Free knowledge base

Microsoft Certified: Azure Administrator Associate — key terms, tricks & tips

Everything from the course in one searchable place: 326 entries. Use it to review before a practice test or look up a word you forgot.

326 results · showing first 300, refine your search

Key term

Functional Group

A major section of the exam objectives, like 'Manage Azure identities and governance'.

Getting Started: Exam AZ-104 Overview

Key term

Weighting

The percentage of the exam dedicated to a specific functional group.

Getting Started: Exam AZ-104 Overview

Key term

Case Study

An exam question format presenting a detailed business scenario.

Getting Started: Exam AZ-104 Overview

Key term

Performance-Based Lab

An exam section where you perform tasks in a simulated Azure environment.

Getting Started: Exam AZ-104 Overview

Key term

Skills Measured Document

Official Microsoft document detailing all specific topics covered by an exam.

Getting Started: Exam AZ-104 Overview

Key term

Multiple-Choice Question

A question type where you select one or more correct answers from a list.

Getting Started: Exam AZ-104 Overview

Key term

Drag-and-Drop Question

A question type where you match items by dragging them to correct targets.

Getting Started: Exam AZ-104 Overview

Memory trick

AZ-104 Exam Structure and Objectives

To remember the exam's focus areas, think 'I S C N M': Identities, Storage, Compute, Networking, Monitoring. It's like a 'SCAN' of Azure!

Getting Started: Exam AZ-104 Overview

Exam tip

AZ-104 Exam Structure and Objectives

The AZ-104 exam was updated in January 2024. Always check the official Microsoft Learn page for the most current 'Skills Measured' document to ensure your study materials are up-to-date.

Getting Started: Exam AZ-104 Overview

Common mistake

AZ-104 Exam Structure and Objectives

Not checking the latest 'Skills Measured' document, leading to studying outdated topics.

Getting Started: Exam AZ-104 Overview

Common mistake

AZ-104 Exam Structure and Objectives

Ignoring exam objective weightings and spending too much time on less important areas.

Getting Started: Exam AZ-104 Overview

Common mistake

AZ-104 Exam Structure and Objectives

Only memorizing facts without understanding how to apply them in real-world scenarios, especially for case studies.

Getting Started: Exam AZ-104 Overview

Key term

Azure Portal

Web-based console for managing Azure resources.

Getting Started: Exam AZ-104 Overview

Key term

Azure Free Account

Provides $200 credit and free services for 12 months.

Getting Started: Exam AZ-104 Overview

Key term

Pay-As-You-Go

Subscription model where you pay for what you use.

Getting Started: Exam AZ-104 Overview

Key term

Resource Group

Logical container for Azure resources.

Getting Started: Exam AZ-104 Overview

Key term

Cloud Shell

Browser-based command-line interface for Azure.

Getting Started: Exam AZ-104 Overview

Key term

Azure Credits

Monetary balance for consuming Azure services.

Getting Started: Exam AZ-104 Overview

Key term

Subscription

Billing unit for Azure services and resources.

Getting Started: Exam AZ-104 Overview

Memory trick

Setting Up Your Azure Free Account and Learning Environment

To remember the free account setup, think 'M-P-C-A-P': Microsoft account, Profile, Phone, Credit card, Access Portal.

Getting Started: Exam AZ-104 Overview

Exam tip

Setting Up Your Azure Free Account and Learning Environment

The AZ-104 exam frequently tests your ability to identify the correct tool or service for a given task within the Azure portal. Keywords like 'create a virtual machine' or 'monitor resource costs' should immediately make you think of navigating the portal or using specific portal features.

Getting Started: Exam AZ-104 Overview

Common mistake

Setting Up Your Azure Free Account and Learning Environment

Forgetting to delete resources after practice, leading to unexpected charges if you upgrade to Pay-As-You-Go.

Getting Started: Exam AZ-104 Overview

Common mistake

Setting Up Your Azure Free Account and Learning Environment

Not monitoring your free credit usage, causing services to stop unexpectedly when credits are exhausted.

Getting Started: Exam AZ-104 Overview

Common mistake

Setting Up Your Azure Free Account and Learning Environment

Attempting to use advanced or high-tier services that quickly consume free credits or are not included in the free tier.

Getting Started: Exam AZ-104 Overview

Key term

Azure AD User

An individual identity used to sign in and access resources.

Module 1: Managing Azure Identities and Governance

Key term

Security Group

Used to manage access to Azure resources and applications.

Module 1: Managing Azure Identities and Governance

Key term

Microsoft 365 Group

For collaboration and access to shared resources like mailboxes.

Module 1: Managing Azure Identities and Governance

Key term

Azure AD Joined

Corporate devices managed entirely by Azure AD.

Module 1: Managing Azure Identities and Governance

Key term

Azure AD Registered

Personal devices integrated with Azure AD for resource access.

Module 1: Managing Azure Identities and Governance

Key term

Hybrid Azure AD Joined

Domain-joined devices also registered with Azure AD.

Module 1: Managing Azure Identities and Governance

Key term

User Principal Name (UPN)

The unique identifier for an Azure AD user account (e.g., user@domain.com).

Module 1: Managing Azure Identities and Governance

Memory trick

Managing Azure AD Objects: Users, Groups, and Devices

Users are 'People', Groups are 'Teams', Devices are 'Tools'. P-T-T helps you remember the main object types!

Module 1: Managing Azure Identities and Governance

Exam tip

Managing Azure AD Objects: Users, Groups, and Devices

The exam often distinguishes between Azure AD joined, Azure AD registered, and Hybrid Azure AD joined devices. Memorize their primary use cases and management characteristics. Also, know the difference between Security groups and Microsoft 365 groups.

Module 1: Managing Azure Identities and Governance

Common mistake

Managing Azure AD Objects: Users, Groups, and Devices

Assigning permissions directly to individual users instead of using groups, leading to complex and hard-to-manage access controls.

Module 1: Managing Azure Identities and Governance

Common mistake

Managing Azure AD Objects: Users, Groups, and Devices

Not implementing a consistent naming convention for users, groups, and devices, making it difficult to identify and manage objects.

Module 1: Managing Azure Identities and Governance

Common mistake

Managing Azure AD Objects: Users, Groups, and Devices

Failing to regularly review and clean up stale user accounts or unused groups, creating potential security vulnerabilities.

Module 1: Managing Azure Identities and Governance

Key term

Role-Based Access Control (RBAC)

System for managing who has access to Azure resources and what they can do.

Module 1: Managing Azure Identities and Governance

Key term

Security Principal

An object representing a user, group, service, or identity requesting access.

Module 1: Managing Azure Identities and Governance

Key term

Role Definition

A collection of permissions that defines what actions can be performed.

Module 1: Managing Azure Identities and Governance

Key term

Scope

The set of resources to which an RBAC assignment applies (e.g., subscription, resource group).

Module 1: Managing Azure Identities and Governance

Key term

Principle of Least Privilege

Security concept of granting only the minimum necessary permissions for a task.

Module 1: Managing Azure Identities and Governance

Key term

Built-in Roles

Predefined RBAC roles provided by Azure (e.g., Owner, Contributor, Reader).

Module 1: Managing Azure Identities and Governance

Key term

Custom Roles

User-defined RBAC roles with specific, tailored sets of permissions.

Module 1: Managing Azure Identities and Governance

Key term

Inheritance

Permissions assigned at a higher scope automatically apply to lower scopes.

Module 1: Managing Azure Identities and Governance

Memory trick

Implementing Role-Based Access Control (RBAC)

To remember the RBAC components, think 'Who Can Do What, Where?'. 'Who' is the Security Principal, 'Can Do What' is the Role Definition, and 'Where' is the Scope.

Module 1: Managing Azure Identities and Governance

Exam tip

Implementing Role-Based Access Control (RBAC)

Memorize the core components of an RBAC assignment: security principal, role definition, and scope. Be ready to differentiate between built-in roles like Owner, Contributor, and Reader, and understand how permissions inherit down the Azure resource hierarchy.

Module 1: Managing Azure Identities and Governance

Common mistake

Implementing Role-Based Access Control (RBAC)

Assigning the 'Owner' role too broadly instead of using more restrictive roles like 'Contributor' or 'Reader'.

Module 1: Managing Azure Identities and Governance

Common mistake

Implementing Role-Based Access Control (RBAC)

Forgetting that permissions are inherited, leading to unintended access at lower levels of the resource hierarchy.

Module 1: Managing Azure Identities and Governance

Common mistake

Implementing Role-Based Access Control (RBAC)

Not regularly reviewing and removing outdated role assignments, creating security vulnerabilities.

Module 1: Managing Azure Identities and Governance

Key term

Azure Subscription

A logical container linking Azure services to an account for billing and management.

Module 1: Managing Azure Identities and Governance

Key term

Azure Account

The entity that owns Azure subscriptions and manages billing.

Module 1: Managing Azure Identities and Governance

Key term

Azure AD Tenant

Provides identity and access management for Azure subscriptions and resources.

Module 1: Managing Azure Identities and Governance

Key term

Billing Unit

The level at which costs are aggregated and charged in Azure.

Module 1: Managing Azure Identities and Governance

Key term

Management Boundary

A scope where policies, access, and governance can be applied.

Module 1: Managing Azure Identities and Governance

Key term

Resource Lifecycle

The process of creating, managing, and deleting Azure resources.

Module 1: Managing Azure Identities and Governance

Memory trick

Understanding Azure Subscriptions and Resource Groups

Imagine 'S'ubscriptions are like 'S'eparate bank accounts for your cloud spending, and 'R'esource 'G'roups are like 'R'elated folders within those accounts.

Module 1: Managing Azure Identities and Governance

Exam tip

Understanding Azure Subscriptions and Resource Groups

Memorize that a resource can only belong to ONE resource group, but a resource group can contain resources from MULTIPLE regions. Also, resource groups cannot be nested.

Module 1: Managing Azure Identities and Governance

Common mistake

Understanding Azure Subscriptions and Resource Groups

Confusing resource group deletion with resource deletion; deleting a resource group deletes ALL contained resources.

Module 1: Managing Azure Identities and Governance

Common mistake

Understanding Azure Subscriptions and Resource Groups

Assuming resource groups are tied to a specific region; they are logical containers and can hold resources from different regions.

Module 1: Managing Azure Identities and Governance

Common mistake

Understanding Azure Subscriptions and Resource Groups

Trying to nest resource groups; Azure does not support nested resource groups.

Module 1: Managing Azure Identities and Governance

Key term

Azure Policy

Service to enforce organizational standards and assess compliance at scale.

Module 1: Managing Azure Identities and Governance

Key term

Policy Definition

Specifies the condition and effect of an Azure Policy rule.

Module 1: Managing Azure Identities and Governance

Key term

Policy Assignment

Applying a policy definition to a specific scope (management group, subscription, resource group).

Module 1: Managing Azure Identities and Governance

Key term

Policy Initiative

A collection of policy definitions grouped for a larger goal; also called a policy set.

Module 1: Managing Azure Identities and Governance

Key term

Policy Effect

The action taken by Azure Policy when a resource is non-compliant (e.g., Deny, Audit).

Module 1: Managing Azure Identities and Governance

Key term

Resource Lock

Prevents accidental deletion or modification of Azure resources, overriding permissions.

Module 1: Managing Azure Identities and Governance

Key term

CanNotDelete Lock

Resource lock type that prevents deletion but allows modification.

Module 1: Managing Azure Identities and Governance

Key term

ReadOnly Lock

Resource lock type that prevents both modification and deletion.

Module 1: Managing Azure Identities and Governance

Memory trick

Implementing Azure Policy and Resource Locks

To remember Policy effects, think 'D.A.D. M.' - Deny, Audit, DeployIfNotExists, Modify. Like a strict but helpful DAD who helps manage your resources!

Module 1: Managing Azure Identities and Governance

Exam tip

Implementing Azure Policy and Resource Locks

On the AZ-104 exam, pay close attention to the specific 'effect' of an Azure Policy. Questions often test your understanding of what happens when a policy with a 'Deny' effect versus an 'Audit' effect is triggered. Also, distinguish clearly between Azure Policy (rules-based compliance) and Resource Locks (preventing accidental changes).

Module 1: Managing Azure Identities and Governance

Common mistake

Implementing Azure Policy and Resource Locks

Confusing Azure Policy with Role-Based Access Control (RBAC). RBAC controls 'who' can do 'what' to resources, while Policy defines 'what' configurations are allowed for resources.

Module 1: Managing Azure Identities and Governance

Common mistake

Implementing Azure Policy and Resource Locks

Applying a 'Deny' policy without thoroughly testing it, which can inadvertently block legitimate operations and cause outages.

Module 1: Managing Azure Identities and Governance

Common mistake

Implementing Azure Policy and Resource Locks

Forgetting that Resource Locks apply to all users, including subscription owners, and must be removed before locked actions can be performed.

Module 1: Managing Azure Identities and Governance

Key term

Shared Access Signature (SAS)

A URI that grants restricted access to Azure Storage resources.

Module 2: Implementing and Managing Storage

Key term

User Delegation SAS

SAS secured with Azure AD credentials, recommended for Blob storage.

Module 2: Implementing and Managing Storage

Key term

Azure RBAC

Authorization system managing who has access to Azure resources.

Module 2: Implementing and Managing Storage

Key term

Storage Service Encryption (SSE)

Automatic encryption of data at rest in Azure Storage.

Module 2: Implementing and Managing Storage

Key term

Customer-Managed Keys (CMK)

Encryption keys stored in Azure Key Vault for storage encryption.

Module 2: Implementing and Managing Storage

Key term

Azure Storage Firewall

Configures network rules to limit access to a storage account.

Module 2: Implementing and Managing Storage

Key term

Service Endpoint

Extends VNet identity to Azure services over the Azure backbone.

Module 2: Implementing and Managing Storage

Key term

Private Endpoint

Provides a private IP for an Azure service within a VNet.

Module 2: Implementing and Managing Storage

Memory trick

Securing Azure Storage Accounts and Data

SAS-sy access: Shared Access Signatures give you a 'sassy' way to share just what's needed, for just how long, and to just who.

Module 2: Implementing and Managing Storage

Exam tip

Securing Azure Storage Accounts and Data

The exam frequently tests the differences between SAS types (User Delegation vs. Service vs. Account) and when to use each. Also, know that SSE is automatic for data at rest, and CMK is an option for increased control.

Module 2: Implementing and Managing Storage

Common mistake

Securing Azure Storage Accounts and Data

Over-provisioning SAS permissions: Granting 'write' when only 'read' is needed.

Module 2: Implementing and Managing Storage

Common mistake

Securing Azure Storage Accounts and Data

Forgetting to set an expiry time for SAS tokens, leading to perpetual access.

Module 2: Implementing and Managing Storage

Common mistake

Securing Azure Storage Accounts and Data

Not enabling 'Require secure transfer' for storage accounts, allowing unencrypted HTTP access.

Module 2: Implementing and Managing Storage

Key term

Storage Account

A unique container for all your Azure Storage data.

Module 2: Implementing and Managing Storage

Key term

GPv2

General-purpose v2, recommended storage account type.

Module 2: Implementing and Managing Storage

Key term

LRS

Local Redundant Storage, 3 copies in one data center.

Module 2: Implementing and Managing Storage

Key term

ZRS

Zone Redundant Storage, 3 copies across availability zones.

Module 2: Implementing and Managing Storage

Key term

GRS

Geo-Redundant Storage, LRS + async copy to another region.

Module 2: Implementing and Managing Storage

Key term

RA-GRS

Read-access GRS, GRS with read access to secondary region.

Module 2: Implementing and Managing Storage

Key term

RPO

Recovery Point Objective, max tolerable data loss.

Module 2: Implementing and Managing Storage

Key term

RTO

Recovery Time Objective, max tolerable downtime.

Module 2: Implementing and Managing Storage

Memory trick

Managing Azure Storage Accounts and Data Redundancy

Remember 'L-Z-G-R' for redundancy: Local, Zone, Geo, Read-access Geo. It's like upgrading your data's 'safety net' from your house to the whole world!

Module 2: Implementing and Managing Storage

Exam tip

Managing Azure Storage Accounts and Data Redundancy

The exam often presents scenarios requiring you to choose the best storage redundancy option based on cost, durability, availability, and performance requirements. Pay close attention to keywords like 'regional disaster', 'lowest cost', 'high availability within a region', and 'read access to secondary'.

Module 2: Implementing and Managing Storage

Common mistake

Managing Azure Storage Accounts and Data Redundancy

Choosing GRS for non-critical data, leading to unnecessary costs.

Module 2: Implementing and Managing Storage

Common mistake

Managing Azure Storage Accounts and Data Redundancy

Not understanding that GRS/RA-GRS replication is asynchronous, meaning potential data loss during a failover.

Module 2: Implementing and Managing Storage

Common mistake

Managing Azure Storage Accounts and Data Redundancy

Selecting LRS for data that requires protection against regional outages.

Module 2: Implementing and Managing Storage

Key term

Azure Files

Fully managed cloud file shares accessible via SMB/NFS.

Module 2: Implementing and Managing Storage

Key term

Azure File Sync

Synchronizes on-premises file servers with Azure Files.

Module 2: Implementing and Managing Storage

Key term

Storage Sync Service

Azure resource for managing File Sync deployments.

Module 2: Implementing and Managing Storage

Key term

Sync Group

Defines the synchronization topology between endpoints.

Module 2: Implementing and Managing Storage

Key term

Cloud Endpoint

The Azure file share within a Sync Group.

Module 2: Implementing and Managing Storage

Key term

Server Endpoint

A specific path on an on-premises Windows Server to sync.

Module 2: Implementing and Managing Storage

Key term

Azure File Sync Agent

Software installed on Windows Server for synchronization.

Module 2: Implementing and Managing Storage

Key term

Cloud Tiering

Moves infrequently accessed files to Azure, freeing local space.

Module 2: Implementing and Managing Storage

Memory trick

Configuring Azure Files and File Sync

To remember the File Sync components, think 'S.S.S.C.S.A.': Storage Sync Service, Sync Group, Server Endpoint, Cloud Endpoint, Sync Agent. It's a 'Sync Server Solution, Cloud-Side, Agent-powered!'

Module 2: Implementing and Managing Storage

Exam tip

Configuring Azure Files and File Sync

For the AZ-104 exam, remember that Azure File Sync requires a Windows Server operating system. You cannot use it to sync directly from client machines or other operating systems. Also, know the order of operations for setting up File Sync: Storage Sync Service -> Sync Group -> Cloud Endpoint (Azure File Share) -> Server Endpoint (on-premises path).

Module 2: Implementing and Managing Storage

Common mistake

Configuring Azure Files and File Sync

Forgetting to install the Azure File Sync agent on the on-premises server before attempting to register it.

Module 2: Implementing and Managing Storage

Common mistake

Configuring Azure Files and File Sync

Not configuring proper network access (e.g., firewall rules) between the on-premises server and Azure.

Module 2: Implementing and Managing Storage

Common mistake

Configuring Azure Files and File Sync

Attempting to use Azure File Sync with an unsupported operating system or a non-Windows Server machine.

Module 2: Implementing and Managing Storage

Common mistake

Configuring Azure Files and File Sync

Not enabling cloud tiering when local disk space optimization is a requirement, leading to full local drives.

Module 2: Implementing and Managing Storage

Key term

Hot access tier

For frequently accessed data, highest storage cost, lowest access cost.

Module 2: Implementing and Managing Storage

Key term

Cool access tier

For infrequently accessed data, lower storage cost, higher access cost.

Module 2: Implementing and Managing Storage

Key term

Archive access tier

For rarely accessed data, lowest storage cost, highest retrieval cost/latency.

Module 2: Implementing and Managing Storage

Key term

Rehydration

Process of moving data from Archive to Hot/Cool for access.

Module 2: Implementing and Managing Storage

Key term

Lifecycle management

Rule-based policy to automate blob tiering and deletion.

Module 2: Implementing and Managing Storage

Key term

Access costs

Costs associated with reading or writing data to a storage tier.

Module 2: Implementing and Managing Storage

Key term

Storage costs

Costs associated with storing data in a particular tier per GB.

Module 2: Implementing and Managing Storage

Memory trick

Working with Azure Blob Storage: Tiers and Lifecycle

HCA: Hot, Cool, Archive. Remember it as 'How Can Anyone' forget the tiers!

Module 2: Implementing and Managing Storage

Exam tip

Working with Azure Blob Storage: Tiers and Lifecycle

Memorize the characteristics of each blob storage tier: Hot (frequent, high storage cost, low access), Cool (infrequent, lower storage, higher access), Archive (rare, lowest storage, highest access/latency). Pay attention to the rehydration process for Archive.

Module 2: Implementing and Managing Storage

Common mistake

Working with Azure Blob Storage: Tiers and Lifecycle

Not implementing lifecycle management, leading to unnecessarily high storage costs for old data.

Module 2: Implementing and Managing Storage

Common mistake

Working with Azure Blob Storage: Tiers and Lifecycle

Using the Archive tier for data that needs immediate or frequent access, causing high rehydration costs and delays.

Module 2: Implementing and Managing Storage

Common mistake

Working with Azure Blob Storage: Tiers and Lifecycle

Forgetting that data in the Archive tier is offline and requires rehydration before it can be accessed.

Module 2: Implementing and Managing Storage

Key term

Infrastructure as Code (IaC)

Managing infrastructure through code, not manual processes.

Module 3: Deploying and Managing Azure Compute Resources

Key term

ARM Template

JSON file defining Azure resources for declarative deployment.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Azure CLI

Command-line interface for managing Azure resources.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Parameters

Values passed into an ARM template at deployment time.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Resources

Azure services defined within an ARM template.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Declarative Deployment

Specifying desired state, not steps to achieve it.

Module 3: Deploying and Managing Azure Compute Resources

Memory trick

Automating VM Deployment with ARM Templates and Azure CLI

To remember ARM template sections: 'PVR' - Parameters, Variables, Resources. Like a 'PVR' for your Azure infrastructure!

Module 3: Deploying and Managing Azure Compute Resources

Exam tip

Automating VM Deployment with ARM Templates and Azure CLI

The AZ-104 exam frequently tests your ability to identify the correct Azure CLI commands for deploying resources using ARM templates. Pay close attention to `az deployment group create` and its required parameters like `--resource-group`, `--name`, and `--template-file`.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Automating VM Deployment with ARM Templates and Azure CLI

Forgetting to specify the resource group or deployment name when using `az deployment group create`.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Automating VM Deployment with ARM Templates and Azure CLI

Incorrectly referencing parameter names or values in the ARM template or CLI command, leading to deployment failures.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Automating VM Deployment with ARM Templates and Azure CLI

Not validating the ARM template before deployment, causing errors that could have been caught earlier.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Virtual Machine (VM)

On-demand, scalable computing resource in the cloud.

Module 3: Deploying and Managing Azure Compute Resources

Key term

VM Size

Defines CPU, memory, and disk capacity of a VM.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Managed Disks

Azure-managed storage for VM disks, recommended for use.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Network Security Group (NSG)

Virtual firewall controlling network traffic to/from Azure resources.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Virtual Network (VNet)

Logically isolated network in Azure for your resources.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Public IP Address

Allows internet access to an Azure resource.

Module 3: Deploying and Managing Azure Compute Resources

Key term

SSH

Secure Shell, used for remote access to Linux VMs.

Module 3: Deploying and Managing Azure Compute Resources

Memory trick

Implementing Azure Virtual Machines: Creation and Configuration

To remember VM creation steps: 'R-OS-D-N-C' - Resource Group, OS/Size, Disks, Networking, Connect. It's like building blocks for your cloud server!

Module 3: Deploying and Managing Azure Compute Resources

Exam tip

Implementing Azure Virtual Machines: Creation and Configuration

The AZ-104 exam frequently tests your knowledge of VM sizing, disk types (Standard HDD, Standard SSD, Premium SSD), and Network Security Group (NSG) rules. Pay close attention to the impact of these choices on cost and performance. Remember that NSGs are evaluated by priority, and 'Deny' rules override 'Allow' rules at the same priority.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Implementing Azure Virtual Machines: Creation and Configuration

Forgetting to open necessary ports in the Network Security Group (NSG), leading to connectivity issues.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Implementing Azure Virtual Machines: Creation and Configuration

Choosing an incorrect VM size or disk type, resulting in either overspending or poor performance.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Implementing Azure Virtual Machines: Creation and Configuration

Not configuring proper authentication (e.g., strong password or SSH key) for VM access, creating security vulnerabilities.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Vertical Scaling

Increasing or decreasing resources of a single VM (scaling up/down).

Module 3: Deploying and Managing Azure Compute Resources

Key term

Horizontal Scaling

Adding or removing VM instances to distribute workload (scaling out/in).

Module 3: Deploying and Managing Azure Compute Resources

Key term

Availability Set

Logical grouping of VMs that ensures high availability during outages.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Fault Domain

Group of VMs sharing common power/network, protecting against hardware failure.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Update Domain

Group of VMs that can be rebooted simultaneously during planned maintenance.

Module 3: Deploying and Managing Azure Compute Resources

Key term

VM Scale Set (VMSS)

Manages a group of identical, load-balanced VMs for horizontal scaling.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Planned Maintenance

Azure-initiated updates to the underlying platform infrastructure.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Unplanned Downtime

Unexpected outages due to hardware failures or other unforeseen events.

Module 3: Deploying and Managing Azure Compute Resources

Memory trick

Managing Azure VMs: Scaling, Availability, and Updates

To remember Fault vs. Update Domains: 'F' for Fault, 'F' for Failure (hardware). 'U' for Update, 'U' for Upgrade (planned maintenance).

Module 3: Deploying and Managing Azure Compute Resources

Exam tip

Managing Azure VMs: Scaling, Availability, and Updates

The exam often tests the purpose and components of Availability Sets. Remember: 3 Fault Domains (FDs) protect against hardware failure, and 5-20 Update Domains (UDs) protect against planned maintenance. Know that VMs in an Availability Set must be in the same resource group and region.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Managing Azure VMs: Scaling, Availability, and Updates

Confusing vertical and horizontal scaling; vertical is about one VM's power, horizontal is about many VMs.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Managing Azure VMs: Scaling, Availability, and Updates

Believing Availability Sets protect against region-wide outages; they only protect within a single datacenter.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Managing Azure VMs: Scaling, Availability, and Updates

Forgetting that VMs in an Availability Set must be the same size and in the same resource group/region.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Azure App Service

PaaS for hosting web apps, APIs, and mobile backends.

Module 3: Deploying and Managing Azure Compute Resources

Key term

App Service Plan

Defines the compute resources (VMs, CPU, memory) for App Service apps.

Module 3: Deploying and Managing Azure Compute Resources

Key term

PaaS

Platform as a Service; managed platform for app development.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Custom Domain

Using your own domain name for an App Service application.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Auto-scaling

Automatically adjusts instance count based on performance metrics.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Deployment Slot

Live app versions for staging, testing, and rollback.

Module 3: Deploying and Managing Azure Compute Resources

Key term

SSL/TLS Certificate

Secures communication over HTTPS for custom domains.

Module 3: Deploying and Managing Azure Compute Resources

Key term

CI/CD

Continuous Integration/Continuous Deployment for automated releases.

Module 3: Deploying and Managing Azure Compute Resources

Memory trick

Implementing Azure App Service for Web Applications

P-A-A-S: 'P'latform, 'A'pps, 'A'utomated, 'S'calable. Remember App Service handles the infrastructure so you can focus on your code!

Module 3: Deploying and Managing Azure Compute Resources

Exam tip

Implementing Azure App Service for Web Applications

For the AZ-104 exam, understand that an App Service Plan is billed, not the individual web apps within it. Also, know the difference between scaling 'up' (changing tier) and scaling 'out' (adding instances).

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Implementing Azure App Service for Web Applications

Assuming each web app requires its own App Service Plan, leading to unnecessary costs.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Implementing Azure App Service for Web Applications

Not configuring auto-scaling, resulting in performance degradation during traffic spikes or overpaying for idle resources.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Implementing Azure App Service for Web Applications

Forgetting to bind an SSL certificate after configuring a custom domain, leaving the site insecure.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Azure Container Instances (ACI)

Serverless service for running Docker containers directly on Azure.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Container Group

Top-level ACI resource; a collection of containers sharing resources.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Serverless

Cloud execution model where providers manage infrastructure.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Docker Image

A lightweight, standalone, executable package of software.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Azure Container Registry (ACR)

Managed registry service for storing Docker container images.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Persistent Storage

Data that remains even after the container is stopped or deleted.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Per-second billing

Cost model where you pay only for actual compute time used.

Module 3: Deploying and Managing Azure Compute Resources

Memory trick

Deploying and Managing Azure Container Instances (ACI)

ACI: 'A Container, Immediately!' – think quick, simple, no fuss deployment.

Module 3: Deploying and Managing Azure Compute Resources

Exam tip

Deploying and Managing Azure Container Instances (ACI)

For the AZ-104 exam, understand when to choose ACI over AKS or App Service. ACI is for simple, isolated, short-lived workloads; AKS for complex, highly available microservices; App Service for web apps/APIs with managed platform features.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Deploying and Managing Azure Container Instances (ACI)

Using ACI for complex, long-running microservice architectures that require advanced orchestration features like load balancing, service discovery, and auto-scaling across multiple nodes. AKS is better for this.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Deploying and Managing Azure Container Instances (ACI)

Forgetting to specify adequate CPU and memory resources, leading to container crashes or poor performance.

Module 3: Deploying and Managing Azure Compute Resources

Common mistake

Deploying and Managing Azure Container Instances (ACI)

Not configuring persistent storage (e.g., Azure Files) for containers that need to retain data beyond their lifecycle, resulting in data loss.

Module 3: Deploying and Managing Azure Compute Resources

Key term

Subnet

Logical subdivision of a VNet's IP address space.

Module 4: Implementing and Managing Virtual Networking

Key term

CIDR (Classless Inter-Domain Routing)

Method for allocating IP addresses and routing IP packets.

Module 4: Implementing and Managing Virtual Networking

Key term

Private IP Address

Internal IP for VNet communication, not internet routable.

Module 4: Implementing and Managing Virtual Networking

Key term

VNet Peering

Connects two Azure VNets securely across regions.

Module 4: Implementing and Managing Virtual Networking

Key term

Address Space

Range of IP addresses assigned to a VNet.

Module 4: Implementing and Managing Virtual Networking

Memory trick

Implementing Azure Virtual Networks and Subnets

VNet: 'V'ery 'N'ice 'E'nvironment for 'T'raffic. Think of it as your own private club in the cloud!

Module 4: Implementing and Managing Virtual Networking

Exam tip

Implementing Azure Virtual Networks and Subnets

The exam often asks about VNet address space planning, specifically non-overlapping ranges for VNet peering or hybrid connections. Remember that Azure reserves 5 IP addresses per subnet for internal use.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure Virtual Networks and Subnets

Using overlapping IP address ranges for VNets that need to communicate (e.g., via peering or VPN Gateway).

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure Virtual Networks and Subnets

Forgetting that Azure reserves 5 IP addresses in each subnet, leading to unexpected address shortages.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure Virtual Networks and Subnets

Not configuring NSGs correctly, leaving resources exposed or blocking legitimate traffic.

Module 4: Implementing and Managing Virtual Networking

Key term

VPN Gateway

Connects on-premises networks to Azure over the public internet using encrypted tunnels.

Module 4: Implementing and Managing Virtual Networking

Key term

ExpressRoute

Establishes a private, dedicated connection between on-premises and Azure.

Module 4: Implementing and Managing Virtual Networking

Key term

Site-to-Site VPN

Connects an entire on-premises network to an Azure VNet.

Module 4: Implementing and Managing Virtual Networking

Key term

Point-to-Site VPN

Allows individual client computers to connect securely to an Azure VNet.

Module 4: Implementing and Managing Virtual Networking

Key term

Local Network Gateway

An Azure object representing your on-premises VPN device or network.

Module 4: Implementing and Managing Virtual Networking

Key term

ExpressRoute Circuit

The logical connection that maps to a physical connection provided by a carrier.

Module 4: Implementing and Managing Virtual Networking

Key term

Peering

Configuration on ExpressRoute defining traffic routing to Azure services.

Module 4: Implementing and Managing Virtual Networking

Memory trick

Securing Access to Virtual Networks: VPN Gateway & ExpressRoute

VPN is 'Via Public Network', ExpressRoute is 'Exclusive Private Route'.

Module 4: Implementing and Managing Virtual Networking

Exam tip

Securing Access to Virtual Networks: VPN Gateway & ExpressRoute

Memorize the key differentiator: VPN Gateway uses the public internet for encrypted tunnels, while ExpressRoute uses a private, dedicated connection. Look for keywords like 'public internet', 'cost-effective', 'encrypted tunnel' for VPN Gateway, and 'private connection', 'high bandwidth', 'low latency', 'SLA' for ExpressRoute.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Securing Access to Virtual Networks: VPN Gateway & ExpressRoute

Confusing VPN Gateway with ExpressRoute; remember one uses public internet, the other private.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Securing Access to Virtual Networks: VPN Gateway & ExpressRoute

Underestimating bandwidth requirements and choosing VPN Gateway for high-throughput scenarios.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Securing Access to Virtual Networks: VPN Gateway & ExpressRoute

Not considering redundancy; both can be combined for failover scenarios.

Module 4: Implementing and Managing Virtual Networking

Key term

DNS Zone

A specific part of the DNS namespace managed by an authoritative DNS server.

Module 4: Implementing and Managing Virtual Networking

Key term

Public DNS Zone

A DNS zone hosted in Azure for internet-resolvable domain names.

Module 4: Implementing and Managing Virtual Networking

Key term

Private DNS Zone

A DNS zone hosted in Azure for name resolution within virtual networks.

Module 4: Implementing and Managing Virtual Networking

Key term

Record Set

A collection of DNS records with the same name and type within a zone.

Module 4: Implementing and Managing Virtual Networking

Key term

A Record

Maps a domain name to an IPv4 address.

Module 4: Implementing and Managing Virtual Networking

Key term

CNAME Record

Maps an alias domain name to another canonical domain name.

Module 4: Implementing and Managing Virtual Networking

Key term

TTL (Time-To-Live)

The duration DNS resolvers cache a record before querying again.

Module 4: Implementing and Managing Virtual Networking

Memory trick

Implementing Azure DNS for Name Resolution

Remember 'P-P-R-V': Public for Public, Private for Private, Records for Resolution, Virtual Network for Visibility.

Module 4: Implementing and Managing Virtual Networking

Exam tip

Implementing Azure DNS for Name Resolution

For the AZ-104 exam, be prepared to differentiate between public and private DNS zones, understand when to use each, and know how to create and manage common record types like A, AAAA, CNAME, and MX. Pay attention to virtual network linking for private zones.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure DNS for Name Resolution

Forgetting to delegate your public domain to Azure's name servers after creating a public DNS zone, leading to unresolved public domains.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure DNS for Name Resolution

Not linking a private DNS zone to the correct virtual network, preventing VMs from resolving internal names.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure DNS for Name Resolution

Using an excessively high TTL for critical records, which delays propagation of necessary DNS changes.

Module 4: Implementing and Managing Virtual Networking

Key term

NSG Rule

Defines parameters like source, destination, port, protocol, and action for traffic.

Module 4: Implementing and Managing Virtual Networking

Key term

Priority

Determines the order in which NSG rules are evaluated (lower number = higher priority).

Module 4: Implementing and Managing Virtual Networking

Key term

Service Tag

System-provided literal string representing a group of IP prefixes for Azure services.

Module 4: Implementing and Managing Virtual Networking

Key term

Application Security Group (ASG)

Allows grouping of VMs by application structure for NSG rule definition.

Module 4: Implementing and Managing Virtual Networking

Key term

Default Security Rules

Built-in NSG rules that cannot be deleted but can be overridden by custom rules.

Module 4: Implementing and Managing Virtual Networking

Key term

Network Interface (NIC)

The point where a VM connects to a virtual network.

Module 4: Implementing and Managing Virtual Networking

Memory trick

Configuring Network Security Groups (NSGs)

P-S-D-A: Priority, Source/Destination, Direction, Action. Remember these four main components of an NSG rule to quickly recall how to configure them.

Module 4: Implementing and Managing Virtual Networking

Exam tip

Configuring Network Security Groups (NSGs)

The exam frequently tests your understanding of NSG rule processing order. Remember: Inbound traffic is Subnet NSG then NIC NSG. Outbound traffic is NIC NSG then Subnet NSG. Both must allow for traffic to pass. Keywords to spot: 'rule priority', 'default rules', 'service tags', 'ASG'.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Configuring Network Security Groups (NSGs)

Forgetting that NSG rules are processed by priority, and once a match is found, processing stops. A poorly ordered rule can inadvertently block or allow traffic.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Configuring Network Security Groups (NSGs)

Not understanding the difference between applying an NSG to a subnet versus a network interface, especially how they interact for inbound and outbound traffic.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Configuring Network Security Groups (NSGs)

Overlooking the default NSG rules, which can sometimes block traffic you intend to allow if your custom rules aren't configured with higher priority.

Module 4: Implementing and Managing Virtual Networking

Key term

Load Balancer

Distributes network traffic at Layer 4 (TCP/UDP) across backend instances.

Module 4: Implementing and Managing Virtual Networking

Key term

Application Gateway

Web traffic load balancer at Layer 7 (HTTP/HTTPS) with advanced features.

Module 4: Implementing and Managing Virtual Networking

Key term

Backend Pool

A group of virtual machines or instances that receive traffic from a load balancer.

Module 4: Implementing and Managing Virtual Networking

Key term

Health Probe

Monitors the availability and health of instances in a backend pool.

Module 4: Implementing and Managing Virtual Networking

Key term

SSL/TLS Termination

Decrypting encrypted traffic at the load balancer before forwarding to backend servers.

Module 4: Implementing and Managing Virtual Networking

Key term

WAF

Web Application Firewall; protects web apps from common vulnerabilities.

Module 4: Implementing and Managing Virtual Networking

Key term

Path-based Routing

Directing traffic to different backend pools based on the URL path.

Module 4: Implementing and Managing Virtual Networking

Key term

Session Affinity

Ensuring requests from the same client go to the same backend server.

Module 4: Implementing and Managing Virtual Networking

Memory trick

Implementing Azure Load Balancer and Application Gateway

L4 for LB (Load Balancer is Layer 4), L7 for AG (Application Gateway is Layer 7). Remember the numbers to recall their primary function!

Module 4: Implementing and Managing Virtual Networking

Exam tip

Implementing Azure Load Balancer and Application Gateway

On the AZ-104 exam, pay close attention to scenario questions that describe web applications needing SSL/TLS offloading, WAF, or URL-based routing – these always point to Application Gateway. If it's just basic TCP/UDP distribution or internal services, think Load Balancer.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure Load Balancer and Application Gateway

Using Application Gateway for non-HTTP/HTTPS traffic, which is inefficient and costly.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure Load Balancer and Application Gateway

Forgetting to configure health probes, leading to traffic being sent to unhealthy instances.

Module 4: Implementing and Managing Virtual Networking

Common mistake

Implementing Azure Load Balancer and Application Gateway

Not enabling WAF on Application Gateway when deploying public-facing web applications.

Module 4: Implementing and Managing Virtual Networking

Key term

Azure Monitor

Comprehensive solution for collecting, analyzing, and acting on telemetry data.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Metrics

Numerical values describing system aspects, ideal for real-time performance tracking.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Logs

Detailed event records providing diagnostic information for root cause analysis.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Log Analytics Workspace

Azure service for ingesting, storing, and querying log data using KQL.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Kusto Query Language (KQL)

Powerful query language used to interact with data in Log Analytics workspaces.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Alerts

Proactive notifications triggered by specific conditions in monitoring data.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Action Groups

Define automated responses (e.g., email, SMS) when an Azure Monitor alert fires.

Module 5: Monitoring and Maintaining Azure Resources

Memory trick

Monitoring Azure Resources: Metrics & Logs

M for Metrics = 'Measure' performance. L for Logs = 'Look' for details.

Module 5: Monitoring and Maintaining Azure Resources

Exam tip

Monitoring Azure Resources: Metrics & Logs

The exam frequently tests your understanding of when to use metrics versus logs. Remember, metrics are for performance and availability (the 'what'), while logs are for diagnosis and auditing (the 'why'). Also, know that KQL is used for querying logs in Log Analytics.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Monitoring Azure Resources: Metrics & Logs

Confusing metrics and logs: Using logs for real-time performance dashboards or metrics for deep diagnostic analysis.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Monitoring Azure Resources: Metrics & Logs

Not configuring Action Groups: Creating alerts without defining what actions should be taken, leading to unhandled incidents.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Monitoring Azure Resources: Metrics & Logs

Ignoring Activity Logs: Overlooking the Activity Log for auditing and understanding control-plane operations in Azure.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Recovery Services vault

A central management entity for backups and recovery points.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Backup policy

Defines backup frequency and retention settings for protected items.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Recovery point

A point in time from which data can be restored; a snapshot.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Soft delete

Protects against accidental deletion of backup data by retaining it.

Module 5: Monitoring and Maintaining Azure Resources

Key term

File-level recovery

Restoring individual files or folders from a VM backup.

Module 5: Monitoring and Maintaining Azure Resources

Key term

MARS agent

Microsoft Azure Recovery Services agent for backing up on-premises data.

Module 5: Monitoring and Maintaining Azure Resources

Memory trick

Implementing Azure Backup for Data Protection

V.P.R.S. (Vaults, Policies, Recovery points, Soft delete) – Remember these key elements for Azure Backup success!

Module 5: Monitoring and Maintaining Azure Resources

Exam tip

Implementing Azure Backup for Data Protection

On the AZ-104 exam, pay close attention to the different components of Azure Backup (Vaults, Policies, Protected Items) and the types of resources it can protect. Understand the difference between full and incremental backups, and the purpose of soft delete.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Implementing Azure Backup for Data Protection

Forgetting to configure a backup policy after creating a Recovery Services vault.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Implementing Azure Backup for Data Protection

Not understanding the difference between restoring an entire VM and performing file-level recovery.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Implementing Azure Backup for Data Protection

Underestimating the importance of soft delete for accidental backup deletion protection.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Incremental Backup

Copies only data changed since the last backup.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Full Backup

Copies all selected data, regardless of changes.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Retention Policy

Rules for how long recovery points are stored.

Module 5: Monitoring and Maintaining Azure Resources

Memory trick

Performing Azure Recovery Services: Vaults and Policies

Vaults Protect Data: V for Vault (storage), P for Policy (rules), D for Data (VMs, SQL).

Module 5: Monitoring and Maintaining Azure Resources

Exam tip

Performing Azure Recovery Services: Vaults and Policies

The exam often tests your understanding of the relationship between Recovery Services vaults, backup policies, and protected items. Be prepared to identify the components and their roles in a backup solution.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Performing Azure Recovery Services: Vaults and Policies

Not matching the Recovery Services vault region with the protected resources, leading to higher latency and costs.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Performing Azure Recovery Services: Vaults and Policies

Configuring overly aggressive retention policies for non-critical data, resulting in unnecessary storage expenses.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Performing Azure Recovery Services: Vaults and Policies

Forgetting to apply the created backup policy to the actual resources, leaving them unprotected.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Azure Site Recovery (ASR)

Azure's DRaaS for replication and failover

Module 5: Monitoring and Maintaining Azure Resources

Key term

Recovery Point Objective (RPO)

Maximum tolerable data loss (time)

Module 5: Monitoring and Maintaining Azure Resources

Key term

Recovery Time Objective (RTO)

Maximum tolerable downtime (time)

Module 5: Monitoring and Maintaining Azure Resources

Key term

Failover

Switching to replica during disaster

Module 5: Monitoring and Maintaining Azure Resources

Key term

Failback

Returning to primary after recovery

Module 5: Monitoring and Maintaining Azure Resources

Memory trick

Implementing Azure Site Recovery for Disaster Recovery

Remember 'ASR' as 'Always Stay Running' – because that's what Azure Site Recovery helps your applications do!

Module 5: Monitoring and Maintaining Azure Resources

Exam tip

Implementing Azure Site Recovery for Disaster Recovery

The AZ-104 exam frequently tests your understanding of ASR's capabilities, especially its role in business continuity and disaster recovery. Pay close attention to the different replication scenarios (on-premises to Azure, Azure to Azure) and the purpose of a Recovery Services vault.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Implementing Azure Site Recovery for Disaster Recovery

Forgetting to perform test failovers: Test failovers are crucial to validate your recovery plan and ensure it works as expected. Without testing, you can't be sure your DR strategy is effective.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Implementing Azure Site Recovery for Disaster Recovery

Not understanding the difference between RPO and RTO: These are distinct metrics. RPO is about data loss, RTO is about downtime. ASR aims to minimize both.

Module 5: Monitoring and Maintaining Azure Resources

Common mistake

Implementing Azure Site Recovery for Disaster Recovery

Incorrectly configuring network settings for failover: During failover, the replicated VMs need to connect to the correct virtual networks and subnets in Azure. Misconfigurations can lead to inaccessible applications.

Module 5: Monitoring and Maintaining Azure Resources

Key term

Azure AD Connect

Microsoft tool for synchronizing on-premises AD with Azure AD.

Module 6: Implementing and Managing Hybrid Identities

Key term

Hybrid Identity

Combining on-premises and cloud identities for unified access.

Module 6: Implementing and Managing Hybrid Identities

Key term

Password Hash Synchronization (PHS)

Synchronizes a hash of the user's password to Azure AD.

Module 6: Implementing and Managing Hybrid Identities

Key term

Pass-Through Authentication (PTA)

Authenticates users against on-premises AD when accessing Azure AD.

Module 6: Implementing and Managing Hybrid Identities

Key term

Synchronization Rules

Define how objects and attributes are synchronized between directories.

Module 6: Implementing and Managing Hybrid Identities

Key term

Staging Mode

Allows testing configurations before applying to production.

Module 6: Implementing and Managing Hybrid Identities

Key term

Writeback

Synchronizing changes from Azure AD back to on-premises AD.

Module 6: Implementing and Managing Hybrid Identities

Memory trick

Implementing Azure AD Connect for Hybrid Identity

Remember 'CONNECT' for Azure AD Connect: C-Credentials, O-On-premises AD, N-Network, N-New Server, E-Express/Custom, C-Cloud AD, T-Test.

Module 6: Implementing and Managing Hybrid Identities

Exam tip

Implementing Azure AD Connect for Hybrid Identity

The exam often tests the differences between PHS, PTA, and AD FS. Memorize which authentication method stores password hashes in Azure AD (PHS), which validates against on-premises AD (PTA), and which requires a federation server (AD FS). Also, know the default synchronization interval (30 minutes).

Module 6: Implementing and Managing Hybrid Identities

Common mistake

Implementing Azure AD Connect for Hybrid Identity

Not meeting all prerequisites before installation, leading to errors or incomplete synchronization.

Module 6: Implementing and Managing Hybrid Identities

Common mistake

Implementing Azure AD Connect for Hybrid Identity

Using 'Express Settings' without understanding its implications, potentially synchronizing unwanted OUs or attributes.

Module 6: Implementing and Managing Hybrid Identities

Common mistake

Implementing Azure AD Connect for Hybrid Identity

Forgetting to verify synchronization status and troubleshoot errors after initial setup, assuming it just works.

Module 6: Implementing and Managing Hybrid Identities

Key term

Azure AD Connect Health

Cloud service for monitoring hybrid identity components.

Module 6: Implementing and Managing Hybrid Identities

Key term

Health Agent

Software installed on servers to collect and transmit data.

Module 6: Implementing and Managing Hybrid Identities

Key term

Synchronization Service

The component of Azure AD Connect responsible for data flow.

Module 6: Implementing and Managing Hybrid Identities