Functional Group
A major section of the exam objectives, like 'Manage Azure identities and governance'.
Getting Started: Exam AZ-104 Overview
Free knowledge base
Everything from the course in one searchable place: 326 entries. Use it to review before a practice test or look up a word you forgot.
326 results · showing first 300, refine your search
A major section of the exam objectives, like 'Manage Azure identities and governance'.
Getting Started: Exam AZ-104 Overview
The percentage of the exam dedicated to a specific functional group.
Getting Started: Exam AZ-104 Overview
An exam question format presenting a detailed business scenario.
Getting Started: Exam AZ-104 Overview
An exam section where you perform tasks in a simulated Azure environment.
Getting Started: Exam AZ-104 Overview
Official Microsoft document detailing all specific topics covered by an exam.
Getting Started: Exam AZ-104 Overview
A question type where you select one or more correct answers from a list.
Getting Started: Exam AZ-104 Overview
A question type where you match items by dragging them to correct targets.
Getting Started: Exam AZ-104 Overview
To remember the exam's focus areas, think 'I S C N M': Identities, Storage, Compute, Networking, Monitoring. It's like a 'SCAN' of Azure!
Getting Started: Exam AZ-104 Overview
The AZ-104 exam was updated in January 2024. Always check the official Microsoft Learn page for the most current 'Skills Measured' document to ensure your study materials are up-to-date.
Getting Started: Exam AZ-104 Overview
Not checking the latest 'Skills Measured' document, leading to studying outdated topics.
Getting Started: Exam AZ-104 Overview
Ignoring exam objective weightings and spending too much time on less important areas.
Getting Started: Exam AZ-104 Overview
Only memorizing facts without understanding how to apply them in real-world scenarios, especially for case studies.
Getting Started: Exam AZ-104 Overview
Web-based console for managing Azure resources.
Getting Started: Exam AZ-104 Overview
Provides $200 credit and free services for 12 months.
Getting Started: Exam AZ-104 Overview
Subscription model where you pay for what you use.
Getting Started: Exam AZ-104 Overview
Logical container for Azure resources.
Getting Started: Exam AZ-104 Overview
Browser-based command-line interface for Azure.
Getting Started: Exam AZ-104 Overview
Monetary balance for consuming Azure services.
Getting Started: Exam AZ-104 Overview
Billing unit for Azure services and resources.
Getting Started: Exam AZ-104 Overview
To remember the free account setup, think 'M-P-C-A-P': Microsoft account, Profile, Phone, Credit card, Access Portal.
Getting Started: Exam AZ-104 Overview
The AZ-104 exam frequently tests your ability to identify the correct tool or service for a given task within the Azure portal. Keywords like 'create a virtual machine' or 'monitor resource costs' should immediately make you think of navigating the portal or using specific portal features.
Getting Started: Exam AZ-104 Overview
Forgetting to delete resources after practice, leading to unexpected charges if you upgrade to Pay-As-You-Go.
Getting Started: Exam AZ-104 Overview
Not monitoring your free credit usage, causing services to stop unexpectedly when credits are exhausted.
Getting Started: Exam AZ-104 Overview
Attempting to use advanced or high-tier services that quickly consume free credits or are not included in the free tier.
Getting Started: Exam AZ-104 Overview
An individual identity used to sign in and access resources.
Module 1: Managing Azure Identities and Governance
Used to manage access to Azure resources and applications.
Module 1: Managing Azure Identities and Governance
For collaboration and access to shared resources like mailboxes.
Module 1: Managing Azure Identities and Governance
Corporate devices managed entirely by Azure AD.
Module 1: Managing Azure Identities and Governance
Personal devices integrated with Azure AD for resource access.
Module 1: Managing Azure Identities and Governance
Domain-joined devices also registered with Azure AD.
Module 1: Managing Azure Identities and Governance
The unique identifier for an Azure AD user account (e.g., user@domain.com).
Module 1: Managing Azure Identities and Governance
Users are 'People', Groups are 'Teams', Devices are 'Tools'. P-T-T helps you remember the main object types!
Module 1: Managing Azure Identities and Governance
The exam often distinguishes between Azure AD joined, Azure AD registered, and Hybrid Azure AD joined devices. Memorize their primary use cases and management characteristics. Also, know the difference between Security groups and Microsoft 365 groups.
Module 1: Managing Azure Identities and Governance
Assigning permissions directly to individual users instead of using groups, leading to complex and hard-to-manage access controls.
Module 1: Managing Azure Identities and Governance
Not implementing a consistent naming convention for users, groups, and devices, making it difficult to identify and manage objects.
Module 1: Managing Azure Identities and Governance
Failing to regularly review and clean up stale user accounts or unused groups, creating potential security vulnerabilities.
Module 1: Managing Azure Identities and Governance
System for managing who has access to Azure resources and what they can do.
Module 1: Managing Azure Identities and Governance
An object representing a user, group, service, or identity requesting access.
Module 1: Managing Azure Identities and Governance
A collection of permissions that defines what actions can be performed.
Module 1: Managing Azure Identities and Governance
The set of resources to which an RBAC assignment applies (e.g., subscription, resource group).
Module 1: Managing Azure Identities and Governance
Security concept of granting only the minimum necessary permissions for a task.
Module 1: Managing Azure Identities and Governance
Predefined RBAC roles provided by Azure (e.g., Owner, Contributor, Reader).
Module 1: Managing Azure Identities and Governance
User-defined RBAC roles with specific, tailored sets of permissions.
Module 1: Managing Azure Identities and Governance
Permissions assigned at a higher scope automatically apply to lower scopes.
Module 1: Managing Azure Identities and Governance
To remember the RBAC components, think 'Who Can Do What, Where?'. 'Who' is the Security Principal, 'Can Do What' is the Role Definition, and 'Where' is the Scope.
Module 1: Managing Azure Identities and Governance
Memorize the core components of an RBAC assignment: security principal, role definition, and scope. Be ready to differentiate between built-in roles like Owner, Contributor, and Reader, and understand how permissions inherit down the Azure resource hierarchy.
Module 1: Managing Azure Identities and Governance
Assigning the 'Owner' role too broadly instead of using more restrictive roles like 'Contributor' or 'Reader'.
Module 1: Managing Azure Identities and Governance
Forgetting that permissions are inherited, leading to unintended access at lower levels of the resource hierarchy.
Module 1: Managing Azure Identities and Governance
Not regularly reviewing and removing outdated role assignments, creating security vulnerabilities.
Module 1: Managing Azure Identities and Governance
A logical container linking Azure services to an account for billing and management.
Module 1: Managing Azure Identities and Governance
The entity that owns Azure subscriptions and manages billing.
Module 1: Managing Azure Identities and Governance
Provides identity and access management for Azure subscriptions and resources.
Module 1: Managing Azure Identities and Governance
The level at which costs are aggregated and charged in Azure.
Module 1: Managing Azure Identities and Governance
A scope where policies, access, and governance can be applied.
Module 1: Managing Azure Identities and Governance
The process of creating, managing, and deleting Azure resources.
Module 1: Managing Azure Identities and Governance
Imagine 'S'ubscriptions are like 'S'eparate bank accounts for your cloud spending, and 'R'esource 'G'roups are like 'R'elated folders within those accounts.
Module 1: Managing Azure Identities and Governance
Memorize that a resource can only belong to ONE resource group, but a resource group can contain resources from MULTIPLE regions. Also, resource groups cannot be nested.
Module 1: Managing Azure Identities and Governance
Confusing resource group deletion with resource deletion; deleting a resource group deletes ALL contained resources.
Module 1: Managing Azure Identities and Governance
Assuming resource groups are tied to a specific region; they are logical containers and can hold resources from different regions.
Module 1: Managing Azure Identities and Governance
Trying to nest resource groups; Azure does not support nested resource groups.
Module 1: Managing Azure Identities and Governance
Service to enforce organizational standards and assess compliance at scale.
Module 1: Managing Azure Identities and Governance
Specifies the condition and effect of an Azure Policy rule.
Module 1: Managing Azure Identities and Governance
Applying a policy definition to a specific scope (management group, subscription, resource group).
Module 1: Managing Azure Identities and Governance
A collection of policy definitions grouped for a larger goal; also called a policy set.
Module 1: Managing Azure Identities and Governance
The action taken by Azure Policy when a resource is non-compliant (e.g., Deny, Audit).
Module 1: Managing Azure Identities and Governance
Prevents accidental deletion or modification of Azure resources, overriding permissions.
Module 1: Managing Azure Identities and Governance
Resource lock type that prevents deletion but allows modification.
Module 1: Managing Azure Identities and Governance
Resource lock type that prevents both modification and deletion.
Module 1: Managing Azure Identities and Governance
To remember Policy effects, think 'D.A.D. M.' - Deny, Audit, DeployIfNotExists, Modify. Like a strict but helpful DAD who helps manage your resources!
Module 1: Managing Azure Identities and Governance
On the AZ-104 exam, pay close attention to the specific 'effect' of an Azure Policy. Questions often test your understanding of what happens when a policy with a 'Deny' effect versus an 'Audit' effect is triggered. Also, distinguish clearly between Azure Policy (rules-based compliance) and Resource Locks (preventing accidental changes).
Module 1: Managing Azure Identities and Governance
Confusing Azure Policy with Role-Based Access Control (RBAC). RBAC controls 'who' can do 'what' to resources, while Policy defines 'what' configurations are allowed for resources.
Module 1: Managing Azure Identities and Governance
Applying a 'Deny' policy without thoroughly testing it, which can inadvertently block legitimate operations and cause outages.
Module 1: Managing Azure Identities and Governance
Forgetting that Resource Locks apply to all users, including subscription owners, and must be removed before locked actions can be performed.
Module 1: Managing Azure Identities and Governance
A URI that grants restricted access to Azure Storage resources.
Module 2: Implementing and Managing Storage
SAS secured with Azure AD credentials, recommended for Blob storage.
Module 2: Implementing and Managing Storage
Authorization system managing who has access to Azure resources.
Module 2: Implementing and Managing Storage
Automatic encryption of data at rest in Azure Storage.
Module 2: Implementing and Managing Storage
Encryption keys stored in Azure Key Vault for storage encryption.
Module 2: Implementing and Managing Storage
Configures network rules to limit access to a storage account.
Module 2: Implementing and Managing Storage
Extends VNet identity to Azure services over the Azure backbone.
Module 2: Implementing and Managing Storage
Provides a private IP for an Azure service within a VNet.
Module 2: Implementing and Managing Storage
SAS-sy access: Shared Access Signatures give you a 'sassy' way to share just what's needed, for just how long, and to just who.
Module 2: Implementing and Managing Storage
The exam frequently tests the differences between SAS types (User Delegation vs. Service vs. Account) and when to use each. Also, know that SSE is automatic for data at rest, and CMK is an option for increased control.
Module 2: Implementing and Managing Storage
Over-provisioning SAS permissions: Granting 'write' when only 'read' is needed.
Module 2: Implementing and Managing Storage
Forgetting to set an expiry time for SAS tokens, leading to perpetual access.
Module 2: Implementing and Managing Storage
Not enabling 'Require secure transfer' for storage accounts, allowing unencrypted HTTP access.
Module 2: Implementing and Managing Storage
A unique container for all your Azure Storage data.
Module 2: Implementing and Managing Storage
General-purpose v2, recommended storage account type.
Module 2: Implementing and Managing Storage
Local Redundant Storage, 3 copies in one data center.
Module 2: Implementing and Managing Storage
Zone Redundant Storage, 3 copies across availability zones.
Module 2: Implementing and Managing Storage
Geo-Redundant Storage, LRS + async copy to another region.
Module 2: Implementing and Managing Storage
Read-access GRS, GRS with read access to secondary region.
Module 2: Implementing and Managing Storage
Recovery Point Objective, max tolerable data loss.
Module 2: Implementing and Managing Storage
Recovery Time Objective, max tolerable downtime.
Module 2: Implementing and Managing Storage
Remember 'L-Z-G-R' for redundancy: Local, Zone, Geo, Read-access Geo. It's like upgrading your data's 'safety net' from your house to the whole world!
Module 2: Implementing and Managing Storage
The exam often presents scenarios requiring you to choose the best storage redundancy option based on cost, durability, availability, and performance requirements. Pay close attention to keywords like 'regional disaster', 'lowest cost', 'high availability within a region', and 'read access to secondary'.
Module 2: Implementing and Managing Storage
Choosing GRS for non-critical data, leading to unnecessary costs.
Module 2: Implementing and Managing Storage
Not understanding that GRS/RA-GRS replication is asynchronous, meaning potential data loss during a failover.
Module 2: Implementing and Managing Storage
Selecting LRS for data that requires protection against regional outages.
Module 2: Implementing and Managing Storage
Fully managed cloud file shares accessible via SMB/NFS.
Module 2: Implementing and Managing Storage
Synchronizes on-premises file servers with Azure Files.
Module 2: Implementing and Managing Storage
Azure resource for managing File Sync deployments.
Module 2: Implementing and Managing Storage
Defines the synchronization topology between endpoints.
Module 2: Implementing and Managing Storage
The Azure file share within a Sync Group.
Module 2: Implementing and Managing Storage
A specific path on an on-premises Windows Server to sync.
Module 2: Implementing and Managing Storage
Software installed on Windows Server for synchronization.
Module 2: Implementing and Managing Storage
Moves infrequently accessed files to Azure, freeing local space.
Module 2: Implementing and Managing Storage
To remember the File Sync components, think 'S.S.S.C.S.A.': Storage Sync Service, Sync Group, Server Endpoint, Cloud Endpoint, Sync Agent. It's a 'Sync Server Solution, Cloud-Side, Agent-powered!'
Module 2: Implementing and Managing Storage
For the AZ-104 exam, remember that Azure File Sync requires a Windows Server operating system. You cannot use it to sync directly from client machines or other operating systems. Also, know the order of operations for setting up File Sync: Storage Sync Service -> Sync Group -> Cloud Endpoint (Azure File Share) -> Server Endpoint (on-premises path).
Module 2: Implementing and Managing Storage
Forgetting to install the Azure File Sync agent on the on-premises server before attempting to register it.
Module 2: Implementing and Managing Storage
Not configuring proper network access (e.g., firewall rules) between the on-premises server and Azure.
Module 2: Implementing and Managing Storage
Attempting to use Azure File Sync with an unsupported operating system or a non-Windows Server machine.
Module 2: Implementing and Managing Storage
Not enabling cloud tiering when local disk space optimization is a requirement, leading to full local drives.
Module 2: Implementing and Managing Storage
For frequently accessed data, highest storage cost, lowest access cost.
Module 2: Implementing and Managing Storage
For infrequently accessed data, lower storage cost, higher access cost.
Module 2: Implementing and Managing Storage
For rarely accessed data, lowest storage cost, highest retrieval cost/latency.
Module 2: Implementing and Managing Storage
Process of moving data from Archive to Hot/Cool for access.
Module 2: Implementing and Managing Storage
Rule-based policy to automate blob tiering and deletion.
Module 2: Implementing and Managing Storage
Costs associated with reading or writing data to a storage tier.
Module 2: Implementing and Managing Storage
Costs associated with storing data in a particular tier per GB.
Module 2: Implementing and Managing Storage
HCA: Hot, Cool, Archive. Remember it as 'How Can Anyone' forget the tiers!
Module 2: Implementing and Managing Storage
Memorize the characteristics of each blob storage tier: Hot (frequent, high storage cost, low access), Cool (infrequent, lower storage, higher access), Archive (rare, lowest storage, highest access/latency). Pay attention to the rehydration process for Archive.
Module 2: Implementing and Managing Storage
Not implementing lifecycle management, leading to unnecessarily high storage costs for old data.
Module 2: Implementing and Managing Storage
Using the Archive tier for data that needs immediate or frequent access, causing high rehydration costs and delays.
Module 2: Implementing and Managing Storage
Forgetting that data in the Archive tier is offline and requires rehydration before it can be accessed.
Module 2: Implementing and Managing Storage
Managing infrastructure through code, not manual processes.
Module 3: Deploying and Managing Azure Compute Resources
JSON file defining Azure resources for declarative deployment.
Module 3: Deploying and Managing Azure Compute Resources
Command-line interface for managing Azure resources.
Module 3: Deploying and Managing Azure Compute Resources
Values passed into an ARM template at deployment time.
Module 3: Deploying and Managing Azure Compute Resources
Azure services defined within an ARM template.
Module 3: Deploying and Managing Azure Compute Resources
Specifying desired state, not steps to achieve it.
Module 3: Deploying and Managing Azure Compute Resources
To remember ARM template sections: 'PVR' - Parameters, Variables, Resources. Like a 'PVR' for your Azure infrastructure!
Module 3: Deploying and Managing Azure Compute Resources
The AZ-104 exam frequently tests your ability to identify the correct Azure CLI commands for deploying resources using ARM templates. Pay close attention to `az deployment group create` and its required parameters like `--resource-group`, `--name`, and `--template-file`.
Module 3: Deploying and Managing Azure Compute Resources
Forgetting to specify the resource group or deployment name when using `az deployment group create`.
Module 3: Deploying and Managing Azure Compute Resources
Incorrectly referencing parameter names or values in the ARM template or CLI command, leading to deployment failures.
Module 3: Deploying and Managing Azure Compute Resources
Not validating the ARM template before deployment, causing errors that could have been caught earlier.
Module 3: Deploying and Managing Azure Compute Resources
On-demand, scalable computing resource in the cloud.
Module 3: Deploying and Managing Azure Compute Resources
Defines CPU, memory, and disk capacity of a VM.
Module 3: Deploying and Managing Azure Compute Resources
Azure-managed storage for VM disks, recommended for use.
Module 3: Deploying and Managing Azure Compute Resources
Virtual firewall controlling network traffic to/from Azure resources.
Module 3: Deploying and Managing Azure Compute Resources
Logically isolated network in Azure for your resources.
Module 3: Deploying and Managing Azure Compute Resources
Allows internet access to an Azure resource.
Module 3: Deploying and Managing Azure Compute Resources
Secure Shell, used for remote access to Linux VMs.
Module 3: Deploying and Managing Azure Compute Resources
To remember VM creation steps: 'R-OS-D-N-C' - Resource Group, OS/Size, Disks, Networking, Connect. It's like building blocks for your cloud server!
Module 3: Deploying and Managing Azure Compute Resources
The AZ-104 exam frequently tests your knowledge of VM sizing, disk types (Standard HDD, Standard SSD, Premium SSD), and Network Security Group (NSG) rules. Pay close attention to the impact of these choices on cost and performance. Remember that NSGs are evaluated by priority, and 'Deny' rules override 'Allow' rules at the same priority.
Module 3: Deploying and Managing Azure Compute Resources
Forgetting to open necessary ports in the Network Security Group (NSG), leading to connectivity issues.
Module 3: Deploying and Managing Azure Compute Resources
Choosing an incorrect VM size or disk type, resulting in either overspending or poor performance.
Module 3: Deploying and Managing Azure Compute Resources
Not configuring proper authentication (e.g., strong password or SSH key) for VM access, creating security vulnerabilities.
Module 3: Deploying and Managing Azure Compute Resources
Increasing or decreasing resources of a single VM (scaling up/down).
Module 3: Deploying and Managing Azure Compute Resources
Adding or removing VM instances to distribute workload (scaling out/in).
Module 3: Deploying and Managing Azure Compute Resources
Logical grouping of VMs that ensures high availability during outages.
Module 3: Deploying and Managing Azure Compute Resources
Group of VMs sharing common power/network, protecting against hardware failure.
Module 3: Deploying and Managing Azure Compute Resources
Group of VMs that can be rebooted simultaneously during planned maintenance.
Module 3: Deploying and Managing Azure Compute Resources
Manages a group of identical, load-balanced VMs for horizontal scaling.
Module 3: Deploying and Managing Azure Compute Resources
Azure-initiated updates to the underlying platform infrastructure.
Module 3: Deploying and Managing Azure Compute Resources
Unexpected outages due to hardware failures or other unforeseen events.
Module 3: Deploying and Managing Azure Compute Resources
To remember Fault vs. Update Domains: 'F' for Fault, 'F' for Failure (hardware). 'U' for Update, 'U' for Upgrade (planned maintenance).
Module 3: Deploying and Managing Azure Compute Resources
The exam often tests the purpose and components of Availability Sets. Remember: 3 Fault Domains (FDs) protect against hardware failure, and 5-20 Update Domains (UDs) protect against planned maintenance. Know that VMs in an Availability Set must be in the same resource group and region.
Module 3: Deploying and Managing Azure Compute Resources
Confusing vertical and horizontal scaling; vertical is about one VM's power, horizontal is about many VMs.
Module 3: Deploying and Managing Azure Compute Resources
Believing Availability Sets protect against region-wide outages; they only protect within a single datacenter.
Module 3: Deploying and Managing Azure Compute Resources
Forgetting that VMs in an Availability Set must be the same size and in the same resource group/region.
Module 3: Deploying and Managing Azure Compute Resources
PaaS for hosting web apps, APIs, and mobile backends.
Module 3: Deploying and Managing Azure Compute Resources
Defines the compute resources (VMs, CPU, memory) for App Service apps.
Module 3: Deploying and Managing Azure Compute Resources
Platform as a Service; managed platform for app development.
Module 3: Deploying and Managing Azure Compute Resources
Using your own domain name for an App Service application.
Module 3: Deploying and Managing Azure Compute Resources
Automatically adjusts instance count based on performance metrics.
Module 3: Deploying and Managing Azure Compute Resources
Live app versions for staging, testing, and rollback.
Module 3: Deploying and Managing Azure Compute Resources
Secures communication over HTTPS for custom domains.
Module 3: Deploying and Managing Azure Compute Resources
Continuous Integration/Continuous Deployment for automated releases.
Module 3: Deploying and Managing Azure Compute Resources
P-A-A-S: 'P'latform, 'A'pps, 'A'utomated, 'S'calable. Remember App Service handles the infrastructure so you can focus on your code!
Module 3: Deploying and Managing Azure Compute Resources
For the AZ-104 exam, understand that an App Service Plan is billed, not the individual web apps within it. Also, know the difference between scaling 'up' (changing tier) and scaling 'out' (adding instances).
Module 3: Deploying and Managing Azure Compute Resources
Assuming each web app requires its own App Service Plan, leading to unnecessary costs.
Module 3: Deploying and Managing Azure Compute Resources
Not configuring auto-scaling, resulting in performance degradation during traffic spikes or overpaying for idle resources.
Module 3: Deploying and Managing Azure Compute Resources
Forgetting to bind an SSL certificate after configuring a custom domain, leaving the site insecure.
Module 3: Deploying and Managing Azure Compute Resources
Serverless service for running Docker containers directly on Azure.
Module 3: Deploying and Managing Azure Compute Resources
Top-level ACI resource; a collection of containers sharing resources.
Module 3: Deploying and Managing Azure Compute Resources
Cloud execution model where providers manage infrastructure.
Module 3: Deploying and Managing Azure Compute Resources
A lightweight, standalone, executable package of software.
Module 3: Deploying and Managing Azure Compute Resources
Managed registry service for storing Docker container images.
Module 3: Deploying and Managing Azure Compute Resources
Data that remains even after the container is stopped or deleted.
Module 3: Deploying and Managing Azure Compute Resources
Cost model where you pay only for actual compute time used.
Module 3: Deploying and Managing Azure Compute Resources
ACI: 'A Container, Immediately!' – think quick, simple, no fuss deployment.
Module 3: Deploying and Managing Azure Compute Resources
For the AZ-104 exam, understand when to choose ACI over AKS or App Service. ACI is for simple, isolated, short-lived workloads; AKS for complex, highly available microservices; App Service for web apps/APIs with managed platform features.
Module 3: Deploying and Managing Azure Compute Resources
Using ACI for complex, long-running microservice architectures that require advanced orchestration features like load balancing, service discovery, and auto-scaling across multiple nodes. AKS is better for this.
Module 3: Deploying and Managing Azure Compute Resources
Forgetting to specify adequate CPU and memory resources, leading to container crashes or poor performance.
Module 3: Deploying and Managing Azure Compute Resources
Not configuring persistent storage (e.g., Azure Files) for containers that need to retain data beyond their lifecycle, resulting in data loss.
Module 3: Deploying and Managing Azure Compute Resources
Logical subdivision of a VNet's IP address space.
Module 4: Implementing and Managing Virtual Networking
Method for allocating IP addresses and routing IP packets.
Module 4: Implementing and Managing Virtual Networking
Internal IP for VNet communication, not internet routable.
Module 4: Implementing and Managing Virtual Networking
Connects two Azure VNets securely across regions.
Module 4: Implementing and Managing Virtual Networking
Range of IP addresses assigned to a VNet.
Module 4: Implementing and Managing Virtual Networking
VNet: 'V'ery 'N'ice 'E'nvironment for 'T'raffic. Think of it as your own private club in the cloud!
Module 4: Implementing and Managing Virtual Networking
The exam often asks about VNet address space planning, specifically non-overlapping ranges for VNet peering or hybrid connections. Remember that Azure reserves 5 IP addresses per subnet for internal use.
Module 4: Implementing and Managing Virtual Networking
Using overlapping IP address ranges for VNets that need to communicate (e.g., via peering or VPN Gateway).
Module 4: Implementing and Managing Virtual Networking
Forgetting that Azure reserves 5 IP addresses in each subnet, leading to unexpected address shortages.
Module 4: Implementing and Managing Virtual Networking
Not configuring NSGs correctly, leaving resources exposed or blocking legitimate traffic.
Module 4: Implementing and Managing Virtual Networking
Connects on-premises networks to Azure over the public internet using encrypted tunnels.
Module 4: Implementing and Managing Virtual Networking
Establishes a private, dedicated connection between on-premises and Azure.
Module 4: Implementing and Managing Virtual Networking
Connects an entire on-premises network to an Azure VNet.
Module 4: Implementing and Managing Virtual Networking
Allows individual client computers to connect securely to an Azure VNet.
Module 4: Implementing and Managing Virtual Networking
An Azure object representing your on-premises VPN device or network.
Module 4: Implementing and Managing Virtual Networking
The logical connection that maps to a physical connection provided by a carrier.
Module 4: Implementing and Managing Virtual Networking
Configuration on ExpressRoute defining traffic routing to Azure services.
Module 4: Implementing and Managing Virtual Networking
VPN is 'Via Public Network', ExpressRoute is 'Exclusive Private Route'.
Module 4: Implementing and Managing Virtual Networking
Memorize the key differentiator: VPN Gateway uses the public internet for encrypted tunnels, while ExpressRoute uses a private, dedicated connection. Look for keywords like 'public internet', 'cost-effective', 'encrypted tunnel' for VPN Gateway, and 'private connection', 'high bandwidth', 'low latency', 'SLA' for ExpressRoute.
Module 4: Implementing and Managing Virtual Networking
Confusing VPN Gateway with ExpressRoute; remember one uses public internet, the other private.
Module 4: Implementing and Managing Virtual Networking
Underestimating bandwidth requirements and choosing VPN Gateway for high-throughput scenarios.
Module 4: Implementing and Managing Virtual Networking
Not considering redundancy; both can be combined for failover scenarios.
Module 4: Implementing and Managing Virtual Networking
A specific part of the DNS namespace managed by an authoritative DNS server.
Module 4: Implementing and Managing Virtual Networking
A DNS zone hosted in Azure for internet-resolvable domain names.
Module 4: Implementing and Managing Virtual Networking
A DNS zone hosted in Azure for name resolution within virtual networks.
Module 4: Implementing and Managing Virtual Networking
A collection of DNS records with the same name and type within a zone.
Module 4: Implementing and Managing Virtual Networking
Maps a domain name to an IPv4 address.
Module 4: Implementing and Managing Virtual Networking
Maps an alias domain name to another canonical domain name.
Module 4: Implementing and Managing Virtual Networking
The duration DNS resolvers cache a record before querying again.
Module 4: Implementing and Managing Virtual Networking
Remember 'P-P-R-V': Public for Public, Private for Private, Records for Resolution, Virtual Network for Visibility.
Module 4: Implementing and Managing Virtual Networking
For the AZ-104 exam, be prepared to differentiate between public and private DNS zones, understand when to use each, and know how to create and manage common record types like A, AAAA, CNAME, and MX. Pay attention to virtual network linking for private zones.
Module 4: Implementing and Managing Virtual Networking
Forgetting to delegate your public domain to Azure's name servers after creating a public DNS zone, leading to unresolved public domains.
Module 4: Implementing and Managing Virtual Networking
Not linking a private DNS zone to the correct virtual network, preventing VMs from resolving internal names.
Module 4: Implementing and Managing Virtual Networking
Using an excessively high TTL for critical records, which delays propagation of necessary DNS changes.
Module 4: Implementing and Managing Virtual Networking
Defines parameters like source, destination, port, protocol, and action for traffic.
Module 4: Implementing and Managing Virtual Networking
Determines the order in which NSG rules are evaluated (lower number = higher priority).
Module 4: Implementing and Managing Virtual Networking
System-provided literal string representing a group of IP prefixes for Azure services.
Module 4: Implementing and Managing Virtual Networking
Allows grouping of VMs by application structure for NSG rule definition.
Module 4: Implementing and Managing Virtual Networking
Built-in NSG rules that cannot be deleted but can be overridden by custom rules.
Module 4: Implementing and Managing Virtual Networking
The point where a VM connects to a virtual network.
Module 4: Implementing and Managing Virtual Networking
P-S-D-A: Priority, Source/Destination, Direction, Action. Remember these four main components of an NSG rule to quickly recall how to configure them.
Module 4: Implementing and Managing Virtual Networking
The exam frequently tests your understanding of NSG rule processing order. Remember: Inbound traffic is Subnet NSG then NIC NSG. Outbound traffic is NIC NSG then Subnet NSG. Both must allow for traffic to pass. Keywords to spot: 'rule priority', 'default rules', 'service tags', 'ASG'.
Module 4: Implementing and Managing Virtual Networking
Forgetting that NSG rules are processed by priority, and once a match is found, processing stops. A poorly ordered rule can inadvertently block or allow traffic.
Module 4: Implementing and Managing Virtual Networking
Not understanding the difference between applying an NSG to a subnet versus a network interface, especially how they interact for inbound and outbound traffic.
Module 4: Implementing and Managing Virtual Networking
Overlooking the default NSG rules, which can sometimes block traffic you intend to allow if your custom rules aren't configured with higher priority.
Module 4: Implementing and Managing Virtual Networking
Distributes network traffic at Layer 4 (TCP/UDP) across backend instances.
Module 4: Implementing and Managing Virtual Networking
Web traffic load balancer at Layer 7 (HTTP/HTTPS) with advanced features.
Module 4: Implementing and Managing Virtual Networking
A group of virtual machines or instances that receive traffic from a load balancer.
Module 4: Implementing and Managing Virtual Networking
Monitors the availability and health of instances in a backend pool.
Module 4: Implementing and Managing Virtual Networking
Decrypting encrypted traffic at the load balancer before forwarding to backend servers.
Module 4: Implementing and Managing Virtual Networking
Web Application Firewall; protects web apps from common vulnerabilities.
Module 4: Implementing and Managing Virtual Networking
Directing traffic to different backend pools based on the URL path.
Module 4: Implementing and Managing Virtual Networking
Ensuring requests from the same client go to the same backend server.
Module 4: Implementing and Managing Virtual Networking
L4 for LB (Load Balancer is Layer 4), L7 for AG (Application Gateway is Layer 7). Remember the numbers to recall their primary function!
Module 4: Implementing and Managing Virtual Networking
On the AZ-104 exam, pay close attention to scenario questions that describe web applications needing SSL/TLS offloading, WAF, or URL-based routing – these always point to Application Gateway. If it's just basic TCP/UDP distribution or internal services, think Load Balancer.
Module 4: Implementing and Managing Virtual Networking
Using Application Gateway for non-HTTP/HTTPS traffic, which is inefficient and costly.
Module 4: Implementing and Managing Virtual Networking
Forgetting to configure health probes, leading to traffic being sent to unhealthy instances.
Module 4: Implementing and Managing Virtual Networking
Not enabling WAF on Application Gateway when deploying public-facing web applications.
Module 4: Implementing and Managing Virtual Networking
Comprehensive solution for collecting, analyzing, and acting on telemetry data.
Module 5: Monitoring and Maintaining Azure Resources
Numerical values describing system aspects, ideal for real-time performance tracking.
Module 5: Monitoring and Maintaining Azure Resources
Detailed event records providing diagnostic information for root cause analysis.
Module 5: Monitoring and Maintaining Azure Resources
Azure service for ingesting, storing, and querying log data using KQL.
Module 5: Monitoring and Maintaining Azure Resources
Powerful query language used to interact with data in Log Analytics workspaces.
Module 5: Monitoring and Maintaining Azure Resources
Proactive notifications triggered by specific conditions in monitoring data.
Module 5: Monitoring and Maintaining Azure Resources
Define automated responses (e.g., email, SMS) when an Azure Monitor alert fires.
Module 5: Monitoring and Maintaining Azure Resources
M for Metrics = 'Measure' performance. L for Logs = 'Look' for details.
Module 5: Monitoring and Maintaining Azure Resources
The exam frequently tests your understanding of when to use metrics versus logs. Remember, metrics are for performance and availability (the 'what'), while logs are for diagnosis and auditing (the 'why'). Also, know that KQL is used for querying logs in Log Analytics.
Module 5: Monitoring and Maintaining Azure Resources
Confusing metrics and logs: Using logs for real-time performance dashboards or metrics for deep diagnostic analysis.
Module 5: Monitoring and Maintaining Azure Resources
Not configuring Action Groups: Creating alerts without defining what actions should be taken, leading to unhandled incidents.
Module 5: Monitoring and Maintaining Azure Resources
Ignoring Activity Logs: Overlooking the Activity Log for auditing and understanding control-plane operations in Azure.
Module 5: Monitoring and Maintaining Azure Resources
A central management entity for backups and recovery points.
Module 5: Monitoring and Maintaining Azure Resources
Defines backup frequency and retention settings for protected items.
Module 5: Monitoring and Maintaining Azure Resources
A point in time from which data can be restored; a snapshot.
Module 5: Monitoring and Maintaining Azure Resources
Protects against accidental deletion of backup data by retaining it.
Module 5: Monitoring and Maintaining Azure Resources
Restoring individual files or folders from a VM backup.
Module 5: Monitoring and Maintaining Azure Resources
Microsoft Azure Recovery Services agent for backing up on-premises data.
Module 5: Monitoring and Maintaining Azure Resources
V.P.R.S. (Vaults, Policies, Recovery points, Soft delete) – Remember these key elements for Azure Backup success!
Module 5: Monitoring and Maintaining Azure Resources
On the AZ-104 exam, pay close attention to the different components of Azure Backup (Vaults, Policies, Protected Items) and the types of resources it can protect. Understand the difference between full and incremental backups, and the purpose of soft delete.
Module 5: Monitoring and Maintaining Azure Resources
Forgetting to configure a backup policy after creating a Recovery Services vault.
Module 5: Monitoring and Maintaining Azure Resources
Not understanding the difference between restoring an entire VM and performing file-level recovery.
Module 5: Monitoring and Maintaining Azure Resources
Underestimating the importance of soft delete for accidental backup deletion protection.
Module 5: Monitoring and Maintaining Azure Resources
Copies only data changed since the last backup.
Module 5: Monitoring and Maintaining Azure Resources
Copies all selected data, regardless of changes.
Module 5: Monitoring and Maintaining Azure Resources
Rules for how long recovery points are stored.
Module 5: Monitoring and Maintaining Azure Resources
Vaults Protect Data: V for Vault (storage), P for Policy (rules), D for Data (VMs, SQL).
Module 5: Monitoring and Maintaining Azure Resources
The exam often tests your understanding of the relationship between Recovery Services vaults, backup policies, and protected items. Be prepared to identify the components and their roles in a backup solution.
Module 5: Monitoring and Maintaining Azure Resources
Not matching the Recovery Services vault region with the protected resources, leading to higher latency and costs.
Module 5: Monitoring and Maintaining Azure Resources
Configuring overly aggressive retention policies for non-critical data, resulting in unnecessary storage expenses.
Module 5: Monitoring and Maintaining Azure Resources
Forgetting to apply the created backup policy to the actual resources, leaving them unprotected.
Module 5: Monitoring and Maintaining Azure Resources
Azure's DRaaS for replication and failover
Module 5: Monitoring and Maintaining Azure Resources
Maximum tolerable data loss (time)
Module 5: Monitoring and Maintaining Azure Resources
Maximum tolerable downtime (time)
Module 5: Monitoring and Maintaining Azure Resources
Switching to replica during disaster
Module 5: Monitoring and Maintaining Azure Resources
Returning to primary after recovery
Module 5: Monitoring and Maintaining Azure Resources
Remember 'ASR' as 'Always Stay Running' – because that's what Azure Site Recovery helps your applications do!
Module 5: Monitoring and Maintaining Azure Resources
The AZ-104 exam frequently tests your understanding of ASR's capabilities, especially its role in business continuity and disaster recovery. Pay close attention to the different replication scenarios (on-premises to Azure, Azure to Azure) and the purpose of a Recovery Services vault.
Module 5: Monitoring and Maintaining Azure Resources
Forgetting to perform test failovers: Test failovers are crucial to validate your recovery plan and ensure it works as expected. Without testing, you can't be sure your DR strategy is effective.
Module 5: Monitoring and Maintaining Azure Resources
Not understanding the difference between RPO and RTO: These are distinct metrics. RPO is about data loss, RTO is about downtime. ASR aims to minimize both.
Module 5: Monitoring and Maintaining Azure Resources
Incorrectly configuring network settings for failover: During failover, the replicated VMs need to connect to the correct virtual networks and subnets in Azure. Misconfigurations can lead to inaccessible applications.
Module 5: Monitoring and Maintaining Azure Resources
Microsoft tool for synchronizing on-premises AD with Azure AD.
Module 6: Implementing and Managing Hybrid Identities
Combining on-premises and cloud identities for unified access.
Module 6: Implementing and Managing Hybrid Identities
Synchronizes a hash of the user's password to Azure AD.
Module 6: Implementing and Managing Hybrid Identities
Authenticates users against on-premises AD when accessing Azure AD.
Module 6: Implementing and Managing Hybrid Identities
Define how objects and attributes are synchronized between directories.
Module 6: Implementing and Managing Hybrid Identities
Allows testing configurations before applying to production.
Module 6: Implementing and Managing Hybrid Identities
Synchronizing changes from Azure AD back to on-premises AD.
Module 6: Implementing and Managing Hybrid Identities
Remember 'CONNECT' for Azure AD Connect: C-Credentials, O-On-premises AD, N-Network, N-New Server, E-Express/Custom, C-Cloud AD, T-Test.
Module 6: Implementing and Managing Hybrid Identities
The exam often tests the differences between PHS, PTA, and AD FS. Memorize which authentication method stores password hashes in Azure AD (PHS), which validates against on-premises AD (PTA), and which requires a federation server (AD FS). Also, know the default synchronization interval (30 minutes).
Module 6: Implementing and Managing Hybrid Identities
Not meeting all prerequisites before installation, leading to errors or incomplete synchronization.
Module 6: Implementing and Managing Hybrid Identities
Using 'Express Settings' without understanding its implications, potentially synchronizing unwanted OUs or attributes.
Module 6: Implementing and Managing Hybrid Identities
Forgetting to verify synchronization status and troubleshoot errors after initial setup, assuming it just works.
Module 6: Implementing and Managing Hybrid Identities
Cloud service for monitoring hybrid identity components.
Module 6: Implementing and Managing Hybrid Identities
Software installed on servers to collect and transmit data.
Module 6: Implementing and Managing Hybrid Identities
The component of Azure AD Connect responsible for data flow.
Module 6: Implementing and Managing Hybrid Identities