Microsoft Certified: Azure Developer Associate (AZ-204) flashcards
154 free flashcards. Tap a card to flip it.
Service Bus PeekLock
Flip cardA message reception mode in Azure Service Bus where a message is locked for processing, preventing other consumers from seeing it. The consumer explicitly completes or abandons the message after processing.
- Ensures 'at-least-once' delivery.
- Allows messages to be returned to the queue on processing failure.
- Works with dead-lettering for poison messages.
Memory trick: PeekLock is like taking a book from the library and returning it if you can't read it, eventually sending it to archives if too many try.
API Management 'send-one-way-request' Policy
Flip cardAn Azure API Management outbound policy used to send a fire-and-forget request to a specified URL, typically for asynchronous operations like sending messages to a queue or topic.
- Does not wait for a response from the backend.
- Ideal for integrating with messaging services like Azure Service Bus.
- Can be combined with 'set-header' to add message properties.
Memory trick: APIM acts as a 'smart post office' for your messages, deciding where and how they go.
Azure Durable Functions Orchestration
Flip cardAn extension of Azure Functions that enables writing stateful workflows in a serverless compute environment.
- Manages state, checkpoints, and restarts automatically.
- Supports long-running workflows with fan-out/fan-in patterns.
- Provides reliable execution and fault tolerance.
Memory trick: When long and complex, Durable Functions orchestrate the dance.
APIM as a Facade for Legacy APIs
Flip cardAzure API Management can act as a façade for legacy APIs, allowing you to expose existing SOAP or other non-RESTful services as modern RESTful APIs. This involves applying transformation policies to requests and responses.
- Converts SOAP to REST (and vice-versa).
- Standardizes API interfaces.
- Improves security and manages access.
- Provides a consistent API experience for consumers.
Memory trick: APIM takes an old temple (SOAP) and gives it a modern, shiny facade (REST).
API Management Policies
Flip cardDeclarative statements in Azure API Management that are executed sequentially on inbound or outbound requests, allowing for functionalities like authentication, caching, transformation, and rate limiting.
- Apply to inbound or outbound requests.
- Configurable at global, product, API, or operation scope.
- Enable security, performance, and transformation features.
Memory trick: APIM is the smart security guard and librarian for your APIs, checking IDs, validating requests, and quickly fetching cached answers.
APIM Named Values with Key Vault
Flip cardAzure API Management Named Values (Properties) can be linked to Azure Key Vault secrets to securely store and reference sensitive configuration data within APIM policies.
- Provides a centralized way to manage secrets.
- Enables secret rotation without policy changes.
- Values are securely retrieved at runtime by APIM.
Memory trick: Name your secrets, link to Key Vault, keep policies clean, without any fault.
APIM Integration with Application Insights
Flip cardConnecting Azure API Management to Azure Application Insights to enable detailed monitoring, distributed tracing, and performance analysis of API requests flowing through APIM.
- Provides end-to-end transaction visibility.
- Traces individual policy execution times.
- Helps identify performance bottlenecks within the APIM pipeline and backend.
Memory trick: App Insights traces every step, showing where the API time is lost.
Cache-aside (Lazy Loading)
Flip cardA caching strategy where the application is responsible for managing data loading into and out of the cache. Data is only loaded into the cache when it's requested and not found.
- Application manages cache population.
- Best for read-heavy workloads with infrequently updated data.
- Reduces unnecessary cache writes.
Memory trick: Read-heavy data, lazy load it, so you don't bog down.
Application Insights Application Map
Flip cardA visual representation of the topology of your application components, showing how they interact and highlighting performance issues or failures in the connections between them.
- Automatically discovers application components and dependencies.
- Visualizes end-to-end transaction flow.
- Helps identify bottlenecks and points of failure across services.
Memory trick: Application Map: See your app's journey, find the roadblocks!
Application Insights Custom Telemetry
Flip cardSending custom events, metrics, traces, and dependencies to Application Insights from your application code to gain deeper insights beyond standard auto-collected telemetry.
- Uses SDK methods like TrackEvent, TrackMetric, TrackTrace.
- Enables monitoring of specific business logic.
- Helps in root cause analysis of application-specific issues.
Memory trick: Track everything: Events for actions, Metrics for numbers!
Application Insights Distributed Tracing
Flip cardA feature of Application Insights that allows tracking the flow of requests across multiple services and components in a distributed application, providing end-to-end visibility and bottleneck identification.
- Visualizes service dependencies (Application Map).
- Provides detailed request timelines (Transaction Search).
- Helps identify latency issues across service boundaries.
Memory trick: To trace your requests end-to-end, Application Insights is your best friend.
APIM IP Filter Policy
Flip cardAn Azure API Management policy that controls access to APIs by allowing or denying requests based on the client's IP address or a specified range of IP addresses.
- Can be configured at the product, API, or operation scope.
- Supports single IP addresses and CIDR ranges.
- Helps enforce network-level security boundaries.
Memory trick: To let IPs in or out, the IP filter leaves no doubt.
Azure Monitor Logs (Log Analytics)
Flip cardA service within Azure Monitor that collects and analyzes telemetry from Azure resources, on-premises environments, and other cloud providers. It uses a Log Analytics workspace as a data store and Kusto Query Language (KQL) for querying.
- Collects diverse log data (application, infrastructure, custom).
- Enables powerful querying and analysis using KQL.
- Supports real-time alerting and dashboard creation.
Memory trick: Logs give you all the details, metrics give you the numbers, activity shows the actions.
Cosmos DB Diagnostic Logs
Flip cardDetailed operational logs from Azure Cosmos DB that can be sent to Azure Log Analytics for in-depth analysis of data plane requests, query performance, and indexing behavior.
- Includes metrics like RU consumption, query duration, and status codes.
- Essential for troubleshooting and optimizing Cosmos DB queries.
- Can be queried using Kusto Query Language (KQL) in Log Analytics.
Memory trick: Cosmos DB logs reveal the query secrets!
APIM validate-jwt Policy
Flip cardAn Azure API Management policy that validates the authenticity and integrity of a JSON Web Token (JWT) included in an API request, enabling secure access control based on token claims.
- Verifies JWT signature using public keys from the issuer.
- Checks token expiration, issuer, and audience.
- Can enforce specific claims for authorization decisions.
Memory trick: For JWTs, APIM's `validate-jwt` is the security guard!
Azure Monitor Metric Alerts
Flip cardAn Azure Monitor feature that triggers notifications or actions when a specific numerical metric crosses a predefined threshold over a specified period.
- Monitors various Azure service metrics.
- Can be configured with dynamic thresholds.
- Supports multiple action groups for notifications.
Memory trick: For numbers that cross a line, metric alerts are truly divine.
APIM Validate JWT Policy
Flip cardAn Azure API Management policy used to enforce authentication by validating JSON Web Tokens (JWTs) in incoming requests.
- Validates JWT signature against a specified key.
- Checks claims such as issuer, audience, and expiry.
- Can be configured to require specific claims.
Memory trick: Secure your APIs, validate the token, let no bad request be spoken.
APIM Conditional Caching
Flip cardA caching strategy in Azure API Management that uses HTTP headers like ETag and Last-Modified to revalidate cached responses with the backend, ensuring cache invalidation when data changes.
- Reduces backend load and improves response times.
- Supports automatic cache invalidation on data changes.
- Requires `cache-lookup` and `cache-store` policies.
Memory trick: Cache with conditions, keep data current!
Azure Cache for Redis
Flip cardA fully managed, in-memory data store service based on the open-source Redis. It offers high performance, scalability, and availability for caching and session management.
- Open-source Redis compatible.
- Supports various data structures.
- Provides high throughput and low latency.
Memory trick: For shared fast data, Redis is the cache that rates.
Azure Functions Premium Plan Benefits
Flip cardThe Premium plan for Azure Functions offers enhanced performance and features over the Consumption plan, primarily by eliminating cold starts through pre-warmed instances.
- No cold starts due to pre-warmed instances.
- Supports VNet connectivity.
- Dynamic scaling with a per-second billing model.
Memory trick: To warm your functions fast, choose Premium, it's built to last.
Write-Through Caching
Flip cardA caching strategy where data is written simultaneously to the cache and the underlying data store. This ensures data consistency between the cache and the database.
- Ensures strong data consistency.
- Writes are slower due to dual write operations.
- Reads are fast from the cache.
Memory trick: Cache consistency: Write-through keeps it tight!
Azure Functions Premium Plan
Flip cardA hosting plan for Azure Functions that offers enhanced performance features, including pre-warmed instances, VNet connectivity, and unlimited execution duration, suitable for demanding workloads.
- Eliminates cold starts due to pre-warmed instances.
- Supports VNet integration.
- Offers dedicated compute resources and faster scaling.
Memory trick: Scale your functions, don't let them be slow, choose the plan that helps them grow.
APIM Set Body Policy with Liquid
Flip cardThe Azure API Management 'Set body' policy allows transforming the request or response body. When combined with Liquid templating, it enables powerful, custom JSON or XML manipulations.
- Used for complex JSON/XML transformations.
- Liquid templates provide conditional logic and looping.
- Can filter, rename, and restructure data fields.
Memory trick: To sculpt your JSON, set the body with Liquid's art, giving clients a fresh, new start.
Retry Pattern
Flip cardA design pattern that enables an application to gracefully handle transient failures by transparently retrying a failed operation multiple times until it succeeds or a maximum retry count is reached.
- Handles transient faults (e.g., network glitches, temporary service unavailability).
- Often includes exponential backoff to avoid overwhelming the service.
- Improves application resilience and availability.
Memory trick: Retry for transient, Circuit Breaker for persistent failures!
Azure Application Insights
Flip cardAn Application Performance Management (APM) service that monitors live web applications, automatically detecting performance anomalies and providing powerful analytics tools to diagnose issues.
- Part of Azure Monitor.
- Collects telemetry data from web apps.
- Offers features like dependency tracking, performance bottlenecks, and usage patterns.
Memory trick: App Insights, the app's watchful eyes!
Read-Through/Write-Through Caching
Flip cardCaching patterns where the cache interacts directly with the backend data store to load (read-through) or persist (write-through) data on behalf of the application, simplifying application logic.
- Read-through: Cache fetches data from DB if not present.
- Write-through: Cache writes data to DB synchronously.
- Requires custom implementation in most cloud caching services.
Memory trick: For 'through' patterns, your code must be clever, Azure's cache won't do it, no, never.
Azure Service Bus Advanced Messaging
Flip cardAzure Service Bus offers advanced messaging capabilities such as dead-lettering, message deferral, and sessions, enabling robust error handling and complex workflow orchestration.
- Dead-letter queue for unprocessable messages.
- Message deferral to re-process messages later.
- Supports message properties for custom retry logic.
Memory trick: For tough messages, Service Bus gives you control, retries, and a dead-letter goal.
APIM Internal VNet Mode
Flip cardAn Azure API Management deployment option where the APIM instance is injected into an Azure Virtual Network (VNet) and exposed via a private IP address. This enables secure access to private backend services within the VNet.
- APIM endpoints are only accessible from within the VNet.
- Requires a Load Balancer or Application Gateway for public access.
- Enables secure communication with VNet-isolated backend services.
Memory trick: Internal for private, External for public, but sometimes private needs a public face!
Azure Functions Event Grid Trigger
Flip cardAn Azure Functions trigger that responds to events published to Azure Event Grid, providing near real-time, push-based event delivery for minimal latency.
- Reacts to events from various Azure services (e.g., Blob Storage, IoT Hub).
- Uses a push model, eliminating polling delays.
- Offers low latency and high scalability for event-driven architectures.
Memory trick: Event Grid for instant, Blob trigger for polling, Function choice is key!
APIM Client Certificate Authentication
Flip cardAzure API Management can be configured to present client certificates for mutual TLS authentication when calling backend services, enhancing security by verifying the identity of the APIM instance to the backend.
- Requires certificates stored securely, ideally in Azure Key Vault.
- Configured in the backend settings of an API or operation.
- Enables mutual TLS between APIM and backend.
Memory trick: Key Vault holds the cert, APIM uses it for the backend's assert.
Azure Front Door Caching
Flip cardA feature of Azure Front Door that allows static content (images, CSS, JS) to be cached at edge locations globally, reducing latency for users and offloading requests from backend origin servers.
- Caches content at the nearest edge location to the user.
- Improves performance and reduces backend load.
- Configurable with caching policies for different content types.
Memory trick: Front Door routes, caches, and protects, making your app fast and safe.
Azure Storage Blob Data Roles
Flip cardAzure RBAC roles specifically for controlling data plane access to Azure Blob Storage, allowing granular permissions like reading, writing, or deleting blobs.
- Storage Blob Data Owner: Full control over blob data, including access management.
- Storage Blob Data Contributor: Read, write, and delete blob data.
- Storage Blob Data Reader: Read blob data only.
- Can be scoped to container or storage account level.
Memory trick: To read and write blobs, the Function needs the 'Blob Data Contributor' role.
Azure Key Vault
Flip cardA cloud service for securely storing and accessing secrets, such as API keys, passwords, certificates, and cryptographic keys.
- Centralized secret management
- Hardware Security Module (HSM) backed protection
- Integration with other Azure services
Memory trick: Key Vault: Your digital safe for secrets.
Azure Service Bus Data Roles
Flip cardBuilt-in Azure roles that provide data plane access to Azure Service Bus entities, allowing for fine-grained control over sending and receiving messages.
- Service Bus Data Sender: Send messages
- Service Bus Data Receiver: Receive messages
- Service Bus Data Owner: Full control over data operations
Memory trick: Sender: You send; Receiver: You get.
System-Assigned Managed Identity
Flip cardAn identity automatically created and managed by Azure for an Azure resource, eliminating the need for developers to manage credentials.
- Tied to the lifecycle of the Azure resource.
- Automatically authenticated by Azure AD.
- Used for secure, passwordless access to other Azure services.
- Adheres to the principle of least privilege when combined with RBAC.
Memory trick: Functions use their own Azure ID to talk to Cosmos DB securely, without needing passwords.
Azure RBAC Custom Role Definition
Flip cardA JSON definition that specifies a set of permissions (actions, notActions, dataActions, notDataActions) that can be assigned to an Azure principal (user, group, managed identity, service principal).
- Allows fine-grained control over Azure resources
- Adheres to the principle of least privilege
- Can define both control plane and data plane actions
Memory trick: RBAC Custom Role: Only give the key for *what* they need to *do*.
Storage Account Network Security
Flip cardSecuring an Azure Storage Account by restricting access to specific virtual networks (using Service Endpoints) and/or specific public IP addresses (using IP firewall rules).
- Service Endpoints for VNet access: traffic stays on Azure backbone.
- IP firewall rules for public IP access: whitelisting external sources.
- Default action is to deny all public access unless explicitly allowed.
- Can be combined to create comprehensive access policies.
Memory trick: For Storage, Service Endpoints for VNet, IP Rules for On-Prem.
OAuth 2.0 Authorization Code Flow with PKCE
Flip cardAn enhanced Authorization Code flow that adds a Proof Key for Code Exchange (PKCE) to mitigate authorization code interception attacks, making it suitable for public clients like mobile and single-page applications (SPAs).
- Recommended for public clients (mobile, SPA)
- Protects against authorization code interception
- Client never stores a secret
Memory trick: PKCE: Mobile's secret handshake for security.
Azure AD Multi-tenant Application
Flip cardAn application registered in Azure AD that can accept sign-ins from users in any Azure AD tenant, enabling SaaS scenarios.
- Uses the `/organizations` or `/common` endpoint for authentication requests.
- Requires administrator consent in each customer's tenant for the application to access their data.
- Allows dynamic discovery of tenant-specific endpoints via OpenID Connect metadata.
Memory trick: Many tenants, one common door for authentication.
Azure Application Gateway with WAF
Flip cardA web traffic load balancer that enables you to manage traffic to your web applications, offering a Web Application Firewall (WAF) to protect against common web vulnerabilities.
- Operates at Layer 7 (HTTP/HTTPS)
- Protects against OWASP Top 10 vulnerabilities
- Integrates with Azure Monitor for logging and diagnostics
Memory trick: App Gateway WAF: Your web app's bouncer.
Customer-Managed Keys (CMK)
Flip cardAn encryption option that allows customers to use and manage their own encryption keys, typically stored in Azure Key Vault, to encrypt data at rest in Azure services.
- Provides granular control over encryption keys
- Often required for regulatory compliance (e.g., FIPS, HIPAA)
- Keys are stored and managed in Azure Key Vault
Memory trick: CMK: My keys, my control, my vault.
Azure Application Gateway WAF
Flip cardA Web Application Firewall (WAF) capability integrated into Azure Application Gateway, providing centralized protection for web applications against common exploits and vulnerabilities.
- Operates at Layer 7 (HTTP/HTTPS).
- Protects against OWASP Top 10 vulnerabilities (e.g., SQL injection, XSS).
- Can be deployed in front of various backend services, including Azure App Service.
Memory trick: App Gateway WAF: The bouncer for your web applications.
Azure AD Connect Pass-through Authentication
Flip cardAn Azure AD Connect sign-in method that allows users to sign in to Azure AD with the same passwords as their on-premises Active Directory, without synchronizing password hashes to Azure AD.
- Agents on-premises validate passwords directly
- No password hashes stored in Azure AD
- Provides single sign-on (SSO) capabilities
Memory trick: Pass-through: Your password 'passes through' to on-prem AD, not stored in the cloud.
Azure AD Conditional Access Policy
Flip cardAn Azure AD feature that allows organizations to enforce policies (access controls) based on specific conditions (user, location, device, app, etc.) when users attempt to access cloud applications.
- Enables risk-based access decisions
- Supports MFA, device compliance, terms of use, etc.
- Uses 'conditions' and 'access controls' to define policies
Memory trick: Conditional Access: If you're 'out of bounds', you need extra ID.
Azure Functions VNet Integration
Flip cardA feature that allows an Azure Function App to connect to resources within an Azure Virtual Network, routing its outbound traffic through the VNet.
- Works with Consumption, Premium, and Dedicated plans.
- Enables access to private endpoints, service endpoints, and custom resources in VNet.
- Does not provide inbound VNet access to the Function App.
- Simplified networking for serverless applications.
Memory trick: To reach inside the VNet, the Function needs VNet Integration.
OpenID Connect Multi-Tenant
Flip cardAn identity layer on OAuth 2.0 that allows applications registered in one Azure AD tenant to accept sign-ins from users in any other Azure AD tenant.
- Uses common endpoints for authentication.
- Requires application registration to be 'multi-tenant'.
- Provides ID tokens for user identity and access tokens for authorization.
- Leverages standard OAuth 2.0 flows like Authorization Code Flow.
Memory trick: OpenID is the key to letting many tenants sign in to one app securely.
Managed Identity
Flip cardAn Azure Active Directory identity automatically managed by Azure, allowing Azure services to authenticate to cloud services without requiring developers to manage credentials.
- Eliminates the need for storing credentials in code or configuration files.
- Supports two types: System-assigned (tied to a single resource) and User-assigned (can be used by multiple resources).
- Used for authenticating to any service that supports Azure AD authentication.
Memory trick: Managed Identity: The robot's built-in key for Azure services.
AKS Persistent Volume CMK Encryption
Flip cardEncrypting Azure Disks used as persistent volumes in Azure Kubernetes Service (AKS) with customer-managed keys (CMK) stored in Azure Key Vault.
- Requires a custom Kubernetes StorageClass.
- The StorageClass references a Key Vault key and user-assigned managed identity.
- The managed identity needs 'Key Vault Crypto Service Encryption User' role on the Key Vault.
- Encryption at host can further enhance security for node-level data.
Memory trick: For AKS volumes, custom StorageClass and Encryption at Host handle CMK.
APIM validate-jwt for Multi-tenant
Flip cardThe `validate-jwt` policy in Azure API Management can be configured for multi-tenant applications by pointing the `openid-config` URL to the Azure AD 'common' endpoint. This allows APIM to dynamically validate JWTs issued by any Azure AD tenant without specific per-tenant configuration.
- Uses the `https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration` endpoint.
- Dynamically discovers public keys for JWT validation.
- The `audience` parameter must match the App ID URI of the API.
Memory trick: To validate tokens from many, use the common key.
Azure AD Workload Identity
Flip cardAn AKS feature that enables Kubernetes pods to authenticate to Azure resources using Azure Active Directory identities, providing fine-grained, distinct identities for each workload.
- Maps Kubernetes Service Accounts to Azure AD identities.
- Eliminates the need for client secrets, certificates, or Managed Identities for the entire cluster.
- Enhances security by providing least-privilege access for individual pods.
Memory trick: Workload Identity gives each pod its own Azure AD ID badge.
App Service Managed Identity
Flip cardAn Azure Active Directory identity automatically managed by Azure for an Azure App Service, enabling it to authenticate to other Azure services without developers managing credentials.
- Eliminates the need for API keys or client secrets.
- Tied to the lifecycle of the App Service.
- Authenticates to Azure AD-protected resources (e.g., Key Vault, Storage).
- Supports both system-assigned and user-assigned types.
Memory trick: App Service uses its own Managed ID to get secrets from Key Vault.
AKS Zero-Trust Microservice Security
Flip cardImplementing identity-based authentication and authorization for microservices in AKS, both for inter-service communication within the cluster and for accessing external Azure services.
- Service Mesh with mTLS for internal communication (service identity).
- Azure AD Workload Identity for external Azure service access (pod identity).
- Eliminates static credentials and provides fine-grained authorization.
- Core components of a zero-trust architecture in AKS.
Memory trick: Service Mesh for inside, Workload Identity for outside, that's Zero Trust.
Azure AD Workload Identity for AKS
Flip cardAzure AD Workload Identity for AKS allows Kubernetes pods to authenticate with Azure Active Directory using a federated identity, eliminating the need for client secrets and providing individual identities for workloads to access Azure resources securely.
- Enables Kubernetes pods to authenticate with Azure AD.
- Uses federated identity (OpenID Connect) with Azure AD.
- Eliminates the need for managing client secrets for pods.
- Provides granular, distinct identities for individual workloads.
Memory trick: Each pod's identity, automatically handled, no shared secrets.
Azure Key Vault for Secrets Management
Flip cardA cloud service for securely storing and accessing secrets, such as API keys, passwords, connection strings, and cryptographic keys.
- Provides hardware security module (HSM) protected keys.
- Offers fine-grained access control with Azure RBAC and Key Vault access policies.
- Supports secret rotation, auditing, and monitoring of access.
Memory trick: Key Vault: The vault for turning secrets, not just storing them.
Service Bus Data Roles
Flip cardAzure RBAC roles specific to Azure Service Bus for controlling data plane operations like sending and receiving messages.
- Data Owner: Full control (send, receive, manage).
- Data Sender: Send messages only.
- Data Receiver: Receive/consume messages only.
- Essential for implementing least privilege access to Service Bus.
Memory trick: To send, the Function needs the 'Sender' role for Service Bus.
Azure AD Pod Identity (or Workload Identity)
Flip cardA mechanism in Azure Kubernetes Service that allows Kubernetes pods to access Azure resources securely using Azure Active Directory identities (managed identities).
- Enables identity-based access for pods
- Replaces the need for explicit credentials in code
- Provides granular access control for Azure resources
Memory trick: Pod Identity: Each pod gets its own ID card to the vault.
Azure AD Application Permissions
Flip cardPermissions granted to an application to access an API directly, using its own identity, without a signed-in user context.
- Used for daemon services or background processes
- Provides application-level access to resources
- Requires administrator consent
Memory trick: Application: The app is its own boss.
Service Mesh for Zero-Trust
Flip cardA dedicated infrastructure layer that handles inter-service communication within a microservices architecture, enabling features like mutual TLS for zero-trust security.
- Provides mutual TLS (mTLS) for authenticating and encrypting all service-to-service traffic.
- Enforces fine-grained authorization policies based on service identity.
- Offers traffic management, observability, and resiliency features.
Memory trick: Service Mesh: Every microservice gets its own security guard and ID check.
Azure AD Pass-through Authentication (PTA)
Flip cardAn Azure AD authentication method that allows users to sign in to cloud applications using their on-premises Active Directory passwords, by validating credentials directly against the on-premises AD.
- No password hashes are stored in Azure AD.
- Uses lightweight agents installed on-premises.
- Provides a simple alternative to AD FS for hybrid identity.
- Offers seamless single sign-on experience.
Memory trick: Pass-through lets on-prem passwords just 'pass through' to Azure AD.
OAuth 2.0 Authorization Code Flow
Flip cardA secure OAuth 2.0 flow for web applications where the client redirects the user to an authorization server to authenticate and authorize, receiving an authorization code which is then exchanged for an access token.
- Recommended for confidential clients (web apps)
- Client never sees user's credentials
- Provides refresh tokens for long-lived sessions
Memory trick: Auth Code: The web app's secure secret handshake.