Microsoft Azure Fundamentals (AZ-900) flashcards
99 free flashcards. Tap a card to flip it.
Azure Blob Storage Soft Delete & Versioning
Flip cardFeatures for Azure Blob Storage that protect data against accidental deletion or modification. Soft delete allows recovery of deleted blobs, and versioning maintains previous states of a blob.
- Soft delete: Recovers deleted blobs for a retention period.
- Versioning: Automatically saves previous versions of a blob.
- Crucial for data protection and recovery from human error.
Memory trick: Keep your data safe, recover old versions, avoid accidental loss.
Azure Advisor
Flip cardAzure Advisor is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. It analyzes your resource configuration and usage telemetry.
- Provides recommendations across five pillars.
- Identifies potential cost savings.
- Helps improve security, reliability, and performance.
Memory trick: Advisor Always Advises Action.
Azure Policy for Enforcement
Flip cardA service that enforces organizational standards and assesses compliance at scale. It can audit, deny, or modify resource deployments to ensure they meet predefined security configurations and other rules.
- Enforces rules on resource properties and configuration.
- Can prevent non-compliant deployments (Deny effect).
- Integrates with CI/CD for automated governance.
- Works across subscriptions and management groups.
Memory trick: Build it, check the rules, ensure security.
Azure Policy
Flip cardA service in Azure that helps enforce organizational standards and assess compliance at scale by defining rules for resource configurations.
- Enforces standards and compliance.
- Evaluates resource configurations.
- Can restrict resource deployment locations.
Memory trick: Policy sets the rules for your Azure playground.
Azure Blueprints
Flip cardA service that enables you to define a repeatable set of Azure resources that implement and adhere to an organization's standards, patterns, and requirements.
- Orchestrates the deployment of various resource templates and artifacts.
- Ensures consistent deployment and compliance across subscriptions.
- Includes role assignments, policy assignments, Azure Resource Manager templates, and resource groups.
Memory trick: Blueprint: Build-it-right, Policy-tight, Role-assigned, Resource-aligned.
Azure Budgets
Flip cardA feature within Azure Cost Management + Billing that allows you to set spending thresholds for your Azure subscriptions or resource groups and receive alerts when those thresholds are approached or exceeded.
- Set spending thresholds
- Receive alerts for overspending
- Can automate actions
- Helps control costs
Memory trick: Budget: your 'spending limit' with an alarm.
Azure Regions
Flip cardA set of datacenters deployed within a latency-defined perimeter and connected through a dedicated regional low-latency network. They define the physical location and legal jurisdiction of Azure resources.
- Geographical areas with datacenters
- Dictate data residency
- Critical for compliance and latency
- Each region has multiple Availability Zones
Memory trick: Region: where your data 'resides' globally.
Azure Management Groups
Flip cardContainers that help you manage access, policy, and compliance across multiple Azure subscriptions.
- Provide a hierarchy above subscriptions.
- Policies and roles applied at the management group level inherit to all child subscriptions.
- Essential for large-scale enterprise governance.
Memory trick: Management Group: Manage Global Governance, Group Subscriptions.
Azure Monitor Logs (Log Analytics)
Flip cardA feature of Azure Monitor that collects and aggregates log data from various sources into a central Log Analytics workspace, enabling powerful querying and analysis.
- Centralizes logs and metrics from diverse Azure resources.
- Uses Kusto Query Language (KQL) for powerful data analysis.
- Supports custom dashboards and alerts.
Memory trick: Logs are collected in one place to be analyzed and understood.
Azure Cost Management + Billing
Flip cardA suite of tools that helps you analyze, manage, and optimize your cloud costs, including creating budgets and setting up alerts.
- Provides cost analysis and reporting.
- Allows setting up budgets and alerts.
- Helps manage and optimize cloud spending.
Memory trick: Cost Management Watches Your Wallet.
Azure Resource Locks
Flip cardAzure Resource Locks prevent accidental deletion or modification of Azure resources. They can be applied at the subscription, resource group, or individual resource level.
- Supported lock types: CanNotDelete and ReadOnly.
- Overrides RBAC permissions for protection.
- Applied to critical resources or environments.
Memory trick: Locks Leave Lasting Legacy.
Data Encryption in Azure Storage
Flip cardAzure provides multiple layers of encryption for data at rest and in transit to protect sensitive information stored within its services.
- Data at rest is encrypted by default using Azure Storage Service Encryption.
- Data in transit is protected using HTTPS/TLS.
- Customer-managed keys can be used with Azure Key Vault for greater control over encryption keys.
Memory trick: Keys guard the vault, the vault holds the data, and HTTPS secures the journey.
Microsoft Sentinel (SIEM/SOAR)
Flip cardA cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.
- Collects security data from various sources.
- Uses AI and machine learning for threat detection.
- Enables automated responses to security incidents (SOAR).
Memory trick: Sentinel watches, detects, and acts on threats.
Azure Stream Analytics
Flip cardA real-time analytics service that is designed for processing large streams of data from various sources.
- Processes high volumes of streaming data with low latency.
- Supports complex event processing (CEP) and anomaly detection.
- Integrates with various input (e.g., IoT Hub) and output (e.g., Power BI, Azure Functions) sinks.
Memory trick: Stream Analytics: See, Process, Alert, React.
Immutable Storage for Azure Blob Storage
Flip cardA feature that allows data to be stored in a Write Once, Read Many (WORM) state, preventing modification or deletion for a configurable retention period, even by administrators.
- Ensures data integrity and tamper-proofing.
- Supports time-based retention and legal hold.
- Meets regulatory compliance requirements (e.g., FINRA, SEC 17a-4).
Memory trick: Immutable storage makes data a 'WORM' that can't be squashed!
Azure Region
Flip cardA set of datacenters deployed within a latency-defined perimeter and connected to a dedicated, regional low-latency network. It directly supports data residency.
- Geographical area for Azure datacenters.
- Choice determines data residency.
- Provides proximity for low-latency access.
Memory trick: Regions are Countries, Zones are Cities.
Azure Monitor
Flip cardAzure Monitor maximizes the availability and performance of your applications and services by delivering a comprehensive solution for collecting, analyzing, and acting on telemetry from your cloud and on-premises environments.
- Collects metrics and logs from virtually all Azure services.
- Provides dashboards, visualizations, and analytics.
- Enables alert configuration and automated actions.
Memory trick: Monitor Makes Metrics Manifest.
Immutable Storage
Flip cardA feature of Azure Blob Storage that stores data in a Write Once, Read Many (WORM) state, meaning it cannot be modified or deleted for a specified retention period.
- WORM (Write Once, Read Many) state
- Protects against accidental deletion/modification
- Supports time-based retention and legal hold
Memory trick: Immutable: can't change, can't delete, just read.
Microsoft Purview Compliance Manager
Flip cardA service that helps organizations manage compliance with various regulatory standards and internal policies by providing risk assessments, actionable recommendations, and a compliance score.
- Unified compliance management
- Supports various regulations (GDPR, PCI DSS)
- Provides compliance score and actionable insights
Memory trick: Purview: a 'view' for 'pure' compliance.
Azure Pricing Calculator
Flip cardA web-based tool that provides estimated costs for Azure products and services based on user-defined configurations.
- Helps estimate costs before deployment.
- Allows configuration of various services.
- Provides a monthly cost projection.
Memory trick: Calculate your Azure cash before you crash!
Azure Log Analytics
Flip cardA service within Azure Monitor that collects, indexes, and stores log data from various Azure resources for advanced querying, analysis, and alerting.
- Collects logs from many sources.
- Supports Kusto Query Language (KQL).
- Centralizes operational and diagnostic logs.
- Essential for security auditing and troubleshooting.
Memory trick: Log Analytics: Your 'L' for 'Logbook' of all Azure actions.
Azure Cost Management + Billing Budgets
Flip cardA feature within Azure Cost Management + Billing that allows users to create budgets to track spending against a specific financial threshold and receive alerts when costs exceed predefined percentages of the budget.
- Proactively manages costs by setting spending limits.
- Generates alerts when spending approaches or exceeds the budget.
- Can be set for subscriptions, resource groups, or management groups.
Memory trick: Budgets are like financial alarms for your Azure spending.
Azure Policy for Tagging
Flip cardAzure Policy can enforce tagging standards by requiring specific tags on resources, automatically applying default tags, or auditing for non-compliant tags.
- Enforces tagging standards.
- Can require specific tags.
- Can automatically apply tags.
- Crucial for cost allocation and reporting.
Memory trick: Policy ensures your tags are always on point, no exceptions.
Azure Monitor Logs
Flip cardA feature of Azure Monitor that collects and aggregates log and performance data from various sources into a central repository (Log Analytics workspace) for analysis, alerting, and visualization.
- Centralized log collection
- Powerful query language (KQL)
- Supports various data sources (VMs, apps, Azure services)
Memory trick: Monitor everything, log it all.
Azure SQL Database Security (TDE & Auditing)
Flip cardAzure SQL Database offers Transparent Data Encryption (TDE) for data at rest encryption and SQL Database Auditing for recording database events for compliance and security monitoring.
- TDE encrypts the entire database, backups, and transaction log files.
- Auditing tracks database events like logins, queries, and schema changes.
- Both are essential for PII protection and compliance requirements.
Memory trick: TDE encrypts the data, Auditing watches the access.
Azure Storage Encryption (At Rest & In Transit)
Flip cardAzure Storage provides automatic encryption for data at rest (Server-Side Encryption) and encrypts data in transit (HTTPS) to protect data confidentiality.
- Data at rest is encrypted by SSE (256-bit AES).
- Data in transit is encrypted via HTTPS/TLS.
- Managed by Microsoft by default, customer-managed keys optional.
Memory trick: Resting data is safe with SSE, moving data with HTTPS.
Microsoft Sentinel
Flip cardA cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.
- Cloud-native SIEM/SOAR
- Collects security data from many sources
- Uses AI for threat detection
- Automates incident response
Memory trick: Sentinel: The 'sentinel' watches, detects, and acts.
Azure Database Security & Auditing
Flip cardA comprehensive suite of security capabilities for Azure SQL Database, including vulnerability assessment, advanced threat protection, and auditing.
- Includes vulnerability assessment.
- Provides advanced threat protection.
- Offers auditing for regulatory compliance.
- Enhances security for sensitive data in SQL databases.
Memory trick: Database Security: Your 'D' for 'Defense' for your sensitive data.
Azure Sentinel
Flip cardA scalable, cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.
- Collects security data from multiple sources.
- Uses AI and machine learning for advanced threat detection.
- Enables automated responses (SOAR) to security incidents.
Memory trick: Sentinel is your AI-powered security guard watching all your digital doors.
Azure Backup
Flip cardA cloud-based backup solution that protects your data in Azure and on-premises. It provides capabilities for point-in-time recovery, long-term retention, and protection against accidental deletion or corruption.
- Cloud-based backup solution
- Point-in-time recovery
- Long-term retention
- Protects various Azure services
Memory trick: Backup: your 'safety copy' for data.
Azure Policy for Encryption Enforcement
Flip cardAzure Policy can enforce specific encryption standards for Azure resources, such as requiring customer-managed keys (CMK) for storage accounts or SQL databases.
- Enforces encryption standards.
- Can require CMK usage.
- Audits for non-compliance.
- Denies non-compliant resource creation.
Memory trick: Policy dictates the encryption keys your Azure resources must obey.
Network Security Group (NSG)
Flip cardA Network Security Group (NSG) is an Azure networking component that contains security rules to filter network traffic to and from Azure resources.
- Filters traffic based on IP, port, protocol
- Can be associated with subnets or individual NICs
- Rules are processed by priority
- Default rules allow all outbound, deny all inbound from internet
Memory trick: NSG is the bouncer at the door, checking IDs and deciding who gets in or out.
Azure AD Connect
Flip cardA Microsoft tool for synchronizing on-premises Active Directory identities with Azure Active Directory.
- Enables hybrid identity scenarios.
- Synchronizes users, groups, and contacts.
- Supports password hash synchronization, pass-through authentication, and federation with ADFS.
Memory trick: AD Connects your on-prem to the cloud.
Azure Active Directory (Azure AD)
Flip cardA cloud-based identity and access management service that helps employees sign in and access resources.
- Provides single sign-on (SSO)
- Supports multi-factor authentication (MFA)
- Manages access to cloud and on-premises applications
Memory trick: Azure AD is the 'key' to 'all doors' in the 'cloud'.
Azure Application Gateway WAF
Flip cardA web application firewall (WAF) capability integrated into Azure Application Gateway, providing centralized protection for web applications.
- Protects against common web vulnerabilities (e.g., SQL injection, XSS).
- Operates at Layer 7 (HTTP/HTTPS).
- Combines WAF functionality with application-level load balancing.
Memory trick: App Gateway WAF stands guard at your web's front door.
Azure Front Door
Flip cardA global, scalable entry point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications.
- Provides global HTTP/HTTPS load balancing.
- Offers dynamic site acceleration and geographic routing.
- Includes Web Application Firewall (WAF) capabilities at the edge.
Memory trick: Front Door opens globally, directs users to the closest entry.
Azure AD Privileged Identity Management (PIM)
Flip cardAzure AD Privileged Identity Management (PIM) is a service in Azure AD that enables you to manage, control, and monitor access to important resources, providing just-in-time access and role activation.
- Provides just-in-time (JIT) access to roles
- Enforces approval workflows for role activation
- Supports access reviews for privileged roles
- Monitors privileged access and provides audit logs
Memory trick: PIM is the royal guard for your most powerful roles, ensuring access is temporary and reviewed.
Azure ExpressRoute
Flip cardAzure ExpressRoute is a service that enables you to create private connections between Azure data centers and infrastructure that's on your premises or in a colocation environment.
- Private, dedicated connection
- Bypasses the public internet
- Offers higher bandwidth and lower latency
- Provides more reliable connectivity than site-to-site VPN
Memory trick: ExpressRoute is your private VIP highway directly to Azure, no public roads allowed.
Azure Application Gateway with WAF
Flip cardA web traffic load balancer that provides a Web Application Firewall (WAF) to protect web applications from common exploits.
- Operates at Layer 7 (HTTP/HTTPS).
- Includes WAF for protection against common web attacks.
- Supports URL-based routing and SSL termination.
Memory trick: App Gateway is the 'smart bouncer' for 'web traffic', with a 'security guard'.
Azure AD Conditional Access
Flip cardA feature of Azure Active Directory that enables organizations to enforce policies based on specific conditions to control access to resources.
- Combines signals like user, device, location, and application.
- Enforces decisions like requiring MFA, blocking access, or requiring a compliant device.
- Central to implementing a zero-trust security model.
Memory trick: Conditional Access grants access, but only if the conditions are right.
Confidential Computing
Flip cardA cloud security technology that protects data while it is in use by processing it in a hardware-based trusted execution environment (TEE).
- Encrypts data during processing (in memory and CPU)
- Uses hardware-based Trusted Execution Environments (TEEs)
- Protects against malicious insiders and compromised systems
- Adds a critical layer of data protection beyond at-rest and in-transit
Memory trick: Confidential Computing: Data secured even when thinking.
Azure Traffic Manager
Flip cardAzure Traffic Manager is a DNS-based traffic load balancer that enables you to distribute user traffic optimally to service endpoints across global Azure regions.
- DNS-based global traffic routing
- Supports various routing methods (Priority, Performance, Geographic, Weighted, Subnet, MultiValue)
- Provides high availability by monitoring endpoint health
- Routes users to the best performing or available endpoint
Memory trick: Traffic Manager is the global GPS for your users, always finding the best route to your app.
Azure Blob Storage
Flip cardA Microsoft-managed service for storing large amounts of unstructured object data, such as text or binary data.
- Optimized for storing enormous amounts of unstructured data.
- Accessible globally via HTTP/HTTPS.
- Supports various access tiers (Hot, Cool, Archive) for cost optimization.
Memory trick: Blob stores the big binary blobs.
Azure Key Vault
Flip cardA cloud service for securely storing and accessing secrets, cryptographic keys, and SSL/TLS certificates.
- Protects sensitive data from unauthorized access.
- Centralized management of application secrets.
- Integrates with other Azure services for easy access.
Memory trick: Key Vault is the 'safe deposit box' for your 'Azure secrets'.
Azure Virtual Network & Azure DNS
Flip cardAzure Virtual Network (VNet) provides private network connectivity for Azure resources, while Azure DNS provides name resolution for resources inside and outside Azure.
- VNet isolates and connects Azure resources privately.
- Azure DNS integrates with VNets for internal name resolution.
- Azure DNS can host public DNS zones for external resolution.
Memory trick: VNet is the 'house' for your 'VMs', and DNS is the 'address book'.
Confidentiality
Flip cardConfidentiality is a security principle that ensures sensitive information is protected from unauthorized access, disclosure, or theft.
- Part of the CIA triad (Confidentiality, Integrity, Availability)
- Achieved through encryption, access controls, data masking
- Protects against data breaches and unauthorized viewing
- Critical for privacy and regulatory compliance
Memory trick: CIA: Confidentiality, Integrity, Availability – your security superheroes.
Azure Conditional Access
Flip cardA feature of Azure AD that enables organizations to enforce policies based on conditions to control access to resources.
- Evaluates user, device, location, and application conditions.
- Supports a zero-trust security model.
- Can require MFA, block access, or restrict access.
Memory trick: Trust 'no one' implicitly, 'verify' everything 'conditionally'.
Azure Activity Log
Flip cardA platform log in Azure that records events at the subscription level, detailing administrative operations and changes made to resources.
- Records administrative actions (who, what, when, where)
- Provides historical data for auditing
- Helps track changes to resources
- Part of Azure Monitor, but distinct for control plane events
Memory trick: Activity Log: Who did what, when, and where, for auditing clarity.
VNet Peering
Flip cardVNet Peering is an Azure networking mechanism that connects two or more Azure Virtual Networks, allowing resources in each VNet to communicate privately.
- Connects VNets securely
- Traffic stays within Microsoft's backbone network
- Appears as a single network for connectivity
- Supports cross-subscription and cross-region peering
Memory trick: Peering is like a private bridge between your Azure neighborhoods.
Azure Virtual Network (VNet)
Flip cardA logical isolation of the Azure cloud dedicated to your subscription, enabling resources to securely communicate.
- Fundamental building block for private networks in Azure.
- Enables secure communication between Azure resources.
- Supports subnetting for logical segmentation and security.
Memory trick: VNet is the virtual house for your Azure resources.
Azure VPN Gateway
Flip cardA service that creates encrypted cross-premises connections between an Azure Virtual Network and on-premises locations over the public internet.
- Establishes secure VPN tunnels over the internet
- Connects Azure VNets to on-premises networks
- Supports Site-to-Site and Point-to-Site VPNs
- Used for hybrid cloud connectivity
Memory trick: VPN Gateway: Your secure internet bridge to Azure.
Azure Firewall Threat Intelligence
Flip cardAzure Firewall's Threat Intelligence feature allows you to enable filtering to alert on or deny traffic to/from known malicious IP addresses and domains.
- Integrated with Azure Firewall
- Uses Microsoft's threat intelligence feeds
- Automatically updated for emerging threats
- Can be configured for alert or deny mode
Memory trick: Azure Firewall's Threat Intel is your smart bouncer, always checking its 'naughty list' of bad IPs.
Role-Based Access Control (RBAC)
Flip cardAn authorization system in Azure that allows you to manage access to Azure resources by assigning roles to users, groups, and applications.
- Aligns with the principle of least privilege.
- Defines what actions identities can perform on resources.
- Permissions are inherited through the resource hierarchy.
Memory trick: RBAC is the 'role assignment' that 'unlocks' specific 'actions'.
Azure DDoS Protection Standard
Flip cardAn Azure service that provides enhanced protection against Distributed Denial of Service (DDoS) attacks for Azure resources.
- Offers advanced mitigation capabilities beyond basic platform protection.
- Includes attack analytics, telemetry, and alerting.
- Protects resources within a Virtual Network.
Memory trick: DDoS Standard is the 'strong shield' that gives you 'insights' into 'attacks'.
Azure Storage Service Encryption (SSE)
Flip cardAzure Storage Service Encryption (SSE) automatically encrypts data at rest when it's written to Azure Storage, including Blob Storage.
- Enabled by default for all Azure Storage accounts.
- Encrypts data at rest using 256-bit AES encryption.
- Can use Microsoft-managed keys or customer-managed keys (CMK) via Key Vault.
Memory trick: SSE is like an invisible, always-on security guard for your storage, locking everything up automatically.
Reduced Capital Expenditure (CapEx)
Flip cardCloud computing shifts IT spending from large upfront capital expenditures (CapEx) to operational expenditures (OpEx), allowing businesses to pay for resources on a consumption model.
- No need to purchase physical hardware.
- Pay-as-you-go model.
- Reduces initial investment and financial risk.
Memory trick: Cloud's financial freedom: no big upfront IT bills.
Azure Container Registry (ACR)
Flip cardA private, managed Docker registry service in Azure for storing and managing container images and other OCI artifacts.
- Fully managed service, based on Docker Registry 2.0.
- Supports geo-replication for global distribution and faster image pulls.
- Integrates with Azure Kubernetes Service (AKS) and other container services.
Memory trick: ACR is the 'Archive' for Containers.
Elasticity (Cloud Computing)
Flip cardThe ability of a cloud system to automatically and dynamically expand or shrink computing resources to match varying workloads in real time, often without manual intervention.
- Automatic scaling (up/down, out/in)
- Responds to unpredictable demand
- Optimizes costs by only using needed resources
Memory trick: Elasticity is the cloud's 'rubber band' for dynamic loads.
Azure Kubernetes Service (AKS)
Flip cardA managed container orchestration service for deploying, managing, and scaling containerized applications using Kubernetes. Azure handles the management of the Kubernetes control plane.
- Managed Kubernetes offering in Azure.
- Simplifies deployment and management of containerized apps.
- Provides high availability and scalability for microservices.
- Integrates with other Azure services for networking, storage, and monitoring.
Memory trick: AKS orchestrates many containers, ACI runs one.
Azure Cosmos DB
Flip cardMicrosoft's globally distributed, multi-model database service for managing data at planet-scale with guaranteed high availability and low latency.
- Globally distributed.
- Multi-master replication.
- Multi-model (document, key-value, graph, column-family).
- Guaranteed low latency and high availability.
Memory trick: Cosmos is for global, fast, and flexible data needs.