralized backup service - Supports VMs, SQL, SAP HANA, Azure Files - Retention: 9999 days max - π Azure Backup Overview - Backup service - π Azure VM Backup - VM backup architecture - π Backup Policies - Retention and scheduling - π Recovery Services Vault - Vault management
Application-Specific Backup: - π SQL Database Backup - Automated SQL backups - π SQL Server on VM Backup - SQL Server backup - π SAP HANA Backup - SAP HANA on Azure
Disaster Recovery¶
Azure Site Recovery (ASR): - Disaster recovery as a service - VM replication to Azure or secondary region - On-premises to Azure replication - Failover and failback orchestration - π Azure Site Recovery - DR service - π ASR Architecture - Replication architecture - π ASR Networking - Network design for DR - π ASR Recovery Plans - Orchestrated failover
Disaster Recovery Strategies: - Backup and Restore - Lowest cost, highest RTO/RPO - Pilot Light - Minimal resources, scale on failover - Warm Standby - Scaled-down environment always running - Active-Active - Multi-region active workloads
High Availability Architecture¶
Availability Zones: - Physically separate datacenters within region - Zone-redundant services (automatic) - Zonal services (manual placement) - 99.99% SLA with zone redundancy - π Availability Zones - Zone architecture - π Zone-Redundant Services - Service support
Availability Sets: - Fault domains (rack-level separation) - Update domains (maintenance isolation) - 99.95% SLA for 2+ VMs - Legacy option (use Availability Zones when possible) - π Availability Sets - VM availability
Load Balancing: - Azure Load Balancer - Layer 4, regional - Application Gateway - Layer 7, regional, WAF - Azure Front Door - Global Layer 7, WAF, CDN - Traffic Manager - DNS-based global routing - π Load Balancing Decision Tree - Choose load balancer
Infrastructure Solutions¶
Compute Services¶
Azure Virtual Machines: - IaaS compute offering - VM sizes: General purpose, Compute optimized, Memory optimized, Storage optimized, GPU - Spot VMs for up to 90% savings - π Azure Virtual Machines - VM overview - π VM Sizes - Complete size list - π Spot VMs - Interruptible compute - π Reserved Instances - 1 or 3 year commitment
VM Scale Sets: - Autoscaling VM groups - Up to 1,000 VMs (custom images) or 600 (marketplace) - Automatic instance management - π Virtual Machine Scale Sets - Autoscaling VMs - π Scale Set Autoscaling - Scaling rules
Azure App Service: - PaaS for web applications - App Service Plans (pricing tiers) - Auto-scaling, deployment slots - π App Service Overview - PaaS hosting - π App Service Plans - Pricing tiers - π Deployment Slots - Blue-green deployment - π App Service Networking - Network integration
Containers and Orchestration¶
Azure Container Instances (ACI): - Serverless containers - Per-second billing - Fast startup time - π Azure Container Instances - Serverless containers - π ACI Container Groups - Multi-container groups
Azure Kubernetes Service (AKS): - Managed Kubernetes - Free control plane - Integration with Azure services - π Azure Kubernetes Service - Managed Kubernetes - π AKS Architecture - Cluster architecture - π AKS Network Concepts - Network models - π AKS Storage - Persistent volumes - π AKS Scaling - Cluster and pod autoscaling - π AKS Security - Security best practices
Azure Container Registry (ACR): - Private Docker registry - Geo-replication for global distribution - Security scanning - π Azure Container Registry - Container images - π ACR Geo-Replication - Multi-region registry
Azure Container Apps: - Serverless Kubernetes-based platform - Automatic scaling to zero - Managed ingress and certificates - π Azure Container Apps - Serverless containers
Serverless Computing¶
Azure Functions: - Event-driven serverless compute - Consumption, Premium, Dedicated plans - Durable Functions for stateful workflows - π Azure Functions - Serverless functions - π Functions Hosting Plans - Plan comparison - π Durable Functions - Stateful workflows
Azure Logic Apps: - Workflow automation and integration - Designer-based workflow creation - 400+ connectors - π Azure Logic Apps - Workflow automation - π Logic Apps Connectors - Integration connectors
Network Architecture¶
Virtual Networks (VNet): - Address space: RFC 1918 private addresses - Subnets with network security groups - Service endpoints and private endpoints - π Virtual Networks Overview - VNet architecture - π VNet Planning - Design guidance - π Subnet Delegation - Service integration
Network Security Groups (NSG): - Layer 4 firewall (port and protocol) - Inbound and outbound rules - Can be applied to subnet or NIC - π Network Security Groups - Traffic filtering - π NSG Rules - Rule evaluation
Azure Firewall: - Managed stateful firewall - Layer 7 filtering with FQDN tags - Threat intelligence - Standard, Premium tiers - π Azure Firewall - Managed firewall - π Firewall Architecture - Common patterns
Application Gateway: - Layer 7 load balancer - Web Application Firewall (WAF) - SSL termination, URL-based routing - π Application Gateway - Layer 7 load balancer - π Application Gateway Components - Architecture - π Web Application Firewall - WAF features
Azure Front Door: - Global HTTP load balancer - CDN, WAF, DDoS protection - Anycast protocol - π Azure Front Door - Global delivery - π Front Door Routing - Global routing
Traffic Manager: - DNS-based global traffic routing - Routing methods: Priority, Weighted, Performance, Geographic, MultiValue, Subnet - Health monitoring and automatic failover - π Traffic Manager - DNS load balancing - π Routing Methods - Traffic distribution
Virtual Network Peering: - Connect VNets in same or different regions - Low latency, high bandwidth - No gateway required - π VNet Peering - VNet connectivity - π Hub-Spoke Topology - Network design pattern
VPN Gateway: - Site-to-Site, Point-to-Site, VNet-to-VNet - Active-active for high availability - BGP support - π VPN Gateway - VPN connectivity - π VPN Gateway SKUs - Performance tiers - π Highly Available VPN - HA design
ExpressRoute: - Private connection to Azure - 50 Mbps to 100 Gbps - Standard (single region) vs Premium (global) - π ExpressRoute Overview - Private connectivity - π ExpressRoute Connectivity Models - Connection types - π ExpressRoute SKUs - Gateway SKUs
Azure Virtual WAN: - Unified hub-and-spoke architecture - Automated branch connectivity - Global transit network - π Azure Virtual WAN - Global networking - π Virtual WAN Architecture - Hub-spoke design
Private Endpoint and Private Link: - Private IP access to PaaS services - Traffic stays on Microsoft network - No data exfiltration risk - π Azure Private Link - Private connectivity - π Private Endpoints - PaaS private access
Azure DNS: - DNS hosting service - Private DNS zones for internal name resolution - π Azure DNS - Managed DNS - π Private DNS Zones - Internal DNS
Hybrid and Migration Solutions¶
Azure Arc: - Extend Azure management to any infrastructure - Arc-enabled servers, Kubernetes, data services - Unified governance and compliance - π Azure Arc - Hybrid management - π Arc-enabled Servers - Server management - π Arc-enabled Kubernetes - K8s anywhere
Azure Migrate: - Centralized migration hub - Discovery, assessment, and migration - Support for VMs, databases, web apps - π Azure Migrate - Migration service - π Azure Migrate Appliance - Discovery tool
Azure Database Migration Service: - Online and offline database migrations - SQL Server, MySQL, PostgreSQL sources - π Database Migration Service - Database migration
Application Architecture¶
Messaging Services¶
Azure Service Bus: - Enterprise messaging - Queues (point-to-point) and Topics (pub-sub) - Sessions, transactions, dead-letter queues - π Azure Service Bus - Enterprise messaging - π Service Bus Queues - Queues and topics
Azure Event Hubs: - Big data streaming platform - Millions of events per second - Capture to storage or Data Lake - π Azure Event Hubs - Event streaming - π Event Hubs Capture - Stream capture
Azure Event Grid: - Serverless event routing - Publish-subscribe model - Event filtering and routing - π Azure Event Grid - Event routing - π Event Grid Concepts - Architecture
Azure Queue Storage: - Simple queue service - Part of storage account - HTTP/HTTPS access - π Azure Queue Storage - Simple queues
API Management¶
Azure API Management: - API gateway and developer portal - Rate limiting, caching, transformation - OAuth, JWT validation - π API Management - API gateway - π API Management Policies - Request/response policies - π APIM Networking - Network integration
Monitoring and Management¶
Azure Monitor¶
Monitoring Platform: - Metrics and logs - Application Insights for APM - Log Analytics workspace - Alerts and action groups - π Azure Monitor Overview - Monitoring platform - π Azure Monitor Metrics - Time-series data - π Azure Monitor Logs - Log data - π Log Analytics Workspace - Log storage
Application Insights: - Application performance monitoring (APM) - Distributed tracing - Live metrics and profiling - π Application Insights - APM service - π Application Map - Dependency visualization
Alerts and Actions: - Metric, log, and activity log alerts - Action groups (email, SMS, webhook, runbook) - Smart groups for alert aggregation - π Azure Monitor Alerts - Alert types - π Action Groups - Alert actions
Azure Advisor¶
Optimization Recommendations: - Cost, security, reliability, operational excellence, performance - AI-powered recommendations - Free service - π Azure Advisor - Recommendations
Security Monitoring¶
Microsoft Defender for Cloud: - Cloud security posture management (CSPM) - Cloud workload protection platform (CWPP) - Secure score and recommendations - π Microsoft Defender for Cloud - Security center - π Secure Score - Security posture
Azure Sentinel: - Cloud-native SIEM - Security analytics and threat intelligence - Playbooks for automation - π Azure Sentinel - SIEM solution
Cost Optimization¶
Cost Management and Billing¶
Cost Analysis: - Cost breakdown by resource, service, location - Budgets and alerts - Cost allocation with tags - π Cost Management - Cost visibility - π Cost Analysis - Analyze spending - π Budgets - Budget alerts
Pricing Models: - Pay-as-you-go - Reserved Instances (1 or 3 year, up to 72% savings) - Spot VMs (up to 90% savings) - Azure Hybrid Benefit (use existing licenses) - π Azure Pricing Calculator - Estimate costs - π Azure Hybrid Benefit - License portability
Cost Optimization Strategies: - Right-sizing VMs - Scaling and auto-scaling - Storage lifecycle management - Dev/test pricing - Reserved capacity for databases
Common Architecture Patterns¶
Pattern 1: N-Tier Web Application¶
Architecture: - Web Tier: Azure Front Door + App Service or VM Scale Set - Application Tier: App Service or AKS - Data Tier: Azure SQL Database with geo-replication - Caching: Azure Cache for Redis - Storage: Azure Storage for static content
Key Services: - Azure Front Door for global load balancing - Azure CDN for static assets - Application Gateway with WAF - Azure SQL Database with failover groups - Azure Monitor for observability
Pattern 2: Microservices on AKS¶
Architecture: - AKS cluster with multiple node pools - Azure Container Registry for images - Service mesh (Istio/Linkerd) for traffic management - Azure Monitor and Application Insights for observability - Key Vault for secrets
Key Services: - AKS with Azure CNI networking - Azure Load Balancer or Application Gateway - Azure Database for PostgreSQL - Event Hubs for event streaming - Azure DevOps or GitHub Actions for CI/CD
Pattern 3: Event-Driven Serverless¶
Architecture: - Event Grid for event routing - Azure Functions for compute - Service Bus or Event Hubs for messaging - Cosmos DB for state - Logic Apps for workflows
Key Services: - Event Grid subscriptions - Functions with Consumption plan - Cosmos DB with geo-replication - API Management for API gateway
Pattern 4: Big Data Analytics¶
Architecture: - Event Hubs or IoT Hub for ingestion - Azure Synapse Analytics for warehousing - Data Lake Storage Gen2 for raw data - Azure Databricks for processing - Power BI for visualization
Key Services: - Synapse Analytics workspace - Data Factory for orchestration - Azure Purview for data governance
Pattern 5: Hybrid Cloud with Azure Arc¶
Architecture: - Azure Arc-enabled servers for on-premises - VPN Gateway or ExpressRoute for connectivity - Azure Policy for governance - Azure Monitor for unified monitoring - Site Recovery for disaster recovery
Key Services: - Azure Arc - Azure Policy - ExpressRoute with redundancy - Azure Backup and Site Recovery
Security and Compliance¶
Data Protection¶
Encryption: - Encryption at rest (Azure Storage Service Encryption) - Encryption in transit (TLS 1.2+) - Azure Key Vault for key management - Customer-managed keys (CMK) - π Azure Encryption Overview - Data protection - π Azure Key Vault - Key management - π Key Vault Best Practices - Security guidelines
Azure Information Protection: - Classify and label sensitive data - Encrypt and protect documents - π Azure Information Protection - Data classification
Network Security¶
Defense in Depth: - Network Security Groups (NSG) - Azure Firewall or Network Virtual Appliances - DDoS Protection Standard - Application Gateway with WAF - π Azure DDoS Protection - DDoS mitigation - π Network Security Best Practices - Network security
Compliance¶
Compliance Offerings: - ISO 27001, SOC ½/3, HIPAA, GDPR, FedRAMP - Azure Compliance Manager - Regional compliance (data residency) - π Azure Compliance - Compliance offerings - π Microsoft Compliance Manager - Compliance assessment
Migration Strategies¶
Assessment and Planning¶
Azure Migrate Hub: - Discovery and assessment - Dependency mapping - Right-sizing recommendations - π Azure Migrate Assessment - Assessment methodology
Migration Approaches (5 Rs)¶
Migration Strategies: 1. Rehost - Lift-and-shift to VMs 2. Refactor - Containerize or use PaaS 3. Rearchitect - Cloud-native redesign 4. Rebuild - Rebuild from scratch 5. Replace - SaaS solutions
Migration Tools: - Azure Migrate for VMs - Database Migration Service for databases - Azure Data Box for large data transfers - Azure Import/Export service
Exam Scenarios and Decision Trees¶
Scenario 1: Identity Solution Selection¶
Decision Tree:
Need directory services?
ββ Cloud-only β Azure AD (Entra ID)
ββ Hybrid (AD + Azure AD) β Azure AD Connect
ββ Lift-and-shift domain controllers β Azure AD Domain Services
Scenario 2: Database Selection¶
Decision Tree:
Relational needed?
ββ YES β SQL Server compatibility?
β ββ 100% compatibility β SQL Managed Instance
β ββ Modern cloud features β Azure SQL Database
β ββ Other RDBMS β Azure Database for PostgreSQL/MySQL
ββ NO β Data model?
ββ Multi-model, global distribution β Cosmos DB
ββ Cache β Azure Cache for Redis
ββ Analytics β Synapse Analytics
Scenario 3: Compute Selection¶
Decision Tree:
Container-based?
ββ YES β Orchestration needed?
β ββ YES (Kubernetes) β AKS
β ββ NO (simple) β Container Instances
β ββ Serverless β Container Apps
ββ NO β Code-based?
ββ YES β Event-driven?
β ββ YES β Azure Functions
β ββ NO β App Service
ββ NO β Virtual Machines
Scenario 4: Load Balancing Selection¶
Decision Tree:
Layer 7 or Layer 4?
ββ Layer 7 (HTTP/HTTPS) β Scope?
β ββ Global β Azure Front Door
β ββ Regional with WAF β Application Gateway
β ββ DNS-based β Traffic Manager
ββ Layer 4 (TCP/UDP) β Azure Load Balancer
Key Numbers to Memorize¶
Service Limits: - Azure Functions: 10 min default (30 min max on Premium), 1.5 GB memory default - Storage Account: 5 PB max capacity, 20,000 IOPS (standard), 500 TB per blob - VNet: 65,536 IPs per VNet, 500 VNets per subscription (default) - Azure SQL Database: 4 TB (General Purpose), 100 TB (Hyperscale) - VM Scale Sets: 1,000 VMs (custom images), 600 (marketplace)
SLA Numbers: - Single VM with Premium SSD: 99.9% - Availability Set: 99.95% - Availability Zones: 99.99% - Multi-region with Traffic Manager: 99.99%+
Retention Periods: - Azure Backup: 9999 days maximum - SQL Database automated backups: 7-35 days (default 7) - Activity Log: 90 days - Log Analytics: 30 days to 730 days
Exam Tips and Strategy¶
Question Analysis Keywords¶
Watch for these keywords: - "Most cost-effective" β Spot VMs, Reserved Instances, storage tiers, auto-scaling - "Least administrative effort" β PaaS over IaaS, managed services, serverless - "High availability" β Availability Zones, geo-replication, load balancing - "Disaster recovery" β Site Recovery, geo-redundant storage, backup - "Security" β Private endpoints, NSGs, Azure Firewall, encryption - "Hybrid" β ExpressRoute, VPN Gateway, Azure Arc, AD Connect - "Real-time" β Event Hubs, Stream Analytics, Azure Functions - "Compliance" β Azure Policy, Blueprints, encryption, audit logs
Time Management¶
- 120 minutes Γ· 50 questions = 2.4 minutes per question
- Case studies: 10-15 minutes per case (3-5 questions each)
- Multiple choice: 1-2 minutes each
- First pass: Answer confident questions (60 minutes)
- Second pass: Review flagged questions (50 minutes)
- Final pass: Review all answers (10 minutes)
Common Traps¶
- β Choosing IaaS when PaaS is appropriate
- β Over-engineering solutions
- β Ignoring cost constraints
- β Missing "hybrid" requirements
- β Confusing service capabilities (tiers, limits)
- β Not considering operational overhead
- β Forgetting about compliance requirements
Study Checklist¶
Technical Knowledge: - [ ] Understand Azure AD vs Azure AD DS vs AD Connect - [ ] Know all load balancing options and when to use each - [ ] Can design multi-region architectures - [ ] Understand VNet peering, VPN, ExpressRoute trade-offs - [ ] Know database options and selection criteria - [ ] Understand Azure Policy, RBAC, Management Groups - [ ] Can design backup and disaster recovery solutions - [ ] Familiar with all compute options (VMs, App Service, AKS, Functions) - [ ] Know storage types and redundancy options - [ ] Understand monitoring and logging architecture
Preparation: - [ ] Hands-on experience with Azure (build projects) - [ ] Read Azure Well-Architected Framework - [ ] Review Azure Architecture Center patterns - [ ] Complete practice exams (80%+ score) - [ ] Understand cost optimization strategies - [ ] Practice designing solutions on paper/whiteboard
Pro Tip: AZ-305 tests your ability to design complete solutions balancing cost, security, performance, and operational overhead. Always read the entire scenario, identify all constraints, and choose the solution that best meets ALL requirements - not just technically correct, but most appropriate for the business context.
Documentation Count: This fact sheet contains 115+ embedded documentation links to official Microsoft Learn and Azure documentation.
Good luck! This certification demonstrates expert-level Azure architecture skills and is highly valued in the industry.