Microsoft Certified: DevOps Engineer Expert flashcards
160 free flashcards. Tap a card to flip it.
Azure Role-Based Access Control (RBAC)
Flip cardA system for managing authorization in Azure that allows you to specify who has access to Azure resources, what actions they can perform, and what resources or scopes they have access to.
- Enforces the principle of least privilege.
- Grants access at management group, subscription, resource group, or resource scope.
- Uses roles (built-in or custom) to define permissions.
Memory trick: RBAC 'Grants Specific Keys' to 'Specific Doors'.
Azure Policy Tag Enforcement
Flip cardUsing Azure Policy to automatically add, modify, or audit tags on Azure resources to ensure compliance with organizational tagging standards.
- Policies can use 'Modify' effect to add/update tags.
- Can enforce mandatory tags or specific tag values.
- Essential for cost management, resource organization, and compliance.
Memory trick: Policy is the Auto-Stamper for your Azure Resources!
Azure Management Groups
Flip cardContainers that allow you to organize subscriptions into groups, applying governance conditions (like policies and access control) at scale, which are then inherited by all subscriptions and resources within that group.
- Provides a hierarchy above subscriptions.
- Enables enterprise-scale governance.
- Used with Azure Policy and RBAC for inherited controls.
Memory trick: Management Groups 'Organize the Floors', and Azure Policy 'Sets the House Rules'.
Key Vault Access Policies
Flip cardSecurity settings in Azure Key Vault that define which users, groups, or applications (service principals/managed identities) have permissions to perform specific operations on keys, secrets, or certificates.
- Granular control over key operations (get, wrap, unwrap).
- Used to grant and revoke access to keys for services like Azure Storage.
- Can be configured with least privilege principles.
Memory trick: To 'Cut Key Access', adjust the Key Vault Access Policy.
Secure Secret Management in Azure DevOps
Flip cardThe practice of securely storing and retrieving sensitive information (secrets) required by applications and pipelines, typically using Azure Key Vault integrated with Azure Pipelines.
- Prevents exposure of secrets in code or logs.
- Centralizes secret management.
- Enables rotation and access control for secrets.
Memory trick: Key Vault 'Holds the Keys' for Pipelines to 'Unlock Safely'.
Azure SQL In-Transit Encryption
Flip cardEnsuring data is encrypted while it travels between the client application and the Azure SQL Database, typically via TLS/SSL, often with FIPS 140-2 validated modules.
- Azure SQL Database uses TLS/SSL for in-transit encryption by default for most client drivers.
- Explicitly configuring 'Encrypt=True' in the connection string is a best practice.
- FIPS 140-2 validation applies to the cryptographic modules used by Azure services, including TLS/SSL.
Memory trick: Securely Transporting SQL Data: Always Encrypt the Journey!
Azure Private Link for Key Vault
Flip cardA networking service that provides private connectivity to Azure Key Vault from your Azure Virtual Network, ensuring traffic traverses the Microsoft backbone network and not the public internet.
- Creates a private endpoint in your VNet.
- Key Vault becomes accessible via a private IP address.
- Enhances security by eliminating public internet exposure.
Memory trick: Key Vault's Private Link: Your Secrets' Private Road to Security!
Mutual TLS (mTLS)
Flip cardA security protocol where both the client and server authenticate each other using digital certificates as part of the TLS handshake. It ensures encrypted and mutually authenticated communication.
- Provides encryption in transit.
- Ensures mutual authentication (client verifies server, server verifies client).
- Often used in zero-trust architectures and microservices communication.
Memory trick: Microservices need to 'Talk Securely and Know Each Other' with mTLS.
Microsoft Sentinel (SIEM/SOAR)
Flip cardA cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that collects, detects, investigates, and responds to security threats across an enterprise.
- Centralizes security data from diverse sources.
- Uses AI and machine learning for threat detection.
- Provides incident management and automated response capabilities (SOAR).
Memory trick: Sentinel 'Watches All', 'Connects All', and 'Acts on All' security events.
Azure Policy Allowed Locations
Flip cardAn Azure Policy capability that restricts resource deployments to a predefined set of Azure regions to enforce data residency and compliance requirements.
- Uses the 'Microsoft.Resources/subscriptions/locations' alias in policy definitions.
- Can be set at management group, subscription, or resource group scope.
- Helps prevent accidental or intentional resource deployment in unapproved regions.
Memory trick: Policy is the Border Patrol for your Azure Regions!
Azure Policy
Flip cardA service in Azure that enables you to create, assign, and manage policies that enforce rules and effects over your resources to stay compliant with corporate standards and service level agreements.
- Can enforce resource configurations, such as required VM extensions.
- Supports audit, deny, deploy if not exists, and modify effects.
- Can be scoped to management groups, subscriptions, or resource groups.
Memory trick: Policy is the Rule Book for Azure, enforcing compliance.
Azure Policy for Compliance
Flip cardA service that enables organizations to define and apply rules (policies) to Azure resources to enforce organizational standards, assess compliance, and automatically remediate non-compliant resources.
- Proactive enforcement (prevent, audit, remediate).
- Ensures adherence to security baselines and compliance standards.
- Applies at management group, subscription, or resource group scope.
Memory trick: Azure Policy 'Sets the Rules' to 'Keep Everything in Line'.
Azure Functions VNet Integration with Firewall
Flip cardConfiguring an Azure Functions app to connect to a virtual network (VNet Integration) and ensuring all its outbound traffic is routed through a centralized Azure Firewall within that VNet for inspection and control.
- Enables secure access to VNet resources from Functions.
- Forces all outbound Function traffic through a firewall.
- Enhances security and compliance for serverless applications.
Memory trick: VNet Integration 'Connects the Function', and Azure Firewall 'Inspects Everything Going Out'.
Deployment Stamps (Scale Units)
Flip cardAn architectural pattern where multiple independent, identical deployments of an application are created, often to serve different tenants, regions, or scale requirements, providing strong isolation and supporting data residency.
- Provides strong tenant isolation.
- Supports data residency by deploying instances in specific regions.
- Scales horizontally by adding more stamps rather than scaling up a single deployment.
Memory trick: Deployment Stamps are like 'Separate Houses in Each Country' for tenants.
Azure Monitor Activity Log
Flip cardA log that records events that occur at the subscription level in Azure, detailing administrative operations on resources, service health events, and other control-plane actions.
- Records who, what, and when for control-plane operations.
- Essential for auditing and compliance.
- Part of Azure Monitor.
Memory trick: To 'See Every Admin Step', check the Activity Log.
Azure Storage CMK Encryption
Flip cardUsing customer-managed encryption keys, stored in Azure Key Vault, to encrypt data at rest within Azure Storage accounts.
- Leverages Azure Key Vault for key management.
- Provides greater control over encryption keys.
- Applies to Blob, File, Table, and Queue storage.
Memory trick: Encrypt your Storage like a Vault, with Keys you Control!
Container Image Security Enforcement
Flip cardThe process of ensuring that only trusted, scanned, and compliant container images are deployed into an environment, typically enforced through policies and integrated registries.
- Prevents deployment of vulnerable or untrusted images.
- Requires a secure container registry.
- Leverages policy engines for enforcement.
Memory trick: ACR 'Stores Safe Ships', and Azure Policy 'Checks Their Papers'.
Azure App Service Deployment Slots
Flip cardDeployment slots are live apps with their own hostnames. App Service plans and configurations are shared across all slots, allowing for pre-production testing and zero-downtime swaps.
- Provide separate environments for different versions of an app.
- Share the same App Service plan and resources.
- Enable zero-downtime swaps between slots.
- Ideal for testing new versions before promoting to production.
Memory trick: Slots for Staging, Swapping for Success.
Azure Pipelines Comprehensive Release Control
Flip cardCombining scheduled triggers, pre-deployment approvals, and post-deployment gates provides robust control over when releases happen, who approves them, and automated verification after deployment.
- Scheduled triggers control release timing.
- Pre-deployment approvals enforce manual sign-offs.
- Post-deployment gates automate verification after deployment.
- Ensures compliance, quality, and timely notifications.
Memory trick: Schedule, Sign-off, Smoke Test, Send Notification.
Azure Pipelines YAML Templates
Flip cardYAML templates enable reuse of pipeline components (stages, jobs, steps) across multiple pipelines, promoting standardization, consistency, and maintainability.
- Define reusable pipeline structures.
- Support parameterization for customization.
- Improve consistency across projects.
- Reduce duplication and simplify maintenance.
Memory trick: Templates Tame the Chaos, Parameters Personalize.
Kubernetes Ingress
Flip cardKubernetes Ingress manages external access to services in a cluster, providing HTTP/HTTPS routing, SSL/TLS termination, and host/path-based routing rules.
- Exposes services externally.
- Requires an Ingress Controller (e.g., NGINX, AGIC).
- Manages SSL/TLS termination.
- Enables host-based and path-based routing.
Memory trick: Ingress: The Gatekeeper to Your K8s Services.
Database Schema Migration Tools
Flip cardTools (e.g., Flyway, Liquibase) that manage the evolution of a database schema by applying version-controlled migration scripts, ensuring consistency and enabling rollback capabilities.
- Version control for database schemas.
- Ensures idempotent and consistent migrations.
- Supports rollback to previous schema versions.
- Integrates with CI/CD pipelines for automated deployments.
Memory trick: Database schemas need a migration tool to grow up gracefully, not haphazardly.
CI Trigger (Azure Pipelines)
Flip cardA configuration in Azure Pipelines that automatically starts a pipeline build and deployment process whenever new code is pushed to a specified branch in a Git repository.
- Automates pipeline execution on code changes.
- Configurable for specific branches (e.g., 'main').
- Essential for Continuous Integration.
- Helps maintain code quality and rapid feedback.
Memory trick: Triggers are like the pipeline's alarm clock, telling it when to start.
Azure Key Vault Integration
Flip cardA feature in Azure DevOps that allows pipelines to securely retrieve secrets, certificates, and keys directly from Azure Key Vault, enhancing security and secret management.
- Centralized secret management.
- Secrets are not stored in pipeline definitions.
- Supports rotation and access policies.
- Integrates with Variable Groups for easy consumption.
Memory trick: Key Vault is the ultimate lock for your pipeline's secrets.
Controlled Multi-Region Deployment
Flip cardMulti-stage YAML pipelines with stage dependencies, delays, and pre-deployment approvals enable controlled, sequential rollouts to multiple regions with human intervention and monitoring time.
- Stages represent distinct regional deployments.
- Dependencies enforce sequential execution.
- Delays allow for monitoring time between regions.
- Pre-deployment approvals enable manual sign-off for each region.
Memory trick: Stages Stack, Delays Dwell, Approvals Allow.
Phased Rollout (Multi-Region)
Flip cardA deployment strategy where application updates are released to one geographical region at a time, validated, and then progressively rolled out to subsequent regions, allowing for isolation and quick rollback of issues.
- Deploys to one region, validates, then moves to the next.
- Minimizes blast radius of issues to a single region.
- Enables region-specific testing and monitoring.
- Supports targeted rollback without affecting other regions.
Memory trick: Phased rollout is like crossing a bridge one section at a time, checking each part before moving on.
Pre-deployment Approvals & Gates
Flip cardMechanisms in Azure DevOps release pipelines that enforce manual sign-off (approvals) and automated checks (gates) before a deployment stage can begin, ensuring control and quality.
- Approvals require designated users to manually sign off.
- Gates perform automated checks (e.g., external service health, security scans).
- Both must pass for the stage to proceed.
- Crucial for controlling deployments to sensitive environments like production.
Memory trick: Before you enter the production 'stage', you need a ticket (approval) and to pass security (gates).
YAML Pipeline Versioning & Backup (Git)
Flip cardStoring Azure Pipelines YAML definitions in a Git repository enables version control, collaboration, auditing, and serves as a fundamental backup and disaster recovery strategy.
- Treats pipelines as code (Pipeline as Code).
- Provides full version history and diffs.
- Facilitates collaboration and code reviews.
- Acts as a robust backup for pipeline definitions.
Memory trick: Git for Pipelines: Code, Control, Comeback.
Azure Key Vault Provider for Secrets Store CSI Driver
Flip cardEnables Kubernetes pods to securely mount secrets, keys, and certificates stored in Azure Key Vault as a volume. This provides secure, centralized secret management for AKS.
- Integrates AKS with Azure Key Vault.
- Allows pods to access Key Vault secrets as files or environment variables.
- Secrets are never stored in Kubernetes native Secrets or manifests.
- Enhances security and compliance for sensitive data.
Memory trick: Key Vault: Secrets in the Cloud, Secure in the Pod.
Terraform for Multi-Cloud IaC
Flip cardTerraform is an open-source Infrastructure as Code tool that enables declarative provisioning and management of cloud resources across multiple cloud providers, including Azure, with state management capabilities.
- Declarative configuration language (HCL).
- Manages infrastructure state.
- Cloud-agnostic (supports many providers).
- Ideal for repeatable and consistent infrastructure provisioning.
Memory trick: Terraform: Your Cross-Cloud Infrastructure Architect.
Azure Pipelines Pre-deployment Gates & Rollback
Flip cardPre-deployment gates enforce automated checks before a stage can start, ensuring quality. Automated rollback provides a mechanism to revert to a previous stable state upon deployment failure.
- Pre-deployment gates automate checks (e.g., health, performance, security).
- Gates prevent deployments until all conditions are met.
- Automated rollback ensures recovery from failed deployments.
- Enhances reliability and reduces manual intervention in critical releases.
Memory trick: Gates Guard, Rollback Recovers.
Microservices with IaC & Kubernetes
Flip cardMicroservices deployed to Kubernetes enable independent updates, while Infrastructure as Code (e.g., Terraform) manages the underlying Kubernetes cluster and resources, ensuring version-controlled and repeatable infrastructure provisioning.
- Microservices allow independent development and deployment.
- Kubernetes provides container orchestration for microservices.
- IaC (Terraform) manages the infrastructure for microservices.
- Ensures repeatable, version-controlled infrastructure provisioning.
Memory trick: Microservices in K8s, Infrastructure by Terraform.
Azure RM Service Connection with Workload Identity
Flip cardAn Azure Resource Manager service connection configured with Workload Identity federation enables secure, credential-less authentication for Azure Pipelines to interact with Azure resources like AKS, leveraging Azure AD.
- Securely connects Azure Pipelines to Azure resources.
- Uses Workload Identity federation for credential-less authentication.
- Leverages Azure Active Directory for identity.
- Recommended for AKS deployments in Azure DevOps.
Memory trick: Workload Identity: Your Pipeline's Password-less Pass to AKS.
Multi-stage YAML Pipelines for Microservices
Flip cardMulti-stage YAML pipelines in Azure DevOps orchestrate complex deployments with stages, dependencies, and conditions, ideal for managing ordered, test-driven microservice deployments.
- Define logical deployment phases as stages.
- Use `dependsOn` for enforcing stage order.
- Apply `conditions` for gatekeeping based on test results.
- Enables complex, ordered, and test-driven deployments.
Memory trick: Stages Depend, Conditions Confirm, Microservices Deploy.
Self-hosted Agent (Azure Pipelines)
Flip cardAn Azure Pipelines agent that is installed and managed on your own computing infrastructure (e.g., on-premises server, VM in your VNet), allowing pipelines to access resources not accessible to Microsoft-hosted agents.
- Runs on customer-managed infrastructure.
- Required for accessing isolated or on-premises resources.
- Provides control over machine specifications and installed software.
- Connects securely to Azure DevOps Services.
Memory trick: Agents are the pipeline's hands; self-hosted agents are YOUR hands in YOUR house.
ARM Service Connection with Workload Identity
Flip cardAn Azure Pipelines service connection type that uses Workload Identity federation for secure, secret-less authentication to Azure resources.
- Eliminates the need to manage service principal secrets.
- Leverages OpenID Connect (OIDC) and managed identities.
- Recommended secure authentication for Azure Pipelines to Azure.
Memory trick: Workload Identity federates trust, no secrets needed.
Continuous Integration (CI) Trigger
Flip cardAn Azure Pipelines trigger that automatically starts a pipeline when code changes are pushed to a specified repository and branch.
- Automates builds and tests on every code commit.
- Can be configured with branch and path filters.
- Essential for rapid feedback in CI/CD workflows.
Memory trick: CI triggers filter paths for microservice harmony.
Key Vault Provider for CSI Driver
Flip cardEnables Kubernetes applications to securely mount secrets, keys, and certificates stored in Azure Key Vault as a volume.
- Integrates Azure Key Vault with AKS pods.
- Secrets are mounted as files, not environment variables.
- Enhances security by centralizing secret management.
Memory trick: CSI mounts Key Vault, keeping secrets sound.
Pre-deployment Gates
Flip cardAutomated validations that must pass before a release can be deployed to a specific stage in Azure Pipelines.
- Enforce quality, security, and performance criteria.
- Prevent problematic releases from reaching production.
- Can include Azure Monitor alerts, Azure Policy compliance, custom REST APIs.
Memory trick: Gates guard the path to production.
Azure DevOps Environments Approvals
Flip cardAzure DevOps Environments allow defining deployment targets with integrated approval gates and automated checks, ensuring controlled and secure deployments.
- Integrates manual approvals directly into CI/CD pipelines.
- Supports pre-deployment and post-deployment checks.
- Enables granular control over who can approve deployments.
- Provides a mechanism to pause or reject deployments.
Memory trick: Environments Guard Production's Gate with Approvals.