What People Actually Mean When They Say "Azure Cloud Architect Inter Questions"
The phrase shows up everywhere on forums and job boards, usually as a vague search term someone types at 2 AM before an interview. It isn't an official Microsoft certification category. The actual exam is AZ-305, the Azure Solutions Architect Expert track, and the "inter" label is just shorthand people use for the intermediate-to-advanced questions that actually separate candidates who have deployed real infrastructure from people who've only watched YouTube walkthroughs. These questions test whether you understand tradeoffs under constraints, not whether you can memorize service names. A typical question will describe a manufacturing company with 400 facilities, each generating 50 GB of sensor telemetry daily, needing near-real-time analytics at the edge with strict data residency in the EU. Your answer choices will include Event Hubs, IoT Hub, Azure Stack Edge, and some combination. The correct answer depends on whether the question emphasizes device management versus raw throughput, and whether "edge" means actual on-prem processing or just low-latency ingestion. I've been writing and reviewing these kinds of scenarios for a long time. One question that consistently trips people up involves a hybrid identity setup where the organization requires Seamless SSO but also needs conditional access policies that evaluate device compliance against an on-premises Active Directory. Most candidates immediately reach for Azure AD Connect with password hash sync. The better answer in that scenario is pass-through authentication combined with Azure AD Connect health monitoring, because password hash sync doesn't validate credentials against your live AD, which breaks the conditional access evaluation chain. I had a colleague who selected password hash sync on a real exam and got it wrong. He swore the question was ambiguous, and honestly, it was borderline, but the key was the words "validate credentials" embedded in the conditional access requirement.
The pattern across these questions is deliberate. They give you a constraint that seems secondary but actually eliminates half the answers. Network latency requirements. Regulatory data sovereignty. Existing on-premises investment. Cost caps stated as a hard monthly ceiling. You have to read past the feature list of every service and map each constraint to a technical limitation.
How to Actually Prepare for These Questions
Reading documentation passively won't help. The questions assume you've made decisions under ambiguity. The most effective study method I've seen is to take the official Microsoft Learn path for AZ-305, then immediately do the practice tests, grade yourself harshly, and spend two to three times longer reviewing the explanations for wrong answers than you did taking the test. Most people skip that review step. That's why they fail on questions that look deceptively simple. Microsoft's own practice test bank has shifted noticeably over the last two years. They've added more architecture diagrams and fewer definition-style questions. A current question type presents a network topology diagram with ExpressRoute circuits, virtual WAN hubs, and spoke VNet peering, then asks about DNS resolution paths between spokes that don't have explicit peering. The answer requires understanding that virtual WAN doesn't auto-propagate routes the way VNet peering does, and that DNS registration depends on whether you've deployed conditional forwarders or Azure Private DNS zones. This is the kind of question that rewards actual deployment experience. I ran into a specific issue last year while building a study lab for a team preparing for AZ-305. We needed a realistic hybrid scenario with an ExpressRoute gateway, a local DNS resolver, and conditional access policies. The problem was that the public IP for our ExpressRoute gateway kept getting reassigned after a routine maintenance window, which broke our DNS records and confused everyone testing the connectivity. The workaround was straightforward but easy to miss: disable the public IP assignment on the ExpressRoute gateway during creation, or use a static public IP and document the reservation ID in your network runbook. Without that, every lab reset costs about forty minutes troubleshooting DNS rather than studying the actual concept being tested.
Get the Full Details

Common Pitfalls That Show Up Repeatedly
The first pitfall is overthinking the "best" answer. These questions don't want the theoretically optimal architecture. They want the most appropriate one given the stated budget, timeline, and existing investment. If the question says the company already has Site-to-Site VPN running and wants to minimize migration effort, ExpressRoute is almost never the right answer, even though it's technically superior. The exam rewards pragmatic decisions. The second pitfall involves Azure policy and governance tools. Candidates confuse Azure Policy, Blueprints, and Management Groups. They're related but serve different purposes. Management Groups are for hierarchy and scope. Azure Policy enforces rules. Blueprints package policy, RBAC, and resource templates together for repeatable deployments. A question asking about standardizing a compliance baseline across fifty subscriptions is testing whether you know that Management Groups provide the inheritance chain and Azure Policy provides the actual rules, not that Blueprints is the primary governance mechanism. Blueprints are useful but they're a packaging tool, not a governance engine. There's also a persistent misconception about disaster recovery options. Azure Site Recovery isn't the only DR tool available. For stateless web applications, a active-active geo-redundant deployment using Traffic Manager or Azure Front Door with zone-redundant VMSS instances often provides better RTO and RPO than an ASR-based failover. The questions sometimes describe a scenario where ASR seems like the obvious answer, but the actual workload characteristics point toward a multi-region active deployment. Recognizing when ASR is the wrong choice is just as important as knowing when it's right.
What the Questions Don't Cover (And Why That Matters)
These exams deliberately avoid questions about services that are in preview or recently retired. They also don't test hands-on configuration steps. You won't be asked to write ARM template syntax or select the exact CLI command for a deployment. The focus is architectural decision-making. This means you can pass without having typed every PowerShell cmdlet, but you'll struggle if you've only ever followed point-and-click tutorials in the Azure portal. The gap between portal clicking and actual architectural reasoning is where most preparation falls short. If you're looking for a concentrated set of practice questions specifically tagged as intermediate difficulty, third-party question banks like Whizlabs, Tutorials Dojo, and ExamTopics have curated collections. Microsoft's own practice assessment is free through the certification dashboard and is worth completing first because it uses the same question engine as the real exam. I usually recommend skipping ExamTopics as a primary source because the explanations are often wrong or outdated, and the community corrections lag behind service changes. Tutorials Dojo's explanations are generally the most accurate because the author updates them within days of exam changes. The certification itself costs $165 USD for a single attempt. If you fail, you pay again. Most people need two or three attempts because the passing threshold is around 700 out of 1000, and the questions are designed to make that margin feel thinner than it actually is. Plan for that. Budget three to six weeks of study depending on your existing experience, and expect to spend more time on the hybrid identity and governance sections than the compute and storage sections, because those are where the tradeoff questions concentrate.