Microsoft Azure Services and Architecture Questions

Microsoft Azure's core service catalog and architectural patterns: Virtual Machines, managed Kubernetes (AKS), App Service and Azure Functions, Storage accounts and managed disks, Azure SQL and Cosmos DB, VNets with hybrid connectivity and global load balancing, Microsoft Entra ID and RBAC, and Key Vault secrets and encryption. Covers Azure service selection, infrastructure as code (ARM, Bicep, Terraform), observability with Azure Monitor and Kusto queries, cost governance and Azure Policy, the Azure Well-Architected design principles, and hybrid management via Azure Arc, common in enterprise Azure estates. For provider-agnostic trade-offs, see the cross-cloud entries.

MediumTechnical
71 practiced

Intermittent 502 Bad Gateway responses are observed from an Application Gateway fronting a backend web API. Create a troubleshooting runbook: which Application Gateway metrics and logs to check, how to validate backend health probes, probe path and host header issues, timeout and keep-alive settings, and SSL termination mismatches that can cause 502s.

MediumTechnical
65 practiced

Compare TCP, HTTP, and HTTPS health probe behaviors on Azure Load Balancer and Application Gateway. Explain how misconfigurations (wrong probe path, host header, response codes) can cause healthy backend instances to be marked unhealthy and cause scale set instance replacement or traffic blackholing.

HardSystem Design
117 practiced

Design a secure Azure network architecture to expose internal microservices only to authenticated internal clients, using Private Link, Azure Firewall with WAF, API Management, and service endpoints. Describe the ingress/egress flows, DNS and private-zone setup, policy enforcement, certificate handling, and the residual risks of the approach.

MediumSystem Design
62 practiced

For a three-tier application (public web, private app, private DB) in Azure, design NSG rules and Azure Firewall placement. Include how to restrict management access using Azure Bastion, capture and analyze flow logs, and control egress to external services while enabling required PaaS access with minimal blast radius.

HardSystem Design
60 practiced

Design hybrid connectivity between an on-prem datacenter and Azure across two regions with stringent latency (<50ms) and high availability requirements. Compare ExpressRoute (private circuits) vs VPN Gateway (IPsec) for this scenario, explain BGP peering and route advertisement, failover strategies, and how to avoid asymmetric routing or single points of failure.

Unlock Full Question Bank

Get access to all 17 Microsoft Azure Services and Architecture interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.