Exam Domain
A major content area covered by the exam.
Getting Started with AZ-900
Free knowledge base
Everything from the course in one searchable place: 229 entries. Use it to review before a practice test or look up a word you forgot.
229 results
A major content area covered by the exam.
Getting Started with AZ-900
The percentage of questions from a specific exam domain.
Getting Started with AZ-900
A standardized score accounting for question difficulty.
Getting Started with AZ-900
Official document detailing all topics covered on an exam.
Getting Started with AZ-900
Question type with one correct answer from several options.
Getting Started with AZ-900
Question type requiring selection of all correct answers.
Getting Started with AZ-900
To remember the exam domains, think: 'Clouds Core Solutions Secure Identity Costs.' (Cloud Concepts, Core Azure Services, Core Solutions, Security, Identity, Costs)
Getting Started with AZ-900
The AZ-900 exam does not include performance-based labs. Focus on conceptual understanding and recognizing correct Azure services and features based on scenarios.
Getting Started with AZ-900
Studying outdated exam objectives, leading to gaps in knowledge.
Getting Started with AZ-900
Not practicing different question formats, causing confusion during the exam.
Getting Started with AZ-900
Panicking on difficult questions instead of marking for review and moving on.
Getting Started with AZ-900
Official list of topics covered on a certification exam.
Getting Started with AZ-900
Free, interactive, self-paced online learning platform from Microsoft.
Getting Started with AZ-900
A study method where you retrieve information from memory.
Getting Started with AZ-900
Reviewing material at increasing intervals to improve retention.
Getting Started with AZ-900
Temporary, free Azure environment for hands-on practice.
Getting Started with AZ-900
Simulated exam to assess knowledge and identify weak areas.
Getting Started with AZ-900
The rate at which memory of information is lost over time.
Getting Started with AZ-900
To remember the study cycle: 'Understand, Learn, Practice, Review, Simulate, Identify.' Think 'U L P R S I' – 'Ultimately, Learning Pays, Right? Study Intensely!'
Getting Started with AZ-900
The AZ-900 exam objectives are your definitive guide. Pay close attention to the percentage weightings for each module; this indicates how many questions you can expect from that section. For example, 'Describe Cloud Concepts' is 25-30%, so expect a significant number of questions there.
Getting Started with AZ-900
Only reading material without active recall or hands-on practice.
Getting Started with AZ-900
Ignoring the official exam objectives and focusing on irrelevant topics.
Getting Started with AZ-900
Cramming all study into the last few days before the exam.
Getting Started with AZ-900
On-demand delivery of computing services over the Internet.
Cloud Computing Fundamentals
Users provision computing resources without human interaction.
Cloud Computing Fundamentals
Cloud provider's resources are shared among multiple consumers.
Cloud Computing Fundamentals
Ability to quickly scale resources up or down as needed.
Cloud Computing Fundamentals
Cloud resource usage is monitored, controlled, and reported.
Cloud Computing Fundamentals
Paying for computing resources based on consumption, like electricity.
Cloud Computing Fundamentals
Think of the cloud as a 'R.O.M.B.S.' service: Rapid Elasticity, On-demand self-service, Measured service, Broad network access, Resource pooling.
Cloud Computing Fundamentals
The AZ-900 exam frequently tests your understanding of the core characteristics of cloud computing. Memorize the five key characteristics as they are often presented in scenarios or direct definition questions.
Cloud Computing Fundamentals
Confusing cloud computing with simply storing files online (like Dropbox) – cloud computing is much broader, encompassing full IT infrastructure.
Cloud Computing Fundamentals
Believing cloud computing is always cheaper than on-premises – while often true, cost depends on usage patterns and careful management.
Cloud Computing Fundamentals
Thinking 'the cloud' is a physical place – it's a network of data centers, but the concept is an abstraction of resources.
Cloud Computing Fundamentals
Upfront spending on physical infrastructure and assets.
Cloud Computing Fundamentals
Paying for services or resources as you consume them.
Cloud Computing Fundamentals
Ability to automatically scale resources up or down based on demand.
Cloud Computing Fundamentals
Ability to handle increasing workload by adding resources.
Cloud Computing Fundamentals
Ensuring systems remain operational despite failures.
Cloud Computing Fundamentals
Deploying applications across geographically diverse data centers.
Cloud Computing Fundamentals
Difficulty migrating from one cloud provider to another.
Cloud Computing Fundamentals
Defines security duties between cloud provider and customer.
Cloud Computing Fundamentals
Think of CLOUD: Cost-effective, Low maintenance, On-demand scaling, Ubiquitous access, Data security.
Cloud Computing Fundamentals
For the AZ-900 exam, precisely understand the difference between CapEx and OpEx, and associate elasticity and scalability with cloud benefits.
Cloud Computing Fundamentals
Confusing CapEx with OpEx; remember CapEx is upfront, OpEx is ongoing.
Cloud Computing Fundamentals
Underestimating the importance of security in the shared responsibility model.
Cloud Computing Fundamentals
Failing to consider potential vendor lock-in when designing cloud solutions.
Cloud Computing Fundamentals
Infrastructure as a Service; cloud provider manages hardware, you manage OS and apps.
Cloud Computing Fundamentals
Platform as a Service; cloud provider manages OS/runtime, you manage apps/data.
Cloud Computing Fundamentals
Software as a Service; cloud provider manages everything, you just use the software.
Cloud Computing Fundamentals
A virtualized computer instance running on a physical server (IaaS).
Cloud Computing Fundamentals
The software environment in which programs are executed (e.g., .NET, Java).
Cloud Computing Fundamentals
Software that connects applications, data, and users (e.g., message queues).
Cloud Computing Fundamentals
Remember 'IPS' for the order of control: IaaS (You control most), PaaS (Platform control), SaaS (Software control). Or, 'I Paint Slowly' (IaaS, PaaS, SaaS) to remember decreasing customer responsibility.
Cloud Computing Fundamentals
On the AZ-900 exam, pay close attention to which party (customer or cloud provider) is responsible for managing specific components (e.g., operating systems, applications, physical security) for each service type. Keywords like 'full control,' 'focus on code,' or 'ready-to-use application' often point to IaaS, PaaS, or SaaS respectively.
Cloud Computing Fundamentals
Confusing the level of customer responsibility between IaaS and PaaS, especially regarding OS management.
Cloud Computing Fundamentals
Incorrectly assuming the cloud provider handles all security in PaaS or SaaS models.
Cloud Computing Fundamentals
Not recognizing that data itself is always the customer's responsibility, regardless of service type.
Cloud Computing Fundamentals
Cloud services offered over the public internet by a third-party provider.
Cloud Computing Fundamentals
Cloud infrastructure exclusively used by a single organization.
Cloud Computing Fundamentals
A combination of public and private cloud environments.
Cloud Computing Fundamentals
Using multiple public cloud providers simultaneously.
Cloud Computing Fundamentals
Moving workloads from a private to a public cloud during demand spikes.
Cloud Computing Fundamentals
Infrastructure located and managed within an organization's own facility.
Cloud Computing Fundamentals
Think of a 'Public' park (anyone can use it), a 'Private' home (only you), and a 'Hybrid' car (uses both gas and electric).
Cloud Computing Fundamentals
The AZ-900 exam frequently asks you to identify which cloud model best suits a given business requirement. Keywords like 'shared resources', 'pay-as-you-go', and 'internet' point to public cloud. 'Dedicated resources', 'high control', and 'on-premises' suggest private cloud. 'Combining the best of both' or 'bursting' indicates hybrid cloud.
Cloud Computing Fundamentals
Confusing hybrid cloud with multi-cloud; hybrid combines public and private, multi-cloud uses multiple public providers.
Cloud Computing Fundamentals
Assuming private cloud is always on-premises; it can be hosted by a third party.
Cloud Computing Fundamentals
Underestimating the management complexity of hybrid and multi-cloud environments.
Cloud Computing Fundamentals
A set of datacenters within a latency-defined perimeter.
Azure Core Architecture and Services
Physically separate datacenters within an Azure region.
Azure Core Architecture and Services
A discrete market with two or more Azure regions.
Azure Core Architecture and Services
Logical container for related Azure resources.
Azure Core Architecture and Services
Billing and access boundary for Azure resources.
Azure Core Architecture and Services
Container for managing access and policies across subscriptions.
Azure Core Architecture and Services
Deployment and management service for Azure resources.
Azure Core Architecture and Services
Remember 'RAMS': Regions, Availability Zones, Management Groups, Subscriptions. These are the core architectural components!
Azure Core Architecture and Services
Memorize the hierarchy: Management Group > Subscription > Resource Group > Resource. The exam often asks about the purpose of each level in managing governance, billing, and resource organization.
Azure Core Architecture and Services
Confusing a region with an Availability Zone; a region contains multiple zones.
Azure Core Architecture and Services
Not understanding that a resource group is a logical, not physical, container.
Azure Core Architecture and Services
Forgetting that Management Groups are for governance across multiple subscriptions, not just one.
Azure Core Architecture and Services
IaaS compute, full control over OS and software.
Azure Core Architecture and Services
PaaS for hosting web apps, APIs, mobile backends.
Azure Core Architecture and Services
Serverless compute for event-driven code execution.
Azure Core Architecture and Services
Logically isolated private network in Azure.
Azure Core Architecture and Services
Virtual firewall for controlling network traffic.
Azure Core Architecture and Services
Connects on-premises networks to Azure over internet.
Azure Core Architecture and Services
Private, dedicated connection from on-premises to Azure.
Azure Core Architecture and Services
Distributes network traffic across multiple resources.
Azure Core Architecture and Services
Remember 'V-N-S' for Virtual Network Security: VNet for your network, NSG for security rules.
Azure Core Architecture and Services
The AZ-900 exam frequently asks about the difference between IaaS (VMs) and PaaS (App Service, Functions) compute models. Understand that IaaS gives you more control, while PaaS abstracts away infrastructure management. Also, know that a VNet is the fundamental network service.
Azure Core Architecture and Services
Confusing Azure Virtual Machines (IaaS) with Azure App Service (PaaS) – remember, VMs give you the OS, App Service just your code.
Azure Core Architecture and Services
Forgetting that Network Security Groups (NSGs) are the primary way to control inbound/outbound traffic for resources within a VNet.
Azure Core Architecture and Services
Not understanding that a Virtual Network is a prerequisite for most Azure compute resources to communicate securely.
Azure Core Architecture and Services
A unique container for Azure Storage data objects.
Azure Core Architecture and Services
Service for storing large amounts of unstructured data like images and videos.
Azure Core Architecture and Services
Managed file shares accessible via SMB protocol.
Azure Core Architecture and Services
Service for storing messages between application components.
Azure Core Architecture and Services
NoSQL key-attribute store for structured, non-relational data.
Azure Core Architecture and Services
Managed relational database service for SQL Server workloads.
Azure Core Architecture and Services
Globally distributed, multi-model NoSQL database service.
Azure Core Architecture and Services
Hot, Cool, and Archive tiers for optimizing blob storage costs based on access frequency.
Azure Core Architecture and Services
Remember 'BFQT' for Blob, File, Queue, Table. Then think 'B' for Big unstructured, 'F' for File shares, 'Q' for Queues of messages, and 'T' for Tables of non-relational data.
Azure Core Architecture and Services
The exam frequently distinguishes between the types of data stored by Blob, File, Queue, and Table storage. Memorize that Blobs are for unstructured data, Files for SMB shares, Queues for messages, and Tables for NoSQL structured data. Also, know the difference between relational (SQL, MySQL, PostgreSQL) and NoSQL (Cosmos DB) database use cases.
Azure Core Architecture and Services
Confusing the use cases for Blob, File, Queue, and Table storage.
Azure Core Architecture and Services
Not understanding the cost implications of different blob access tiers (Hot, Cool, Archive).
Azure Core Architecture and Services
Assuming all database workloads are best suited for a relational database, ignoring NoSQL options like Cosmos DB.
Azure Core Architecture and Services
Web-based console for managing Azure resources graphically.
Azure Core Architecture and Services
Command-line interface for managing Azure resources programmatically.
Azure Core Architecture and Services
Module for Windows PowerShell to manage Azure resources.
Azure Core Architecture and Services
Browser-based shell with pre-installed Azure management tools.
Azure Core Architecture and Services
JSON files defining Azure infrastructure for Infrastructure as Code.
Azure Core Architecture and Services
Service for collecting, analyzing, and acting on telemetry data.
Azure Core Architecture and Services
Enforces organizational standards and assesses compliance.
Azure Core Architecture and Services
Helps track, analyze, and optimize Azure cloud spending.
Azure Core Architecture and Services
To remember the main management tools: 'P' for Portal (visual), 'C' for CLI (command), 'P' for PowerShell (script), 'C' for Cloud Shell (browser). Think 'PC PC' for managing Azure!
Azure Core Architecture and Services
The exam often tests your ability to choose the right management tool for a scenario. Keywords like 'graphical interface' point to the Azure portal, 'scripting' or 'automation' to CLI/PowerShell, and 'browser-based' to Cloud Shell. Remember ARM templates are for 'Infrastructure as Code'.
Azure Core Architecture and Services
Confusing Azure CLI and Azure PowerShell; they serve similar purposes but use different command syntaxes.
Azure Core Architecture and Services
Underestimating the importance of Infrastructure as Code (IaC) for consistent and repeatable deployments.
Azure Core Architecture and Services
Forgetting that Azure Monitor is for collecting and analyzing operational data, not just setting up alerts.
Azure Core Architecture and Services
Network of physical objects with sensors exchanging data.
Azure Core Architecture and Services
Central messaging hub for secure IoT device communication.
Azure Core Architecture and Services
Extremely large datasets analyzed for patterns and trends.
Azure Core Architecture and Services
Integrated service for data warehousing and Big Data analytics.
Azure Core Architecture and Services
Computer science field enabling human-like intelligence.
Azure Core Architecture and Services
AI subset where systems learn from data without explicit programming.
Azure Core Architecture and Services
Cloud service for managing the ML project lifecycle.
Azure Core Architecture and Services
APIs for pre-built AI capabilities like vision and speech.
Azure Core Architecture and Services
Imagine a 'BIG AI' (Big Data, IoT, AI) working together: IoT devices are the 'eyes and ears,' Big Data is the 'memory,' and AI is the 'brain' that makes sense of it all!
Azure Core Architecture and Services
The exam often tests your ability to choose the *right* Azure service for a given scenario. Focus on the primary purpose of each service: IoT Hub for device connectivity, Synapse Analytics for integrated Big Data, and Cognitive Services for pre-built AI features.
Azure Core Architecture and Services
Confusing Azure IoT Hub with Azure IoT Central: Hub is for custom solutions, Central is a managed application platform.
Azure Core Architecture and Services
Thinking all AI requires deep ML expertise: Azure Cognitive Services provide pre-built AI capabilities without extensive ML knowledge.
Azure Core Architecture and Services
Underestimating the interconnectedness: IoT, Big Data, and AI are rarely used in isolation for complex solutions.
Azure Core Architecture and Services
Tools to monitor, analyze, and optimize Azure spending.
Azure Management and Governance
Visual tool to explore and break down Azure costs by various dimensions.
Azure Management and Governance
Financial thresholds set to track spending and trigger alerts.
Azure Management and Governance
Matching resource size/tier to actual usage for cost efficiency.
Azure Management and Governance
Commitment to use resources for 1 or 3 years for significant discounts.
Azure Management and Governance
Cost savings for using existing Windows Server/SQL Server licenses on Azure.
Azure Management and Governance
Applying metadata labels to resources for organization and cost allocation.
Azure Management and Governance
To manage costs, remember 'T.A.G.S.': Tagging, Analysis, Budgets, Savings.
Azure Management and Governance
The exam often asks about the purpose of Azure Cost Management + Billing, how to use budgets and alerts, and the benefits of resource tagging for cost allocation. Look for keywords like 'control spending,' 'analyze costs,' 'set limits,' and 'categorize resources.'
Azure Management and Governance
Not consistently tagging resources, which makes cost allocation and analysis extremely difficult.
Azure Management and Governance
Ignoring Azure Advisor recommendations, missing out on easy cost-saving opportunities.
Azure Management and Governance
Failing to set up budgets and alerts, leading to unexpected and uncontrolled spending.
Azure Management and Governance
Over-provisioning resources without rightsizing, paying for capacity that isn't used.
Azure Management and Governance
A rule specifying conditions and effects for Azure resources.
Azure Management and Governance
Applying a policy definition to a specific scope (e.g., subscription).
Azure Management and Governance
Service to define repeatable sets of Azure resources for consistent deployment.
Azure Management and Governance
A package including ARM templates, policies, and role assignments.
Azure Management and Governance
Deploying a blueprint definition to a subscription.
Azure Management and Governance
The level at which a policy or blueprint is applied (e.g., management group).
Azure Management and Governance
Adherence to rules, standards, or regulations.
Azure Management and Governance
Imagine a 'Policy' is like a strict security guard checking everyone's ID at the door. A 'Blueprint' is like the architect's plan for the entire building, including where the security guards will stand.
Azure Management and Governance
For the AZ-900 exam, remember that Azure Policy is for *enforcing* rules on individual resources, while Azure Blueprints is for *deploying* a *set* of compliant resources and configurations. Keywords like 'enforce standards' point to Policy, while 'deploy repeatable environments' point to Blueprints.
Azure Management and Governance
Confusing Azure Policy with Azure Blueprints: Policy enforces rules, Blueprints deploy environments.
Azure Management and Governance
Thinking Blueprints replace Policies: Blueprints can *include* Policy assignments.
Azure Management and Governance
Not understanding the scope of application for policies (management group, subscription, resource group).
Azure Management and Governance
Numerical values describing system aspects at a point in time, used for performance and alerts.
Azure Management and Governance
Event data providing detailed information for analysis, troubleshooting, and auditing.
Azure Management and Governance
Azure Monitor tool for querying and analyzing log data using KQL.
Azure Management and Governance
Powerful query language used to interact with data in Log Analytics.
Azure Management and Governance
Personalized view of the health of Azure services and regions you are using.
Azure Management and Governance
Notifications triggered by specific conditions in metrics or logs, can automate actions.
Azure Management and Governance
Customizable, consolidated views of monitoring data for quick health assessment.
Azure Management and Governance
MONITOR = Metrics, Outages (Service Health), Notifications, Insights, Telemetry, Observe, Reports.
Azure Management and Governance
For the AZ-900 exam, remember that Azure Monitor is for YOUR resources, while Azure Service Health is for the Azure platform itself. Be able to distinguish between metrics (numerical, performance) and logs (detailed events, troubleshooting).
Azure Management and Governance
Confusing Azure Monitor (your resources) with Azure Service Health (Azure platform).
Azure Management and Governance
Not understanding the difference between metrics (performance numbers) and logs (detailed event records).
Azure Management and Governance
Ignoring alerts or not configuring them, leading to reactive instead of proactive issue resolution.
Azure Management and Governance
General Data Protection Regulation, EU data privacy law.
Azure Management and Governance
Health Insurance Portability and Accountability Act, US healthcare data privacy.
Azure Management and Governance
Payment Card Industry Data Security Standard, for credit card data.
Azure Management and Governance
International standard for information security management systems.
Azure Management and Governance
US government program for cloud product security assessment.
Azure Management and Governance
Microsoft portal for compliance reports and trust documents.
Azure Management and Governance
Geographical location where data is physically stored.
Azure Management and Governance
To remember key compliance standards: 'GHP' - GDPR for General, HIPAA for Health, PCI for Payments. Just remember the 'S' for Security is at the end of PCI DSS!
Azure Management and Governance
The exam often asks about specific compliance standards. Memorize that GDPR is for EU data privacy, HIPAA for US healthcare, and PCI DSS for payment card data. Also, remember the Service Trust Portal is where you find compliance documentation.
Azure Management and Governance
Assuming Microsoft is 100% responsible for all compliance; remember the shared responsibility model.
Azure Management and Governance
Confusing data protection (technical safeguards) with compliance (meeting regulations).
Azure Management and Governance
Not knowing where to find compliance documentation (the Service Trust Portal is key!).
Azure Management and Governance
Microsoft's cloud-based identity and access management service.
Azure Identity, Security, and Networking
Allows users to log in once and access multiple applications without re-entering credentials.
Azure Identity, Security, and Networking
Requires two or more verification methods for user authentication.
Azure Identity, Security, and Networking
Azure AD feature to enforce policies based on user, device, location, and application context.
Azure Identity, Security, and Networking
Framework of policies and technologies to manage digital identities and control access.
Azure Identity, Security, and Networking
Tool to synchronize on-premises Active Directory identities with Azure AD.
Azure Identity, Security, and Networking
A dedicated instance of Azure AD for an organization.
Azure Identity, Security, and Networking
Think of 'Azure AD' as your 'Access Door' to all your cloud apps. It's the single door you go through to get to everything.
Azure Identity, Security, and Networking
The exam often tests the fundamental difference between Azure AD and traditional Active Directory. Remember: Azure AD is for cloud identities and applications, while traditional AD DS is for on-premises domains and servers. Keywords like 'cloud applications,' 'SaaS,' 'Microsoft 365,' and 'external resources' point to Azure AD.
Azure Identity, Security, and Networking
Confusing Azure AD with traditional Windows Server Active Directory; they are distinct services.
Azure Identity, Security, and Networking
Assuming Azure AD directly manages on-premises server authentication or group policies.
Azure Identity, Security, and Networking
Underestimating the importance of MFA for securing cloud identities.
Azure Identity, Security, and Networking
Unified security management and threat protection for hybrid cloud.
Azure Identity, Security, and Networking
Safeguards Azure resources from Distributed Denial of Service attacks.
Azure Identity, Security, and Networking
Granting users only necessary permissions to perform their job.
Azure Identity, Security, and Networking
Transforming data to protect it from unauthorized access.
Azure Identity, Security, and Networking
Overall strength of an organization's security defenses.
Azure Identity, Security, and Networking
For Shared Responsibility, think 'I-P-S' (IaaS, PaaS, SaaS) and 'You-Me-Us' (You do most, Me (Microsoft) does more, Us (shared) does almost all for SaaS).
Azure Identity, Security, and Networking
The exam frequently tests your understanding of the Shared Responsibility Model, especially how responsibilities shift between IaaS, PaaS, and SaaS. Memorize which party (Microsoft or customer) is responsible for each layer of the stack in different service models.
Azure Identity, Security, and Networking
Assuming Microsoft handles all security in the cloud, regardless of the service model.
Azure Identity, Security, and Networking
Not enabling Multi-Factor Authentication for administrative accounts.
Azure Identity, Security, and Networking
Ignoring security recommendations provided by Microsoft Defender for Cloud.
Azure Identity, Security, and Networking
Logically isolated network in Azure for resources.
Azure Identity, Security, and Networking
Segment of a VNet, allowing for network organization.
Azure Identity, Security, and Networking
Connects two Azure VNets privately.
Azure Identity, Security, and Networking
Connects Azure VNets to on-premises over internet.
Azure Identity, Security, and Networking
Private, dedicated connection to Azure from on-premises.
Azure Identity, Security, and Networking
Distributes incoming traffic across backend resources.
Azure Identity, Security, and Networking
Entry-level load balancer, limited features.
Azure Identity, Security, and Networking
Feature-rich load balancer for production workloads.
Azure Identity, Security, and Networking
Think of a VNet as a 'Virtual Neighborhood' for your cloud resources, with 'Subnets' being individual streets. The 'Load Balancer' is like a traffic cop, directing cars (requests) to different houses (servers) on those streets.
Azure Identity, Security, and Networking
The exam often asks to identify the purpose of a VNet (isolation, resource communication) or a Load Balancer (traffic distribution, high availability). Be ready to distinguish between Basic and Standard Load Balancers, focusing on scalability and features.
Azure Identity, Security, and Networking
Confusing a VNet with a public internet connection; VNets are private.
Azure Identity, Security, and Networking
Not understanding that a Load Balancer distributes traffic, it doesn't secure it (that's for NSGs and Firewalls).
Azure Identity, Security, and Networking
Underestimating the differences between Basic and Standard Load Balancers for production scenarios.
Azure Identity, Security, and Networking
Defines allow/deny for traffic based on 5-tuple (source, dest, port, protocol).
Azure Identity, Security, and Networking
Determines the order rules are evaluated (lowest number first).
Azure Identity, Security, and Networking
System-defined group of IP prefixes for Azure services.
Azure Identity, Security, and Networking
Managed, cloud-based network security service with advanced threat protection.
Azure Identity, Security, and Networking
Azure Firewall feature to filter traffic based on domain names.
Azure Identity, Security, and Networking
Tracks active connections to allow return traffic automatically.
Azure Identity, Security, and Networking
Network design with a central VNet (hub) and peered VNets (spokes).
Azure Identity, Security, and Networking
Think of an NSG as a 'Neighborhood Security Guard' for your house (VM) or street (subnet), checking IDs at the gate. Azure Firewall is like a 'Fortress Wall' around your entire city (VNet), with advanced scanners and guards for all traffic in and out.
Azure Identity, Security, and Networking
The exam often asks you to differentiate between NSGs and Azure Firewall. Remember NSGs are for granular subnet/NIC control, while Azure Firewall is for centralized, advanced, and VNet-wide protection. Look for keywords like 'centralized,' 'application-level filtering,' or 'threat intelligence' for Azure Firewall; 'VM-level,' 'subnet-level,' or 'basic packet filtering' for NSGs.
Azure Identity, Security, and Networking
Forgetting that NSG rules are processed by priority (lowest number first), and that once a match is found, no further rules are evaluated.
Azure Identity, Security, and Networking
Confusing the capabilities: NSGs are basic packet filters; Azure Firewall offers advanced, centralized, application-level filtering and threat intelligence.
Azure Identity, Security, and Networking
Not understanding that if both a subnet NSG and a NIC NSG are applied, the most restrictive rule takes precedence.
Azure Identity, Security, and Networking