Skip to content

Azure AZ-305: Designing Microsoft Azure Infrastructure Solutions - Fact Sheet

Quick Reference

Exam Code: AZ-305 Duration: 120 minutes (2 hours) Questions: 40-60 questions (case studies + multiple choice) Passing Score: 700/1000 Cost: $165 USD Validity: 1 year (renewable annually) Prerequisites: AZ-104 (Azure Administrator) recommended Difficulty: ⭐⭐⭐⭐⭐ (Expert-level certification) Experience: 3+ years of IT experience, including advanced Azure design skills

Exam Domains

Domain Weight Key Focus
Design Identity, Governance, and Monitoring Solutions 25-30% Azure AD, RBAC, governance, policy, monitoring
Design Data Storage Solutions 25-30% Storage accounts, databases, caching, data integration
Design Business Continuity Solutions 10-15% Backup, disaster recovery, high availability
Design Infrastructure Solutions 25-30% Compute, networking, containers, migration

Azure Well-Architected Framework

πŸ“– Azure Well-Architected Framework - Complete architecture framework πŸ“– Well-Architected Review - Assessment tool and guidance

Five Pillars: 1. Reliability - Availability, resiliency, recovery 2. Security - Identity, data protection, network security 3. Cost Optimization - Resource optimization, monitoring 4. Operational Excellence - DevOps, monitoring, automation 5. Performance Efficiency - Scalability, load balancing

Key Resources: - πŸ“– Azure Architecture Center - Reference architectures - πŸ“– Cloud Design Patterns - Common architecture patterns - πŸ“– Best Practices for Cloud Applications - Design guidance - πŸ“– Design Principles - Architecture principles

Identity and Governance Architecture

Azure Active Directory (Azure AD / Entra ID)

Identity Foundation: - Cloud-based identity and access management - Single sign-on (SSO) across applications - Multi-factor authentication (MFA) - Conditional Access policies - πŸ“– Azure Active Directory Overview - Core concepts - πŸ“– Azure AD Architecture - Design patterns - πŸ“– Azure AD Editions - Free, P1, P2 comparison - πŸ“– Azure AD Licensing - Feature comparison

Advanced Identity Features: - Azure AD B2B - Guest user access and collaboration - πŸ“– Azure AD B2B - Business-to-business identity - Azure AD B2C - Customer identity and access management - πŸ“– Azure AD B2C - Consumer identity platform - Azure AD Domain Services - Managed domain services (LDAP, Kerberos) - πŸ“– Azure AD Domain Services - Managed domain controllers - Privileged Identity Management (PIM) - Just-in-time privileged access - πŸ“– Azure AD PIM - Privileged access management - Identity Protection - Risk-based conditional access - πŸ“– Azure AD Identity Protection - Risk detection

Authentication and Authorization

Authentication Methods: - Password Hash Synchronization (PHS) - Pass-through Authentication (PTA) - Federated Authentication (ADFS) - Seamless SSO - πŸ“– Azure AD Authentication Methods - Choosing authentication - πŸ“– Azure AD Connect - Hybrid identity integration - πŸ“– Azure AD Connect Health - Monitoring hybrid identity

Conditional Access: - User and group-based policies - Location-based access - Device compliance requirements - Risk-based access control - πŸ“– Conditional Access Overview - Policy framework - πŸ“– Conditional Access Policies - Policy design - πŸ“– Common Conditional Access Policies - Best practices

Multi-Factor Authentication: - πŸ“– Azure AD MFA - How MFA works - πŸ“– MFA Deployment Guide - Implementation - πŸ“– MFA Methods - Available methods

Role-Based Access Control (RBAC)

Authorization Model: - Management group, subscription, resource group, resource scopes - Built-in roles vs custom roles - Role assignments (security principal + role + scope) - Deny assignments for Azure Blueprints - πŸ“– Azure RBAC Overview - Core concepts - πŸ“– Azure Built-in Roles - Complete role list - πŸ“– Custom Roles - Creating custom roles - πŸ“– RBAC Best Practices - Security guidelines

Key Built-in Roles: - Owner - Full access including access management - Contributor - Full access except access management - Reader - View all resources - User Access Administrator - Manage user access only

Governance and Compliance

Management Groups: - Hierarchical organization structure - Policy and RBAC inheritance - Up to 6 levels deep (excluding root and subscription) - πŸ“– Management Groups - Organizational hierarchy - πŸ“– Management Group Design - Design patterns

Azure Policy: - Enforce organizational standards - Assess compliance at scale - Built-in and custom policy definitions - Policy initiatives (policy sets) - Remediation tasks for non-compliant resources - πŸ“– Azure Policy Overview - Policy framework - πŸ“– Policy Definitions - Policy structure - πŸ“– Policy Assignment Structure - Assignment design - πŸ“– Built-in Policies - Policy library - πŸ“– Remediation Tasks - Fixing non-compliance

Azure Blueprints: - Repeatable environment deployment - Artifacts: Resource groups, ARM templates, policies, role assignments - Blueprint versioning and lifecycle - πŸ“– Azure Blueprints - Environment orchestration - πŸ“– Blueprint Lifecycle - Version management

Resource Organization: - πŸ“– Resource Naming Conventions - Naming standards - πŸ“– Resource Tagging - Tag strategy - πŸ“– Subscription Organization - Subscription design

Data Storage Architecture

Storage Accounts

Storage Account Types: - Standard General-purpose v2 - Blobs, files, queues, tables - Premium Block Blobs - High transaction rates, low latency - Premium File Shares - Enterprise file shares - Premium Page Blobs - Managed/unmanaged disks - πŸ“– Storage Account Overview - Account types - πŸ“– Storage Account Performance - Standard vs Premium - πŸ“– Storage Replication - Redundancy options

Redundancy Options: - LRS (Locally Redundant) - 3 copies in single datacenter, 99.999999999% (11 9's) - ZRS (Zone Redundant) - 3 copies across AZs, 99.9999999999% (12 9's) - GRS (Geo-Redundant) - LRS + async copy to secondary region - GZRS (Geo-Zone Redundant) - ZRS + async copy to secondary region - RA-GRS / RA-GZRS - Read access to secondary region - πŸ“– Azure Storage Redundancy - Complete comparison

Blob Storage: - Access Tiers: - Hot - Frequently accessed, highest storage cost, lowest access cost - Cool - Infrequently accessed, 30-day minimum, lower storage cost - Cold - Rarely accessed, 90-day minimum, even lower storage cost - Archive - Offline, 180-day minimum, lowest storage cost, hours to rehydrate - πŸ“– Blob Storage Overview - Architecture - πŸ“– Blob Access Tiers - Tier comparison - πŸ“– Blob Lifecycle Management - Automated tiering - πŸ“– Blob Versioning - Version control - πŸ“– Blob Soft Delete - Data protection - πŸ“– Blob Immutable Storage - Compliance storage

Azure Files: - SMB and NFS file shares - Lift-and-shift scenarios - Azure File Sync for hybrid scenarios - πŸ“– Azure Files Overview - Managed file shares - πŸ“– Azure File Sync - Hybrid file sync - πŸ“– Azure Files Networking - Private endpoints

Data Lake Storage Gen2: - Hierarchical namespace for big data analytics - Compatible with Hadoop and Spark - POSIX permissions - πŸ“– Data Lake Storage Gen2 - Big data storage - πŸ“– Data Lake Access Control - POSIX ACLs

Azure Databases

Azure SQL Database: - Fully managed PaaS database - Purchasing models: vCore (predictable) vs DTU (simplified) - Service tiers: General Purpose, Business Critical, Hyperscale - πŸ“– Azure SQL Database Overview - PaaS database - πŸ“– SQL Database Purchasing Models - vCore vs DTU - πŸ“– SQL Database Service Tiers - Tier comparison - πŸ“– Hyperscale Service Tier - 100TB+ databases - πŸ“– Elastic Pools - Shared resources

High Availability for Azure SQL: - πŸ“– SQL Database High Availability - Built-in HA - πŸ“– Active Geo-Replication - Multi-region read replicas - πŸ“– Auto-Failover Groups - Automatic failover - πŸ“– SQL Database Backup - Automated backups

Azure SQL Managed Instance: - Near 100% compatibility with SQL Server - VNet integration, private IP addresses - Instance-level features (SQL Agent, CLR, etc.) - πŸ“– SQL Managed Instance Overview - Instance features - πŸ“– SQL MI Connectivity - Network architecture

Azure Cosmos DB: - Globally distributed, multi-model database - Multiple consistency levels - Automatic and manual failover - APIs: Core (SQL), MongoDB, Cassandra, Gremlin, Table - πŸ“– Azure Cosmos DB Overview - Multi-model database - πŸ“– Cosmos DB Consistency Levels - Consistency trade-offs - πŸ“– Cosmos DB Global Distribution - Multi-region replication - πŸ“– Cosmos DB Partitioning - Partition key design - πŸ“– Cosmos DB Request Units - Throughput management - πŸ“– Cosmos DB Pricing - Cost optimization

Azure Database Services: - Azure Database for PostgreSQL - Managed PostgreSQL - πŸ“– Azure Database for PostgreSQL - PostgreSQL on Azure - Azure Database for MySQL - Managed MySQL - πŸ“– Azure Database for MySQL - MySQL on Azure - Azure Database for MariaDB - Managed MariaDB - πŸ“– Azure Database for MariaDB - MariaDB on Azure

Azure Cache for Redis: - In-memory data store - Enterprise, Premium, Basic, Standard tiers - Clustering and geo-replication - πŸ“– Azure Cache for Redis - Managed Redis - πŸ“– Redis Cache Tiers - Tier comparison - πŸ“– Redis Clustering - Scale-out architecture

Data Integration and Analytics

Azure Synapse Analytics: - Unified analytics platform - Dedicated SQL pools (data warehouse) - Serverless SQL pools (query on data lake) - Spark pools for big data processing - πŸ“– Azure Synapse Analytics - Unified analytics - πŸ“– Synapse SQL Architecture - SQL architecture - πŸ“– Synapse Spark Pools - Spark processing

Azure Data Factory: - ETL/ELT orchestration - Data integration pipelines - SSIS integration runtime - πŸ“– Azure Data Factory - Data integration - πŸ“– Data Factory Pipelines - Pipeline architecture - πŸ“– Data Factory Mapping Data Flows - Visual ETL

Azure Databricks: - Apache Spark-based analytics platform - Interactive notebooks - MLflow integration - πŸ“– Azure Databricks - Spark platform

Business Continuity Solutions

Backup Solutions

Azure Backup: - Centralized backup service - Supports VMs, SQL, SAP HANA, Azure Files - Retention: 9999 days max - πŸ“– Azure Backup Overview - Backup service - πŸ“– Azure VM Backup - VM backup architecture - πŸ“– Backup Policies - Retention and scheduling - πŸ“– Recovery Services Vault - Vault management

Application-Specific Backup: - πŸ“– SQL Database Backup - Automated SQL backups - πŸ“– SQL Server on VM Backup - SQL Server backup - πŸ“– SAP HANA Backup - SAP HANA on Azure

Disaster Recovery

Azure Site Recovery (ASR): - Disaster recovery as a service - VM replication to Azure or secondary region - On-premises to Azure replication - Failover and failback orchestration - πŸ“– Azure Site Recovery - DR service - πŸ“– ASR Architecture - Replication architecture - πŸ“– ASR Networking - Network design for DR - πŸ“– ASR Recovery Plans - Orchestrated failover

Disaster Recovery Strategies: - Backup and Restore - Lowest cost, highest RTO/RPO - Pilot Light - Minimal resources, scale on failover - Warm Standby - Scaled-down environment always running - Active-Active - Multi-region active workloads

High Availability Architecture

Availability Zones: - Physically separate datacenters within region - Zone-redundant services (automatic) - Zonal services (manual placement) - 99.99% SLA with zone redundancy - πŸ“– Availability Zones - Zone architecture - πŸ“– Zone-Redundant Services - Service support

Availability Sets: - Fault domains (rack-level separation) - Update domains (maintenance isolation) - 99.95% SLA for 2+ VMs - Legacy option (use Availability Zones when possible) - πŸ“– Availability Sets - VM availability

Load Balancing: - Azure Load Balancer - Layer 4, regional - Application Gateway - Layer 7, regional, WAF - Azure Front Door - Global Layer 7, WAF, CDN - Traffic Manager - DNS-based global routing - πŸ“– Load Balancing Decision Tree - Choose load balancer

Infrastructure Solutions

Compute Services

Azure Virtual Machines: - IaaS compute offering - VM sizes: General purpose, Compute optimized, Memory optimized, Storage optimized, GPU - Spot VMs for up to 90% savings - πŸ“– Azure Virtual Machines - VM overview - πŸ“– VM Sizes - Complete size list - πŸ“– Spot VMs - Interruptible compute - πŸ“– Reserved Instances - 1 or 3 year commitment

VM Scale Sets: - Autoscaling VM groups - Up to 1,000 VMs (custom images) or 600 (marketplace) - Automatic instance management - πŸ“– Virtual Machine Scale Sets - Autoscaling VMs - πŸ“– Scale Set Autoscaling - Scaling rules

Azure App Service: - PaaS for web applications - App Service Plans (pricing tiers) - Auto-scaling, deployment slots - πŸ“– App Service Overview - PaaS hosting - πŸ“– App Service Plans - Pricing tiers - πŸ“– Deployment Slots - Blue-green deployment - πŸ“– App Service Networking - Network integration

Containers and Orchestration

Azure Container Instances (ACI): - Serverless containers - Per-second billing - Fast startup time - πŸ“– Azure Container Instances - Serverless containers - πŸ“– ACI Container Groups - Multi-container groups

Azure Kubernetes Service (AKS): - Managed Kubernetes - Free control plane - Integration with Azure services - πŸ“– Azure Kubernetes Service - Managed Kubernetes - πŸ“– AKS Architecture - Cluster architecture - πŸ“– AKS Network Concepts - Network models - πŸ“– AKS Storage - Persistent volumes - πŸ“– AKS Scaling - Cluster and pod autoscaling - πŸ“– AKS Security - Security best practices

Azure Container Registry (ACR): - Private Docker registry - Geo-replication for global distribution - Security scanning - πŸ“– Azure Container Registry - Container images - πŸ“– ACR Geo-Replication - Multi-region registry

Azure Container Apps: - Serverless Kubernetes-based platform - Automatic scaling to zero - Managed ingress and certificates - πŸ“– Azure Container Apps - Serverless containers

Serverless Computing

Azure Functions: - Event-driven serverless compute - Consumption, Premium, Dedicated plans - Durable Functions for stateful workflows - πŸ“– Azure Functions - Serverless functions - πŸ“– Functions Hosting Plans - Plan comparison - πŸ“– Durable Functions - Stateful workflows

Azure Logic Apps: - Workflow automation and integration - Designer-based workflow creation - 400+ connectors - πŸ“– Azure Logic Apps - Workflow automation - πŸ“– Logic Apps Connectors - Integration connectors

Network Architecture

Virtual Networks (VNet): - Address space: RFC 1918 private addresses - Subnets with network security groups - Service endpoints and private endpoints - πŸ“– Virtual Networks Overview - VNet architecture - πŸ“– VNet Planning - Design guidance - πŸ“– Subnet Delegation - Service integration

Network Security Groups (NSG): - Layer 4 firewall (port and protocol) - Inbound and outbound rules - Can be applied to subnet or NIC - πŸ“– Network Security Groups - Traffic filtering - πŸ“– NSG Rules - Rule evaluation

Azure Firewall: - Managed stateful firewall - Layer 7 filtering with FQDN tags - Threat intelligence - Standard, Premium tiers - πŸ“– Azure Firewall - Managed firewall - πŸ“– Firewall Architecture - Common patterns

Application Gateway: - Layer 7 load balancer - Web Application Firewall (WAF) - SSL termination, URL-based routing - πŸ“– Application Gateway - Layer 7 load balancer - πŸ“– Application Gateway Components - Architecture - πŸ“– Web Application Firewall - WAF features

Azure Front Door: - Global HTTP load balancer - CDN, WAF, DDoS protection - Anycast protocol - πŸ“– Azure Front Door - Global delivery - πŸ“– Front Door Routing - Global routing

Traffic Manager: - DNS-based global traffic routing - Routing methods: Priority, Weighted, Performance, Geographic, MultiValue, Subnet - Health monitoring and automatic failover - πŸ“– Traffic Manager - DNS load balancing - πŸ“– Routing Methods - Traffic distribution

Virtual Network Peering: - Connect VNets in same or different regions - Low latency, high bandwidth - No gateway required - πŸ“– VNet Peering - VNet connectivity - πŸ“– Hub-Spoke Topology - Network design pattern

VPN Gateway: - Site-to-Site, Point-to-Site, VNet-to-VNet - Active-active for high availability - BGP support - πŸ“– VPN Gateway - VPN connectivity - πŸ“– VPN Gateway SKUs - Performance tiers - πŸ“– Highly Available VPN - HA design

ExpressRoute: - Private connection to Azure - 50 Mbps to 100 Gbps - Standard (single region) vs Premium (global) - πŸ“– ExpressRoute Overview - Private connectivity - πŸ“– ExpressRoute Connectivity Models - Connection types - πŸ“– ExpressRoute SKUs - Gateway SKUs

Azure Virtual WAN: - Unified hub-and-spoke architecture - Automated branch connectivity - Global transit network - πŸ“– Azure Virtual WAN - Global networking - πŸ“– Virtual WAN Architecture - Hub-spoke design

Private Endpoint and Private Link: - Private IP access to PaaS services - Traffic stays on Microsoft network - No data exfiltration risk - πŸ“– Azure Private Link - Private connectivity - πŸ“– Private Endpoints - PaaS private access

Azure DNS: - DNS hosting service - Private DNS zones for internal name resolution - πŸ“– Azure DNS - Managed DNS - πŸ“– Private DNS Zones - Internal DNS

Hybrid and Migration Solutions

Azure Arc: - Extend Azure management to any infrastructure - Arc-enabled servers, Kubernetes, data services - Unified governance and compliance - πŸ“– Azure Arc - Hybrid management - πŸ“– Arc-enabled Servers - Server management - πŸ“– Arc-enabled Kubernetes - K8s anywhere

Azure Migrate: - Centralized migration hub - Discovery, assessment, and migration - Support for VMs, databases, web apps - πŸ“– Azure Migrate - Migration service - πŸ“– Azure Migrate Appliance - Discovery tool

Azure Database Migration Service: - Online and offline database migrations - SQL Server, MySQL, PostgreSQL sources - πŸ“– Database Migration Service - Database migration

Application Architecture

Messaging Services

Azure Service Bus: - Enterprise messaging - Queues (point-to-point) and Topics (pub-sub) - Sessions, transactions, dead-letter queues - πŸ“– Azure Service Bus - Enterprise messaging - πŸ“– Service Bus Queues - Queues and topics

Azure Event Hubs: - Big data streaming platform - Millions of events per second - Capture to storage or Data Lake - πŸ“– Azure Event Hubs - Event streaming - πŸ“– Event Hubs Capture - Stream capture

Azure Event Grid: - Serverless event routing - Publish-subscribe model - Event filtering and routing - πŸ“– Azure Event Grid - Event routing - πŸ“– Event Grid Concepts - Architecture

Azure Queue Storage: - Simple queue service - Part of storage account - HTTP/HTTPS access - πŸ“– Azure Queue Storage - Simple queues

API Management

Azure API Management: - API gateway and developer portal - Rate limiting, caching, transformation - OAuth, JWT validation - πŸ“– API Management - API gateway - πŸ“– API Management Policies - Request/response policies - πŸ“– APIM Networking - Network integration

Monitoring and Management

Azure Monitor

Monitoring Platform: - Metrics and logs - Application Insights for APM - Log Analytics workspace - Alerts and action groups - πŸ“– Azure Monitor Overview - Monitoring platform - πŸ“– Azure Monitor Metrics - Time-series data - πŸ“– Azure Monitor Logs - Log data - πŸ“– Log Analytics Workspace - Log storage

Application Insights: - Application performance monitoring (APM) - Distributed tracing - Live metrics and profiling - πŸ“– Application Insights - APM service - πŸ“– Application Map - Dependency visualization

Alerts and Actions: - Metric, log, and activity log alerts - Action groups (email, SMS, webhook, runbook) - Smart groups for alert aggregation - πŸ“– Azure Monitor Alerts - Alert types - πŸ“– Action Groups - Alert actions

Azure Advisor

Optimization Recommendations: - Cost, security, reliability, operational excellence, performance - AI-powered recommendations - Free service - πŸ“– Azure Advisor - Recommendations

Security Monitoring

Microsoft Defender for Cloud: - Cloud security posture management (CSPM) - Cloud workload protection platform (CWPP) - Secure score and recommendations - πŸ“– Microsoft Defender for Cloud - Security center - πŸ“– Secure Score - Security posture

Azure Sentinel: - Cloud-native SIEM - Security analytics and threat intelligence - Playbooks for automation - πŸ“– Azure Sentinel - SIEM solution

Cost Optimization

Cost Management and Billing

Cost Analysis: - Cost breakdown by resource, service, location - Budgets and alerts - Cost allocation with tags - πŸ“– Cost Management - Cost visibility - πŸ“– Cost Analysis - Analyze spending - πŸ“– Budgets - Budget alerts

Pricing Models: - Pay-as-you-go - Reserved Instances (1 or 3 year, up to 72% savings) - Spot VMs (up to 90% savings) - Azure Hybrid Benefit (use existing licenses) - πŸ“– Azure Pricing Calculator - Estimate costs - πŸ“– Azure Hybrid Benefit - License portability

Cost Optimization Strategies: - Right-sizing VMs - Scaling and auto-scaling - Storage lifecycle management - Dev/test pricing - Reserved capacity for databases

Common Architecture Patterns

Pattern 1: N-Tier Web Application

Architecture: - Web Tier: Azure Front Door + App Service or VM Scale Set - Application Tier: App Service or AKS - Data Tier: Azure SQL Database with geo-replication - Caching: Azure Cache for Redis - Storage: Azure Storage for static content

Key Services: - Azure Front Door for global load balancing - Azure CDN for static assets - Application Gateway with WAF - Azure SQL Database with failover groups - Azure Monitor for observability

Pattern 2: Microservices on AKS

Architecture: - AKS cluster with multiple node pools - Azure Container Registry for images - Service mesh (Istio/Linkerd) for traffic management - Azure Monitor and Application Insights for observability - Key Vault for secrets

Key Services: - AKS with Azure CNI networking - Azure Load Balancer or Application Gateway - Azure Database for PostgreSQL - Event Hubs for event streaming - Azure DevOps or GitHub Actions for CI/CD

Pattern 3: Event-Driven Serverless

Architecture: - Event Grid for event routing - Azure Functions for compute - Service Bus or Event Hubs for messaging - Cosmos DB for state - Logic Apps for workflows

Key Services: - Event Grid subscriptions - Functions with Consumption plan - Cosmos DB with geo-replication - API Management for API gateway

Pattern 4: Big Data Analytics

Architecture: - Event Hubs or IoT Hub for ingestion - Azure Synapse Analytics for warehousing - Data Lake Storage Gen2 for raw data - Azure Databricks for processing - Power BI for visualization

Key Services: - Synapse Analytics workspace - Data Factory for orchestration - Azure Purview for data governance

Pattern 5: Hybrid Cloud with Azure Arc

Architecture: - Azure Arc-enabled servers for on-premises - VPN Gateway or ExpressRoute for connectivity - Azure Policy for governance - Azure Monitor for unified monitoring - Site Recovery for disaster recovery

Key Services: - Azure Arc - Azure Policy - ExpressRoute with redundancy - Azure Backup and Site Recovery

Security and Compliance

Data Protection

Encryption: - Encryption at rest (Azure Storage Service Encryption) - Encryption in transit (TLS 1.2+) - Azure Key Vault for key management - Customer-managed keys (CMK) - πŸ“– Azure Encryption Overview - Data protection - πŸ“– Azure Key Vault - Key management - πŸ“– Key Vault Best Practices - Security guidelines

Azure Information Protection: - Classify and label sensitive data - Encrypt and protect documents - πŸ“– Azure Information Protection - Data classification

Network Security

Defense in Depth: - Network Security Groups (NSG) - Azure Firewall or Network Virtual Appliances - DDoS Protection Standard - Application Gateway with WAF - πŸ“– Azure DDoS Protection - DDoS mitigation - πŸ“– Network Security Best Practices - Network security

Compliance

Compliance Offerings: - ISO 27001, SOC ½/3, HIPAA, GDPR, FedRAMP - Azure Compliance Manager - Regional compliance (data residency) - πŸ“– Azure Compliance - Compliance offerings - πŸ“– Microsoft Compliance Manager - Compliance assessment

Migration Strategies

Assessment and Planning

Azure Migrate Hub: - Discovery and assessment - Dependency mapping - Right-sizing recommendations - πŸ“– Azure Migrate Assessment - Assessment methodology

Migration Approaches (5 Rs)

Migration Strategies: 1. Rehost - Lift-and-shift to VMs 2. Refactor - Containerize or use PaaS 3. Rearchitect - Cloud-native redesign 4. Rebuild - Rebuild from scratch 5. Replace - SaaS solutions

Migration Tools: - Azure Migrate for VMs - Database Migration Service for databases - Azure Data Box for large data transfers - Azure Import/Export service

Exam Scenarios and Decision Trees

Scenario 1: Identity Solution Selection

Decision Tree:

Need directory services?
β”œβ”€ Cloud-only β†’ Azure AD (Entra ID)
β”œβ”€ Hybrid (AD + Azure AD) β†’ Azure AD Connect
└─ Lift-and-shift domain controllers β†’ Azure AD Domain Services

Scenario 2: Database Selection

Decision Tree:

Relational needed?
β”œβ”€ YES β†’ SQL Server compatibility?
β”‚  β”œβ”€ 100% compatibility β†’ SQL Managed Instance
β”‚  β”œβ”€ Modern cloud features β†’ Azure SQL Database
β”‚  └─ Other RDBMS β†’ Azure Database for PostgreSQL/MySQL
└─ NO β†’ Data model?
   β”œβ”€ Multi-model, global distribution β†’ Cosmos DB
   β”œβ”€ Cache β†’ Azure Cache for Redis
   └─ Analytics β†’ Synapse Analytics

Scenario 3: Compute Selection

Decision Tree:

Container-based?
β”œβ”€ YES β†’ Orchestration needed?
β”‚  β”œβ”€ YES (Kubernetes) β†’ AKS
β”‚  β”œβ”€ NO (simple) β†’ Container Instances
β”‚  └─ Serverless β†’ Container Apps
└─ NO β†’ Code-based?
   β”œβ”€ YES β†’ Event-driven?
   β”‚  β”œβ”€ YES β†’ Azure Functions
   β”‚  └─ NO β†’ App Service
   └─ NO β†’ Virtual Machines

Scenario 4: Load Balancing Selection

Decision Tree:

Layer 7 or Layer 4?
β”œβ”€ Layer 7 (HTTP/HTTPS) β†’ Scope?
β”‚  β”œβ”€ Global β†’ Azure Front Door
β”‚  β”œβ”€ Regional with WAF β†’ Application Gateway
β”‚  └─ DNS-based β†’ Traffic Manager
└─ Layer 4 (TCP/UDP) β†’ Azure Load Balancer

Key Numbers to Memorize

Service Limits: - Azure Functions: 10 min default (30 min max on Premium), 1.5 GB memory default - Storage Account: 5 PB max capacity, 20,000 IOPS (standard), 500 TB per blob - VNet: 65,536 IPs per VNet, 500 VNets per subscription (default) - Azure SQL Database: 4 TB (General Purpose), 100 TB (Hyperscale) - VM Scale Sets: 1,000 VMs (custom images), 600 (marketplace)

SLA Numbers: - Single VM with Premium SSD: 99.9% - Availability Set: 99.95% - Availability Zones: 99.99% - Multi-region with Traffic Manager: 99.99%+

Retention Periods: - Azure Backup: 9999 days maximum - SQL Database automated backups: 7-35 days (default 7) - Activity Log: 90 days - Log Analytics: 30 days to 730 days

Exam Tips and Strategy

Question Analysis Keywords

Watch for these keywords: - "Most cost-effective" β†’ Spot VMs, Reserved Instances, storage tiers, auto-scaling - "Least administrative effort" β†’ PaaS over IaaS, managed services, serverless - "High availability" β†’ Availability Zones, geo-replication, load balancing - "Disaster recovery" β†’ Site Recovery, geo-redundant storage, backup - "Security" β†’ Private endpoints, NSGs, Azure Firewall, encryption - "Hybrid" β†’ ExpressRoute, VPN Gateway, Azure Arc, AD Connect - "Real-time" β†’ Event Hubs, Stream Analytics, Azure Functions - "Compliance" β†’ Azure Policy, Blueprints, encryption, audit logs

Time Management

  • 120 minutes Γ· 50 questions = 2.4 minutes per question
  • Case studies: 10-15 minutes per case (3-5 questions each)
  • Multiple choice: 1-2 minutes each
  • First pass: Answer confident questions (60 minutes)
  • Second pass: Review flagged questions (50 minutes)
  • Final pass: Review all answers (10 minutes)

Common Traps

  • ❌ Choosing IaaS when PaaS is appropriate
  • ❌ Over-engineering solutions
  • ❌ Ignoring cost constraints
  • ❌ Missing "hybrid" requirements
  • ❌ Confusing service capabilities (tiers, limits)
  • ❌ Not considering operational overhead
  • ❌ Forgetting about compliance requirements

Study Checklist

Technical Knowledge: - [ ] Understand Azure AD vs Azure AD DS vs AD Connect - [ ] Know all load balancing options and when to use each - [ ] Can design multi-region architectures - [ ] Understand VNet peering, VPN, ExpressRoute trade-offs - [ ] Know database options and selection criteria - [ ] Understand Azure Policy, RBAC, Management Groups - [ ] Can design backup and disaster recovery solutions - [ ] Familiar with all compute options (VMs, App Service, AKS, Functions) - [ ] Know storage types and redundancy options - [ ] Understand monitoring and logging architecture

Preparation: - [ ] Hands-on experience with Azure (build projects) - [ ] Read Azure Well-Architected Framework - [ ] Review Azure Architecture Center patterns - [ ] Complete practice exams (80%+ score) - [ ] Understand cost optimization strategies - [ ] Practice designing solutions on paper/whiteboard


Pro Tip: AZ-305 tests your ability to design complete solutions balancing cost, security, performance, and operational overhead. Always read the entire scenario, identify all constraints, and choose the solution that best meets ALL requirements - not just technically correct, but most appropriate for the business context.

Documentation Count: This fact sheet contains 115+ embedded documentation links to official Microsoft Learn and Azure documentation.

Good luck! This certification demonstrates expert-level Azure architecture skills and is highly valued in the industry.