Microsoft Azure Solutions Architect Expert AZ-305 — Study Guide
Practice as you learn. Every concept maps to real exam questions with verified answers in the Microsoft exam hub, or drill the full exam with timed practice on ExamRoll.io.
This guide covers each AZ-305 domain in depth. Pick a domain to go deep, or work through them in order.
The domains
- Identity, Governance and Compliance — Identity Protection applies machine-learning risk detection to users and sign-ins. User risk policies evaluate compromised-credential likelihood and
- Data Storage and Database Solutions — Elastic pools let multiple databases share a compute budget and I/O headroom, smoothing peaks and reducing cost for many small, variable-load
- Compute and Application Architecture — Availability sets distribute VMs across fault domains (rack/power) and update domains to reduce correlated failures within a single datacenter.
- Networking and Connectivity — Subnet design segments traffic by function and trust. Subnets should carry one security intent each, gated with NSGs and UDRs. Right-size prefixes
- High Availability, Disaster Recovery and Business Continuity — Availability Zones are independent datacenter fault domains within a region. Zonal services (for example, Virtual Machines, managed disks, Standard
- Security Architecture and Zero Trust — Azure Key Vault is central for secrets and keys. Two data-plane authorization models exist: - Access policies are the legacy per-vault ACL model.
- Integration and Messaging Architecture — Azure Event Grid is a fully managed event router for reactive, push-based patterns. It uses either the native Event Grid schema or CloudEvents 1.0.
- Monitoring, Cost Optimization and Operations — Action groups decouple detection from response. Associate email/SMS/voice, push notifications, secure webhooks, ITSM connectors, Azure Functions,
- Migration and Modernization — Server assessments output readiness (OS support, drivers, agents), performance-based sizing (vCPU/RAM/IOPS/throughput), and monthly cost estimates
- Well-Architected Framework and Design Principles — Security is layered defense in depth, anchored in Zero Trust. Enforce least privilege with Azure RBAC, Privileged Identity Management (PIM), and
Ready to practice?
- Browse every question with verified answers → — free, with explanations.
- Start timed practice tests on ExamRoll.io → — the full question bank, in 20+ languages.
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →