Microsoft Certified: Azure Administrator Associate flashcards
181 free flashcards. Tap a card to flip it.
App Service VNet Integration
Flip cardEnables an App Service to access resources in an Azure Virtual Network by routing outbound traffic through the VNet. This allows the App Service to use private IP addresses within the VNet.
- Enables outbound connectivity to VNet resources
- App Service gets a private IP address within the VNet
- Used for connecting to private endpoints, service endpoints, or other VNet resources
- Does not provide inbound access to the App Service from the VNet by default
Memory trick: Integrate your App Service to Get to Your SQL DB.
Azure Container Apps for Microservices
Flip cardA serverless platform optimized for microservices architectures, offering built-in capabilities for service communication, scaling, and operational simplicity.
- Ideal for microservices and event-driven architectures.
- Supports Dapr for service-to-service communication and other features.
- Scales automatically, including to zero.
- Fully managed, reducing operational overhead compared to AKS.
Memory trick: For flexible microservices with minimal operations, Container Apps are the 'easy button'.
ACI Resource Allocation
Flip cardThe process of defining the specific CPU cores and memory (RAM) that an Azure Container Instance container group will be provisioned with, directly impacting performance and cost.
- Resources are specified at container group creation.
- CPU is measured in fractional cores (e.g., 0.5, 1, 2).
- Memory is measured in GB.
- Directly impacts billing and container performance.
Memory trick: ACI Needs Custom Cores and Memory.
Azure Custom VM Image
Flip cardA snapshot of a virtual hard disk (VHD) that includes the operating system, data disks, and all pre-installed software and configurations, used to create new VMs.
- Ensures consistent VM deployments
- Reduces deployment time
- Can be generalized (Sysprep for Windows, waagent for Linux)
- Stored in a Shared Image Gallery for sharing and versioning
Memory trick: Imagine a VM Factory, building replicas.
Azure VM Size
Flip cardA specification that defines the amount of CPU, memory, storage, and optional GPU resources available to an Azure Virtual Machine.
- Determines the hardware capabilities of the VM.
- Different series (e.g., D, E, N) are optimized for various workloads.
- Crucial for performance, cost, and application compatibility.
Memory trick: To get the right hardware, check the VM's 'size' label.
Azure Compute Gallery
Flip cardA service that allows you to manage, share, and distribute custom VM images across Azure subscriptions and tenants, providing versioning and regional replication.
- Centralized repository for custom VM images (managed images).
- Enables sharing of images across subscriptions, resource groups, and Azure AD tenants.
- Supports image versioning and regional replication for high availability and faster deployments.
- Simplifies the deployment of consistent, identical VMs for large-scale or frequent use cases.
Memory trick: Gallery: Great for Grouping and Global distribution of images.
Azure Container Apps
Flip cardA serverless platform for building and deploying modern apps and microservices using containers.
- Supports event-driven scaling (e.g., HTTP, Kafka, KEDA-compliant).
- Can scale down to zero instances.
- Ideal for microservices and serverless containers, abstracts Kubernetes complexity.
Memory trick: Container Apps are like smart thermostats for your containers: they turn off when not needed.
Azure Static Public IP
Flip cardA public IP address assigned to an Azure resource (like a VM) that does not change over time, even after the resource is deallocated or restarted.
- Ensures consistent IP address for external access
- Required for DNS records, firewall rules, client configurations
- Incurs a small cost even when not actively used
- Can be assigned to VMs, load balancers, application gateways
Memory trick: Static IP: Stay Put, Don't Move.
Azure Availability Sets
Flip cardA logical grouping capability for isolating VM resources from each other when they're deployed. It ensures that VMs are distributed across different physical hardware in a datacenter.
- Protects against unplanned hardware failures
- Protects against planned maintenance
- Distributes VMs across Fault Domains (up to 3)
- Distributes VMs across Update Domains (up to 20)
Memory trick: Availability Sets Keep VMs Safe in the Same House.
PowerShell Desired State Configuration (DSC) Extension
Flip cardAn Azure VM extension that allows you to apply PowerShell Desired State Configuration (DSC) configurations to Windows VMs, enabling consistent and automated software installation and system configuration.
- Uses configuration scripts to define desired state.
- Ensures idempotency (running multiple times yields same result).
- Can be used for software installation, service configuration, and more.
- Delivered via the Azure VM extension mechanism.
Memory trick: DSC Designs Consistent Configs.
Azure App Service
Flip cardA fully managed platform-as-a-service (PaaS) for building, deploying, and scaling web apps, mobile backends, and RESTful APIs, supporting multiple languages and frameworks.
- Supports auto-scaling and deployment slots.
- Integrated monitoring and diagnostics.
- Can scale to zero with specific plans (e.g., Consumption for Functions).
- Reduces infrastructure management overhead.
Memory trick: App Service Shines for Scalable Sites.
Azure Managed Image
Flip cardA resource in Azure that allows you to capture a snapshot of a generalized (sysprepped) virtual machine's operating system and data disks, enabling you to create identical VMs from that image.
- Used for creating 'golden images' or templates.
- VM must be generalized (sysprepped for Windows) before capture.
- Simplifies consistent deployment of multiple VMs.
- Can be shared across subscriptions or tenants.
Memory trick: Sysprep a Source, Save as Image.
Azure Kubernetes Service (AKS)
Flip cardA managed container orchestration service that simplifies deploying, managing, and scaling containerized applications using Kubernetes.
- Provides full control over Kubernetes clusters.
- Offers advanced networking features (e.g., custom DNS, network policies).
- Deep integration with Azure Virtual Networks.
- Suitable for complex, microservices-based applications.
Memory trick: When you need 'K'ontrol over 'K'ontainers and 'K'omplex networking, think AKS.
Azure VMSS Auto-scale
Flip cardA feature of Azure Virtual Machine Scale Sets that automatically adjusts the number of VM instances based on defined rules, such as CPU utilization, queue length, or schedules.
- Optimizes performance and cost by matching capacity to demand.
- Supports metric-based, schedule-based, and manual scaling.
- Can define both scale-out (increase instances) and scale-in (decrease instances) rules.
- Commonly uses CPU usage as a scaling metric.
Memory trick: Scale Sets Sense CPU Swings.
Azure Shared Disks
Flip cardA feature of Azure Managed Disks that allows multiple Azure VMs to concurrently attach a single disk.
- Enables building highly available clustered applications (e.g., WSFC).
- Provides shared storage for stateful workloads.
- Requires a cluster manager (e.g., Windows Server Failover Clustering) to manage disk access.
Memory trick: To share state and fail over fast, make sure your disks are shared and clustered.
Azure Load Balancer Health Probes
Flip cardMechanisms used by Azure Load Balancer to determine the health of backend instances. If a probe fails, the instance is taken out of rotation until it passes the probe again.
- Supports TCP, HTTP, and HTTPS protocols.
- HTTP/HTTPS probes are best for application health checks.
- TCP probes check if a port is listening.
- Configured with interval and unhealthy threshold.
Memory trick: Probes Check App's Life.
Azure Blob Tiering
Flip cardAzure Blob storage offers different access tiers (Hot, Cool, Archive) to optimize costs based on data access patterns. Data can be moved between tiers manually or automatically using lifecycle management policies.
- Hot tier: For frequently accessed data, higher storage cost, lower access cost.
- Cool tier: For infrequently accessed data, lower storage cost, higher access cost.
- Archive tier: For rarely accessed data with flexible latency requirements, lowest storage cost, highest access cost.
- Lifecycle management policies automate tier transitions.
Memory trick: Tiering your blobs wisely saves bucks, keeping data hot, cool, or archived.
Azure AD Authentication for Storage
Flip cardAzure Active Directory (Azure AD) authentication uses Azure role-based access control (RBAC) to grant granular permissions to security principals (users, groups, applications) for accessing Azure storage resources.
- Provides secure, token-based authentication.
- Enables granular access control with RBAC.
- Supports managed identities for Azure resources.
- Adheres to the principle of least privilege.
Memory trick: Keys, SAS, AD: Choose Your Access Path Wisely.
Immutable Storage Time-based Retention
Flip cardImmutable storage with a time-based retention policy allows you to store business-critical data in a non-erasable, non-rewritable format for a specified duration.
- Protects data from deletion or modification for a fixed period.
- Data can be automatically deleted after the retention period expires.
- Useful for regulatory compliance and data archiving.
- Once set, the retention period cannot be shortened.
Memory trick: Immutable: Soft for Safety, Version for History, Time for Rules, Legal for Forever.
Azure Table Storage
Flip cardAzure Table Storage is a NoSQL key-value store that can store vast amounts of structured, non-relational data. It is ideal for flexible datasets like web app configuration, address books, device information, and other metadata.
- Stores structured, non-relational data.
- Uses a key-value attribute store with a schemaless design.
- Offers low-latency access and high scalability.
- Cost-effective for large volumes of data.
Memory trick: Storage: Blobs for big files, Queues for messages, Tables for structured config, Files for SMB.
Zone-Redundant Storage (ZRS)
Flip cardZone-Redundant Storage (ZRS) synchronously replicates your data across three Azure availability zones in the primary region. This provides high availability and resilience against failures within a single data center or availability zone.
- Synchronous replication across three availability zones.
- Offers resilience against availability zone outages.
- Provides excellent data durability.
- Data remains within the primary region.
Memory trick: Redundancy: LRS for local, ZRS for zones, GRS for geo, GZRS for global zones.
Azure Premium File Shares
Flip cardAzure Premium File Shares are SSD-backed file shares designed for high-performance, latency-sensitive workloads that require consistent throughput.
- Offers consistent low-latency performance.
- Supports SMB and NFS protocols.
- Backed by SSDs, higher cost than Standard shares.
- Ideal for databases, developer environments, and high-performance applications.
Memory trick: SMB needs: Standard for Budget, Premium for Speed, NetApp for Extreme.
Azure AD Kerberos authentication for hybrid identities
Flip cardAzure AD Kerberos authentication for hybrid identities enables identity-based access to Azure File Shares for both Windows and Linux clients that are either Azure AD-joined or hybrid Azure AD-joined, without requiring a traditional domain controller.
- Supports both Windows and Linux clients.
- Leverages Azure AD for identity management.
- Provides Kerberos authentication without Azure AD DS or on-premises AD DS.
- Suitable for hybrid environments.
Memory trick: Files authentication: AD DS for traditional, AAD DS for cloud, AAD Kerberos for hybrid, or simple key.
Azure AD SMB Authentication Prerequisites
Flip cardTo use Azure AD authentication over SMB for Azure File Shares, client machines must be Azure AD-joined or hybrid Azure AD-joined, allowing them to obtain Kerberos tickets from Azure AD.
- Enables password-less Kerberos authentication for SMB.
- Requires the client to be Azure AD-joined or hybrid Azure AD-joined.
- Storage account must be configured for Azure AD authentication.
- Supports Windows 10 client versions 1809 and later.
Memory trick: SMB to Azure Files: AD DS, AAD DS, or Azure AD Join.
Customer-Managed Keys (CMK)
Flip cardCustomer-Managed Keys (CMK) allow you to use your own encryption keys from Azure Key Vault to encrypt data at rest in Azure Storage, providing greater control over the encryption process.
- Keys are stored and managed in Azure Key Vault (or Key Vault Managed HSM).
- Provides an additional layer of encryption over Microsoft-managed keys.
- You control the lifecycle of the encryption keys (creation, rotation, revocation).
- Supported for General-purpose v2 (GPv2) and Blob storage accounts.
Memory trick: Encryption: SSE is default, CMK gives control, HSM for hardware.
Azure Block Blobs
Flip cardBlock blobs are composed of blocks of data that can be managed individually, making them ideal for efficient and parallel upload of large files.
- Optimized for uploading large files up to 190.7 TiB.
- Data is broken into blocks, which can be uploaded in parallel.
- Commonly used for documents, images, videos, and backups.
Memory trick: Blocks for big files, Pages for disks, Appends for logs.
General-purpose v2 (GPv2) Storage Account
Flip cardGeneral-purpose v2 (GPv2) storage accounts are the recommended storage account type for most scenarios, offering the latest Azure Storage features and supporting all storage services (Blobs, Files, Queues, Tables) with various access tiers.
- Supports Blobs, Files, Queues, and Tables.
- Offers Hot, Cool, and Archive access tiers for Blob storage.
- Recommended for most workloads due to feature set and cost efficiency.
- Can be used with Azure Files Premium for high-performance file shares.
Memory trick: General Purpose VIPs excel in Versatility and Performance for all data needs.
Azure Blob Archive Tier
Flip cardThe Azure Blob Archive tier is an offline tier optimized for storing rarely accessed data with flexible latency requirements of several hours, offering the lowest storage costs.
- Lowest storage cost among all tiers.
- Data retrieval can take several hours (up to 15 hours).
- Suitable for long-term backups, archival, and compliance data.
Memory trick: Hot for 'now', Cool for 'later', Archive for 'never-unless-I-really-need-it'.
Azure Key Vault Purge Protection
Flip cardPurge protection in Azure Key Vault is a feature that prevents the permanent deletion (purging) of a key vault or its contents during the soft-delete retention period, even by privileged users. Disabling it allows immediate and permanent deletion.
- Protects against accidental or malicious key deletion.
- Works in conjunction with soft delete.
- When enabled, keys cannot be purged until the soft-delete retention period expires.
- Disabling it allows immediate, permanent deletion of keys and vaults.
Memory trick: Soft delete saves, purge protection guards, but disabling both ensures immediate data lockdown.
Azure Blob Storage Hot Tier
Flip cardThe Hot access tier is optimized for storing data that is accessed frequently, providing the lowest access costs and highest performance.
- Lowest latency for data retrieval.
- Higher storage costs compared to Cool and Archive tiers.
- Ideal for current data, frequently accessed media, or active backups.
Memory trick: Hot, Cool, Archive: Know Your Access Needs.
Read-Access Geo-Redundant Storage (RA-GRS)
Flip cardRA-GRS replicates your data to a secondary region and provides read access to the data in the secondary region, even if the primary region becomes unavailable.
- Data is replicated across two distinct Azure regions.
- Provides read access to data in the secondary region.
- Higher cost than GRS due to read endpoint availability.
Memory trick: LRS, ZRS, GRS, RA-GRS: Know Your Data's Reach.
User Delegation SAS
Flip cardA User Delegation SAS is a Shared Access Signature (SAS) secured with Azure Active Directory (Azure AD) credentials, allowing for more granular control and enhanced security by integrating with Azure RBAC and eliminating the need to use storage account keys.
- Secured with Azure AD credentials.
- Requires Azure RBAC permissions to create and use.
- Offers superior security compared to Account SAS or Service SAS.
- Supports blob and container operations, but not queues or tables directly.
Memory trick: SAS tokens: Account for broad, Service for specific, User for secure identity, Stored for central policy.
Azure Files Premium Tier with ZRS
Flip cardAzure Files Premium tier provides high-performance, low-latency SMB/NFS file shares, and when combined with Zone-Redundant Storage (ZRS), it offers high availability within a single region by replicating data across distinct Azure Availability Zones.
- Premium tier for high performance and low latency.
- Supports SMB 3.0 and NFS 4.1 protocols.
- ZRS ensures data is replicated across 3 Azure Availability Zones within a region.
- Ideal for enterprise-grade file shares requiring high availability and low latency.
Memory trick: Files for shares, Blobs for objects, NetApp for extreme performance.
Azure Private Endpoint for Storage
Flip cardAn Azure Private Endpoint provides a private IP address for an Azure service (like Storage Account) inside a virtual network, allowing secure and private access over the Azure backbone network, bypassing the public internet.
- Provides a private IP address for the Azure service.
- Traffic flows over the Azure backbone network, not the public internet.
- Enhances security by eliminating public internet exposure.
- Simplifies network configuration for secure access.
Memory trick: Private Endpoint for ultimate seclusion, Service Endpoint for backbone highway, Firewall for traffic cop.
Azure File Sync Cloud Change Detection
Flip cardAzure File Sync detects changes made directly to an Azure file share by polling the share on a scheduled basis, which can result in a delay (up to 24 hours) for these changes to synchronize down to on-premises servers.
- Changes on-premises are detected by the File Sync agent in real-time.
- Changes in the cloud are detected by a scheduled polling process.
- This polling can introduce a delay of up to 24 hours for cloud-originating changes.
Memory trick: Cloud Watches, On-Prem Whispers, Sync Happens.
Azure Public DNS Zone
Flip cardA container for DNS records for a specific domain that is publicly resolvable on the internet.
- Hosts DNS records for public domains.
- Managed within Azure portal, PowerShell, CLI, or API.
- Requires updating NS records at the domain registrar.
Memory trick: Create zone, get NS, update registrar, add records.
Forced Tunneling with UDRs and Azure Firewall
Flip cardForced tunneling redirects or 'forces' all internet-bound traffic from Azure virtual machines or subnets to an on-premises or Azure-based firewall for inspection and auditing, typically using User Defined Routes (UDRs).
- Achieved by configuring UDRs on subnets.
- Azure Firewall is a common target for forced tunneling in Azure.
- Ensures all outbound traffic passes through a central security appliance.
Memory trick: To filter all outbound traffic, force it through the firewall's funnel.
Standard Load Balancer for NVAs
Flip cardThe Azure Standard Load Balancer SKU supports High Availability Ports, a feature critical for deploying active-passive Network Virtual Appliances (NVAs) to ensure automatic failover and comprehensive traffic handling.
- Standard SKU supports High Availability Ports.
- HA Ports enable a single frontend to receive traffic on all ports/protocols.
- Essential for active-passive NVA deployments.
- Provides automatic failover for the NVA.
Memory trick: Standard SKU for NVAs, HA Ports for failover.
Azure Front Door
Flip cardA global, scalable, and secure entry point for fast delivery of web applications and APIs, offering Layer 7 capabilities, global load balancing, and WAF.
- Global Layer 7 load balancing
- Optimal routing based on user location (latency)
- Supports session affinity
- Integrated WAF and CDN capabilities
Memory trick: Front Door is global for web apps, Traffic Manager for DNS, Load Balancer for regional TCP/UDP.
Application Gateway Backend Pool
Flip cardA collection of backend targets (VMs, VMSS, IP addresses, App Services) that receive traffic from the Application Gateway.
- Supports various backend target types.
- VMSS provides dynamic scaling integration.
- Health probes monitor backend health.
Memory trick: VMSS for auto-scale, IP for static, App Service for PaaS.
Azure Firewall FQDN Filtering
Flip cardAzure Firewall can filter outbound traffic based on Fully Qualified Domain Names (FQDNs), providing granular control over external access.
- Operates at Layer 3/4 and Layer 7.
- Supports FQDN filtering for HTTP/HTTPS and non-HTTP/HTTPS protocols.
- Provides centralized network security across VNets and subscriptions.
Memory trick: Firewall for FQDN, NSG for IP/Port, UDR for routes.
VNet Peering
Flip cardVNet Peering connects two Azure virtual networks (VNets) directly, enabling private communication between them using the Azure backbone network.
- Enables high-bandwidth, low-latency communication.
- Traffic stays within the Azure backbone network.
- Can connect VNets in the same or different regions.
Memory trick: Peering is like a direct handshake between two Azure networks.
Azure Load Balancer
Flip cardA Layer 4 (TCP/UDP) load balancer that distributes incoming network traffic across multiple healthy virtual machines or services.
- Operates at Layer 4 (Transport Layer)
- Supports TCP and UDP protocols
- Can be Public or Internal
- Distributes traffic based on health probes and load-balancing rules
Memory trick: Load Balancer handles TCP/UDP, App Gateway handles HTTP/S, Front Door is global, Traffic Manager is DNS.
Azure VPN Gateway
Flip cardAn Azure networking service that creates encrypted cross-premises connections between on-premises networks and Azure Virtual Networks over the public internet.
- Uses IPsec/IKE VPN tunnels.
- Supports Site-to-Site and Point-to-Site connections.
- Connects over the public internet.
- Supports both IKEv1 and IKEv2.
Memory trick: VPN over public internet, ExpressRoute is private fiber.
Application Gateway WAF
Flip cardA Web Application Firewall (WAF) SKU integrated with Azure Application Gateway, providing protection against common web-based attacks.
- Protects against OWASP Top 10 vulnerabilities.
- Operates at Layer 7 (HTTP/HTTPS).
- Can be enabled on existing Application Gateway instances.
Memory trick: App Gateway for regional WAF, Front Door for global WAF.
VNet Connectivity with Overlapping IPs
Flip cardWhen Azure Virtual Networks have overlapping IP address spaces, VNet Peering is not possible, and a VPN Gateway with NAT functionality is required to enable communication.
- VNet Peering requires non-overlapping IP spaces.
- VPN Gateway can use NAT for overlapping IP spaces.
- NAT translates addresses to avoid conflicts.
- Crucial for multi-region or multi-subscription connectivity.
Memory trick: Peering is simple, VPN handles overlaps, ExpressRoute is dedicated, Virtual WAN is global hub.
NSG Subnet Association
Flip cardAssociating a Network Security Group (NSG) to a subnet applies its security rules to all resources within that subnet, providing a consistent and scalable approach to network traffic filtering.
- NSGs can be associated with subnets or NICs.
- Subnet association applies rules to all resources in the subnet.
- NIC association provides granular, per-VM control.
- Rules are evaluated first at the subnet level, then at the NIC level.
Memory trick: Subnet for broad, NIC for fine, both for full control.
Azure DNS Resolution
Flip cardAzure provides default DNS resolution for public names. For private names within Azure, private DNS zones must be linked to virtual networks.
- Azure-provided DNS handles public names by default.
- Private DNS zones are used for internal Azure resource names.
- Virtual networks must be linked to private DNS zones for resolution.
Memory trick: Link private zones to VNet for internal, Azure default for external.
Azure ExpressRoute
Flip cardAzure ExpressRoute extends an on-premises network into the Microsoft cloud over a private connection facilitated by a connectivity provider.
- Bypasses the public internet for enhanced security and reliability.
- Offers consistent low latency and high bandwidth.
- Requires an ExpressRoute circuit and an ExpressRoute Gateway in Azure.
Memory trick: For a dedicated connection, ExpressRoute is the private highway.
Internal Azure Load Balancer
Flip cardAn Internal Azure Load Balancer distributes incoming traffic among virtual machines within a virtual network or a hybrid network connected via VPN/ExpressRoute, without exposing a public IP address.
- Only accessible from within the VNet or connected private networks.
- Does not have a public IP address.
- Used for load balancing internal L4 (TCP/UDP) traffic.
Memory trick: Keep it internal, keep it private, keep it balanced.
Azure Private Link
Flip cardA service that enables private access to Azure PaaS services (e.g., Azure Storage, Azure SQL Database) and customer-owned/partner services over a private endpoint in your virtual network.
- Traffic travels over the Microsoft global network, not the public internet.
- The private endpoint maps to a private IP address in your VNet.
- Provides secure and isolated access to Azure services.
Memory trick: Private Link: Your PaaS has its own personal, private lane.
Hub-Spoke with Forced Tunneling
Flip cardA network topology where a central 'hub' VNet (containing shared services like a firewall) connects to multiple 'spoke' VNets, and all traffic from spokes is forced through the hub's firewall.
- VNet peering connects hub and spoke VNets.
- UDRs on spoke subnets direct 0.0.0.0/0 traffic to the hub firewall's private IP.
- Requires 'Allow forwarded traffic' and 'Use remote gateways' on peering links.
Memory trick: Hub-Spoke: All roads lead to the firewall.
Azure Files AD DS Authentication
Flip cardAzure Active Directory Domain Services (Azure AD DS) authentication allows domain-joined Windows VMs to mount and access Azure File Shares using Active Directory credentials and to enforce directory and file-level permissions with NTFS ACLs.
- Enables traditional domain-based authentication for Azure Files.
- Supports NTFS ACLs for granular permissions.
- Requires an Azure AD DS managed domain.
Memory trick: AD DS bridges on-prem to Azure Files.
Azure Private Link for Storage
Flip cardAzure Private Link allows you to access Azure PaaS services (like Azure Storage) over a private endpoint in your virtual network, ensuring that traffic between your VNet and the service travels entirely over the Microsoft backbone network.
- Provides a private IP address for the service within your VNet.
- Traffic bypasses the public internet.
- Enhances security and compliance for sensitive data.
Memory trick: Private Link: Secret road to storage.
User Defined Routes (UDRs) and Azure Firewall
Flip cardUDRs allow overriding Azure's default routing to direct traffic, often used to force all outbound internet traffic from a subnet through an Azure Firewall for centralized inspection and control.
- UDRs are applied to subnets.
- A common use case is forced tunneling to a firewall or NVA.
- Azure Firewall provides stateful inspection and threat intelligence.
Memory trick: UDR: 'U' Decide the Route, NSG: 'N'arrow the Security Gate.
Azure VPN Gateway SKUs
Flip cardDifferent performance and feature tiers for Azure VPN Gateways, offering varying bandwidth, tunnel limits, and BGP support.
- Basic SKU is the lowest cost but lacks BGP and Zone Redundancy.
- VpnGw1-5 SKUs provide increasing bandwidth and tunnel capacity.
- All VpnGw1+ SKUs support BGP and active-active configurations.
Memory trick: Connect to Cloud: VPN Gateway is your secure bridge.
NSG Flow Logs
Flip cardA feature of Azure Network Watcher that logs information about IP traffic flowing through a Network Security Group (NSG), providing details like source/destination IP, port, protocol, and traffic action.
- Enables deep network visibility for auditing and security.
- Logs are stored in Azure Storage accounts.
- Can be analyzed with tools like Network Watcher traffic analytics or Azure Log Analytics.
Memory trick: Flow Logs: Your network's detailed diary.
A Record (Azure DNS)
Flip cardA DNS record type that maps a domain name or hostname to an IPv4 address, used to point custom domains to web services or VMs.
- Fundamental for resolving domain names to IP addresses.
- Can be used for root domains or subdomains.
- One of the most common DNS record types.
Memory trick: DNS Records: Your domain's address book.
NSG Association Scope
Flip cardNetwork Security Groups can be associated with either a subnet or an individual network interface (NIC) of a VM, or both.
- Rules are processed at both levels if two NSGs are applied.
- Subnet NSG rules are processed first for inbound traffic, then NIC NSG rules.
- NIC NSG rules are processed first for outbound traffic, then Subnet NSG rules.
Memory trick: One NSG: Your VM's single security guard.
Immutable Storage
Flip cardImmutable storage for Azure Blob Storage allows users to store business-critical data in a WORM (Write Once, Read Many) state, meaning it cannot be modified or deleted for a specified retention period.
- Supports time-based retention policies.
- Legal holds can be applied for indefinite retention.
- Data cannot be overwritten or deleted by any user, including root accounts.
Memory trick: Immutability locks data in time.