Step2Study
IT & TechnologyAZ-900100% Free

Microsoft Azure Fundamentals (AZ-900)

Practice bank
243 Qs
Real exam
45 Qs
Time limit
45 min
Passing
700 out of 1000

Exam blueprint

Describe cloud concepts
25%
Describe Azure architecture and services
30%
Describe Azure management and governance
25%
Describe Azure identity, security, and networking
20%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 90 min · pass 70% · 243 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Microsoft Azure Fundamentals (AZ-900) practice test questions

Sample questions from the 243-question bank, with answers and explanations.

All questions
  1. 1. A global software vendor is using Azure to host their SaaS application. Their customers are located worldwide, and the vendor needs to ensure that customer data is stored and processed within specific geographical boundaries to comply with local data residency regulations. Which Azure concept allows them to specify the physical location where their data and resources will reside?

    Describe Azure management and governance

    • A. Azure Resource Groups
    • B. Azure Availability Zones
    • C. Azure Management Groups
    • D. Azure Regions
    Show answer

    D. Azure Regions

    Azure Regions are geographical areas that contain one or more data centers. By deploying resources to a specific Azure Region, organizations can ensure that their data resides within the required geographical boundaries, addressing data residency requirements.

  2. 2. A company is planning to deploy a new web application to Azure. They need to estimate the monthly cost of running the application, including virtual machines, databases, and storage, before deployment. Which Azure tool should they use to get a detailed cost projection?

    Describe Azure management and governance

    • A. Azure Monitor
    • B. Azure Pricing Calculator
    • C. Azure Cost Management + Billing
    • D. Azure Advisor
    Show answer

    B. Azure Pricing Calculator

    The Azure Pricing Calculator is designed to provide estimated costs for Azure products and services. It allows users to configure services and see a projected monthly cost before deployment, which is exactly what the company needs for their new web application.

  3. 3. A global company uses multiple Azure subscriptions across different departments. They need a centralized mechanism to apply a common set of security policies, compliance standards, and cost management policies across all subscriptions, ensuring consistency. Which Azure feature is designed for this hierarchical management?

    Describe Azure management and governance

    • A. Azure Policy
    • B. Azure Management Groups
    • C. Azure Resource Groups
    • D. Azure Blueprints
    Show answer

    B. Azure Management Groups

    Azure Management Groups provide a level of scope above subscriptions, enabling you to organize subscriptions into containers to apply governance conditions like policies and access control at scale. This is ideal for a global company with multiple subscriptions requiring centralized management.

  4. 4. A startup is running several virtual machines (VMs) and Azure SQL Databases. They've noticed that some VMs are consistently underutilized, and some SQL databases are provisioned with more capacity than they need, leading to unnecessary costs. They want a service that provides personalized recommendations for optimizing costs, performance, and reliability across their Azure environment. Which Azure service should they leverage?

    Describe Azure management and governance

    • A. Azure Monitor
    • B. Azure Advisor
    • C. Azure Security Center
    • D. Azure Cost Management + Billing
    Show answer

    B. Azure Advisor

    Azure Advisor is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. It analyzes your resource configuration and usage telemetry and recommends solutions to improve cost effectiveness, performance, reliability, operational excellence, and security.

  5. 5. A company is planning to deploy a new mission-critical application on Azure. They need to ensure that the application remains highly available and performs optimally, even during peak loads. They also need to be able to quickly identify and troubleshoot performance bottlenecks and errors across all components, including virtual machines, databases, and web services. Which Azure service offers comprehensive monitoring capabilities, including application performance monitoring (APM), infrastructure monitoring, and log collection, to meet these requirements?

    Describe Azure management and governance

    • A. Azure Sentinel
    • B. Azure Advisor
    • C. Azure Monitor
    • D. Azure Security Center
    Show answer

    C. Azure Monitor

    Azure Monitor is a comprehensive solution for collecting, analyzing, and acting on telemetry from your Azure and on-premises environments. It includes Application Insights for APM, Log Analytics for centralized logging, and metrics for infrastructure monitoring, making it ideal for troubleshooting and ensuring high availability.

  6. 6. A global company needs to monitor its Azure environment for security threats, collect security logs from various sources (e.g., Azure Activity Logs, Azure AD, firewalls), and use security orchestration, automation, and response (SOAR) capabilities to automatically handle incidents. Which Azure service provides these comprehensive SIEM and SOAR capabilities?

    Describe Azure management and governance

    • A. Microsoft Sentinel
    • B. Azure Security Center
    • C. Azure Monitor
    • D. Azure Log Analytics
    Show answer

    A. Microsoft Sentinel

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It provides capabilities for security analytics, threat intelligence, and automated response across an enterprise's digital estate, including Azure resources.

  7. 7. A startup is rapidly expanding its Azure footprint. They want to avoid unexpected high costs and need to be alerted when their monthly spending for a specific subscription approaches a predefined limit. Which feature within Azure Cost Management + Billing should they configure?

    Describe Azure management and governance

    • A. Cost analysis reports
    • B. Budgets
    • C. Reservations
    • D. Cost optimization recommendations
    Show answer

    B. Budgets

    Azure Budgets allow you to set spending limits for subscriptions or resource groups and trigger alerts when those limits are approached or exceeded. This directly addresses the need to be alerted about monthly spending nearing a predefined limit.

  8. 8. A startup is rapidly expanding its Azure footprint and is concerned about unexpected costs. They want to receive automatic notifications when their monthly Azure spending approaches a predefined limit for their subscription. Which Azure Cost Management + Billing feature should they configure?

    Describe Azure management and governance

    • A. Budgets
    • B. Azure Reservations
    • C. Azure Advisor cost recommendations
    • D. Cost analysis reports
    Show answer

    A. Budgets

    Azure Budgets allow you to set spending thresholds for your Azure subscriptions or resource groups. When actual or forecasted spending exceeds these thresholds, you can configure alerts to be triggered, helping to manage and control costs effectively.

  9. 9. A global e-commerce company uses Azure to host its customer-facing applications. Due to the sensitive nature of customer data and international regulations, they need to continuously monitor their compliance posture against various industry standards and regulatory frameworks, such as PCI DSS and GDPR. Which Azure service is designed to help them assess, track, and improve their compliance with these standards?

    Describe Azure management and governance

    • A. Azure Policy
    • B. Microsoft Purview Compliance Manager
    • C. Azure Active Directory Identity Protection
    • D. Azure Security Center
    Show answer

    B. Microsoft Purview Compliance Manager

    Microsoft Purview Compliance Manager is a workflow-based solution in the Microsoft Purview compliance portal that helps you manage your organization's compliance activities from assessment to reporting. It provides actionable insights to improve your compliance posture.

  10. 10. A large enterprise has hundreds of Azure subscriptions across various departments. They need to apply a consistent set of Azure Policies and Role-Based Access Control (RBAC) assignments uniformly across multiple subscriptions to ensure governance and compliance. Which Azure organizational construct is specifically designed to manage access, policy, and compliance for multiple subscriptions at scale?

    Describe Azure management and governance

    • A. Azure Blueprints
    • B. Azure AD Tenants
    • C. Azure Resource Groups
    • D. Azure Management Groups
    Show answer

    D. Azure Management Groups

    Azure Management Groups provide a level of scope above subscriptions. You can organize subscriptions into management groups, and apply your governance conditions (like policies and RBAC assignments) at the management group level. All subscriptions within that management group automatically inherit these conditions, enabling management at scale.

  11. 11. A multinational corporation has multiple Azure subscriptions for different business units and development environments. They need to apply a consistent set of governance policies and access controls across all these subscriptions, ensuring that new subscriptions automatically inherit these standards. Which Azure feature should they use to achieve this hierarchical governance?

    Describe Azure management and governance

    • A. Azure Policy
    • B. Azure Management Groups
    • C. Azure Blueprints
    • D. Azure Resource Groups
    Show answer

    B. Azure Management Groups

    Azure Management Groups provide a level of scope above subscriptions, allowing you to organize subscriptions into containers and apply governance conditions, such as policies and access control, to all contained subscriptions. Policies applied at a management group level inherit down to all subscriptions and resources.

  12. 12. A financial services company is storing highly sensitive customer data in Azure Blob Storage. They need to ensure that this data is protected against accidental deletion or modification for a specified retention period, even if an attacker gains access and attempts to delete it. Which feature of Azure Blob Storage should they implement?

    Describe Azure management and governance

    • A. Azure Storage Account encryption
    • B. Azure Key Vault integration
    • C. Azure Policy for resource locks
    • D. Immutable storage for Blob Storage
    Show answer

    D. Immutable storage for Blob Storage

    Immutable storage for Azure Blob Storage allows you to store business-critical data in a WORM (Write Once, Read Many) state. This means that once data is written, it cannot be modified or deleted for a user-specified interval, providing strong data protection.

  13. 13. A global manufacturing company uses Azure IoT Hub to collect telemetry data from thousands of devices. They need to monitor the health and performance of their IoT solution, visualize data, and set up alerts for anomalies. Which Azure service provides a comprehensive solution for collecting, analyzing, and acting on telemetry data from various sources, including IoT devices?

    Describe Azure management and governance

    • A. Azure Data Explorer
    • B. Azure Log Analytics
    • C. Azure Stream Analytics
    • D. Azure Monitor
    Show answer

    D. Azure Monitor

    Azure Monitor is a comprehensive solution for collecting, analyzing, and acting on telemetry from your cloud and on-premises environments. It can ingest data from IoT Hub, visualize metrics, and trigger alerts.

  14. 14. A financial institution is implementing a strict data residency policy, requiring that all customer data for a specific region must physically reside within that region and never leave its geographical boundaries, even for replication or backup. Which Azure concept directly supports this requirement by allowing customers to choose where their data is stored and processed?

    Describe Azure management and governance

    • A. Azure Availability Zones
    • B. Azure Management Groups
    • C. Azure Regions
    • D. Azure Resource Groups
    Show answer

    C. Azure Regions

    Azure regions are geographical areas that contain one or more datacenters. When you deploy resources, you choose the region, and this choice dictates where your data physically resides, directly addressing data residency requirements. This is a fundamental concept for meeting regulatory and compliance needs.

  15. 15. A startup is rapidly expanding its Azure footprint. They want to avoid unexpected high costs and need to be notified when their monthly Azure spending approaches a predefined limit. They also want to automatically trigger actions, such as shutting down non-critical development environments, if the budget is exceeded. Which Azure cost management feature should they implement?

    Describe Azure management and governance

    • A. Azure Reservations
    • B. Azure Cost Management + Billing exports
    • C. Azure Advisor cost recommendations
    • D. Azure Budgets
    Show answer

    D. Azure Budgets

    Azure Budgets allow you to set spending thresholds and receive alerts when costs exceed or are projected to exceed the defined amount. Crucially, they can also be configured to trigger action groups, enabling automated responses like shutting down resources when a budget threshold is met, directly addressing the startup's needs.

  16. 16. A company is migrating its on-premises virtual machines to Azure. They want to ensure that the Azure VMs consistently use specific naming conventions, tags, and network configurations as defined by their corporate standards. Furthermore, they need to deploy a consistent set of security policies for these VMs. Which Azure governance feature is designed to orchestrate the deployment of multiple Azure resources, including policies and resource templates, in a repeatable manner?

    Describe Azure management and governance

    • A. Azure Resource Graph
    • B. Azure Monitor
    • C. Azure Policy
    • D. Azure Blueprints
    Show answer

    D. Azure Blueprints

    Azure Blueprints allows you to define a repeatable set of Azure resources, policies, and configurations that implement and adhere to an organization's standards, patterns, and requirements. It orchestrates the deployment of various resource templates, policy assignments, and role assignments.

  17. 17. A development team is deploying a new application that processes sensitive customer data. They need to ensure that the data is protected against accidental deletion or corruption, and that they can recover previous versions of the data if necessary. Which Azure data protection strategy should they implement for their Azure storage accounts?

    Describe Azure management and governance

    • A. Azure Firewall rules
    • B. Azure DDoS Protection
    • C. Soft delete and versioning for Blob Storage
    • D. Azure Active Directory authentication
    Show answer

    C. Soft delete and versioning for Blob Storage

    Soft delete for Azure Blob Storage allows you to recover accidentally deleted data or overwritten blobs, while blob versioning automatically maintains previous versions of a blob. These features directly address the need to protect against accidental deletion/corruption and recover previous data versions.

  18. 18. A software development company uses Azure DevOps for its CI/CD pipelines. They want to ensure that all virtual machines deployed by these pipelines automatically have specific monitoring agents installed and are tagged correctly for cost allocation. Which Azure governance feature can help automate the deployment of these configurations consistently?

    Describe Azure management and governance

    • A. Azure Security Center
    • B. Azure Advisor
    • C. Azure Blueprints
    • D. Azure Resource Locks
    Show answer

    C. Azure Blueprints

    Azure Blueprints allow you to define a repeatable set of Azure resources, along with policies, role assignments, and resource groups, that can be consistently deployed. This is ideal for ensuring new VMs automatically include specific extensions (like monitoring agents) and tags.

  19. 19. A financial services company needs to ensure that all sensitive customer data stored in Azure Blob Storage is immutable, meaning it cannot be modified or deleted for a specific retention period, even by administrators. This is a regulatory requirement to prevent data tampering. Which Azure Storage feature should they use?

    Describe Azure management and governance

    • A. Immutable storage for Azure Blob Storage
    • B. Blob soft delete
    • C. Azure Disk Encryption
    • D. Versioning for blobs
    Show answer

    A. Immutable storage for Azure Blob Storage

    Immutable storage for Azure Blob Storage allows users to store business-critical data in a WORM (Write Once, Read Many) state. This means that data cannot be modified or deleted for a user-specified interval, fulfilling regulatory requirements for data retention and tamper-proofing, even from privileged accounts.

  20. 20. A company is migrating its on-premises virtual machines to Azure. They want to ensure that all deployed VMs, networks, and other resources consistently adhere to a predefined set of organizational standards and regulatory compliance requirements from the moment they are provisioned. Which Azure governance feature should they use to automate this consistent deployment?

    Describe Azure management and governance

    • A. Azure Resource Groups
    • B. Azure Management Groups
    • C. Azure Tags
    • D. Azure Blueprints
    Show answer

    D. Azure Blueprints

    Azure Blueprints allow you to define a repeatable set of Azure resources that implement and adhere to an organization's standards, patterns, and requirements. It orchestrates the deployment of various resource templates, policies, and role assignments to ensure consistency and compliance from the start.

  21. 21. A manufacturing company uses Azure IoT Hub to collect telemetry data from thousands of devices. They need to process this data in real-time, detect anomalies, and trigger alerts if certain thresholds are exceeded. This requires a solution that can ingest high volumes of data, perform complex analytics, and integrate with alerting systems. Which Azure service should they primarily use for processing and analyzing this real-time data?

    Describe Azure management and governance

    • A. Azure Stream Analytics
    • B. Azure SQL Database
    • C. Azure Data Lake Storage
    • D. Azure Data Factory
    Show answer

    A. Azure Stream Analytics

    Azure Stream Analytics is a real-time analytics service designed for processing large streams of data from various sources, including IoT Hub. It can perform complex event processing, detect anomalies, and trigger alerts, making it ideal for the company's requirements.

  22. 22. An e-commerce company is experiencing a significant increase in malicious login attempts and potential data breaches. They need a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution to collect security data from various Azure services and on-premises resources, analyze threats, and automate responses. Which Azure service should they implement?

    Describe Azure management and governance

    • A. Microsoft Sentinel
    • B. Azure DDoS Protection
    • C. Azure Security Center (now Defender for Cloud)
    • D. Azure Monitor
    Show answer

    A. Microsoft Sentinel

    Microsoft Sentinel is Azure's cloud-native SIEM and SOAR solution. It provides capabilities for collecting security data from diverse sources, intelligent threat detection, threat investigation, and automated responses to security incidents, directly addressing the company's need for a comprehensive security operations platform.

  23. 23. A financial services company is storing highly sensitive customer data in Azure Blob Storage. Due to strict regulatory requirements, they need to ensure that this data is encrypted both at rest and in transit. They also require auditing of all access to this data. Which combination of Azure services would best meet these requirements?

    Describe Azure management and governance

    • A. Azure Security Center for vulnerability assessments, Azure Firewall for network protection, and Azure AD Identity Protection for user authentication.
    • B. Azure Policy for compliance enforcement, Azure Monitor for activity logging, and Azure Advisor for security recommendations.
    • C. Azure Key Vault for encryption keys, Azure Storage Service Encryption for data at rest, and HTTPS for data in transit.
    • D. Azure Sentinel for threat detection, Azure DDoS Protection for network attacks, and Azure Information Protection for data classification.
    Show answer

    C. Azure Key Vault for encryption keys, Azure Storage Service Encryption for data at rest, and HTTPS for data in transit.

    Azure Key Vault helps manage encryption keys. Azure Storage Service Encryption encrypts data at rest automatically for Blob Storage. HTTPS (TLS) ensures data is encrypted while in transit between the client and Azure services.

  24. 24. A media company uses Azure Blob Storage to store large video files. They want to prevent accidental deletion or modification of critical files by users or applications, including changes to resource properties or tags. Which Azure feature should they implement to protect these resources from unintended changes?

    Describe Azure management and governance

    • A. Azure Backup
    • B. Azure Resource Locks
    • C. Azure Policy
    • D. Azure Role-Based Access Control (RBAC)
    Show answer

    B. Azure Resource Locks

    Azure Resource Locks prevent users from accidentally deleting or modifying critical resources, including resource properties and tags. They can be applied at various scopes, such as a subscription, resource group, or individual resource.

  25. 25. A global software vendor is using Azure to host their SaaS application. Their customers are located worldwide, and the vendor wants to ensure that data for each customer segment is stored in the Azure region closest to them to minimize latency and comply with local data residency regulations. Which Azure concept is fundamental to achieving this goal?

    Describe Azure management and governance

    • A. Azure Regions
    • B. Azure Resource Groups
    • C. Azure Geographies
    • D. Azure Availability Zones
    Show answer

    A. Azure Regions

    Azure Regions are specific geographical locations where Azure data centers are housed. Deploying resources to regions closest to users minimizes latency and helps meet data residency requirements.

Microsoft Azure Fundamentals (AZ-900) flashcards

Tap a card to flip it. 99 flashcards in the full deck.

  • Azure Regions

    Flip card

    Geographical areas around the world that contain one or more Azure datacenters. They provide flexibility for deploying applications closer to users and meeting data residency requirements.

    • Each region consists of multiple datacenters.
    • Allows for data residency control.
    • Offers regional redundancy and disaster recovery options.
    Study this card →
  • Azure Pricing Calculator

    Flip card

    A web-based tool that provides estimated costs for Azure products and services based on user-defined configurations.

    • Helps estimate costs before deployment.
    • Allows configuration of various services.
    • Provides a monthly cost projection.
    Study this card →
  • Azure Management Groups

    Flip card

    A container for subscriptions that allows for hierarchical organization and the application of governance policies, access controls, and compliance standards at scale.

    • Organizes subscriptions into a hierarchy.
    • Enables governance at scale.
    • Supports applying policies and access control.
    Study this card →
  • Azure Advisor

    Flip card

    A free service that provides personalized recommendations to help you optimize your Azure deployments across five pillars: cost, security, reliability, operational excellence, and performance.

    • Analyzes resource configuration and usage.
    • Provides actionable recommendations.
    • Covers cost, security, reliability, performance, and operational excellence.
    Study this card →
  • Azure Monitor

    Flip card

    A comprehensive monitoring solution for applications, infrastructure, and network resources in Azure and on-premises, providing data collection, analysis, visualization, and alerting capabilities.

    • Collects metrics and logs from various sources.
    • Includes Application Insights for APM and Log Analytics for centralized logging.
    • Enables proactive alerting and diagnostic troubleshooting.
    Study this card →
  • Microsoft Sentinel (SIEM/SOAR)

    Flip card

    A cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across an enterprise.

    • Cloud-native SIEM and SOAR.
    • Collects security data from many sources.
    • Detects, investigates, and responds to threats.
    Study this card →
  • Azure Budgets

    Flip card

    A feature within Azure Cost Management + Billing that allows users to set spending thresholds and receive alerts when actual or forecasted costs exceed those thresholds.

    • Monitors spending against a defined limit.
    • Generates alerts for thresholds.
    • Can be set at subscription or resource group scope.
    Study this card →
  • Microsoft Purview Compliance Manager

    Flip card

    A service that helps organizations manage compliance with various regulatory standards and internal policies by providing risk assessments, actionable recommendations, and a compliance score.

    • Unified compliance management
    • Supports various regulations (GDPR, PCI DSS)
    • Provides compliance score and actionable insights
    Study this card →
  • Immutable Storage

    Flip card

    A feature of Azure Blob Storage that stores data in a Write Once, Read Many (WORM) state, meaning it cannot be modified or deleted for a specified retention period.

    • WORM (Write Once, Read Many) state
    • Protects against accidental deletion/modification
    • Supports time-based retention and legal hold
    Study this card →
  • Azure Region

    Flip card

    A set of datacenters deployed within a latency-defined perimeter and connected to a dedicated, regional low-latency network. It directly supports data residency.

    • Geographical area for Azure datacenters.
    • Choice determines data residency.
    • Provides proximity for low-latency access.
    Study this card →
  • Azure Blueprints

    Flip card

    A service that enables you to define a repeatable set of Azure resources, policies, and configurations that implement and adhere to an organization's standards and requirements.

    • Orchestrates deployment of compliant environments.
    • Combines resource templates, policy assignments, and role assignments.
    • Ensures consistency and compliance at scale.
    Study this card →
  • Azure Blob Storage Soft Delete & Versioning

    Flip card

    Features for Azure Blob Storage that protect data against accidental deletion or modification. Soft delete allows recovery of deleted blobs, and versioning maintains previous states of a blob.

    • Soft delete: Recovers deleted blobs for a retention period.
    • Versioning: Automatically saves previous versions of a blob.
    • Crucial for data protection and recovery from human error.
    Study this card →
  • Immutable Storage for Azure Blob Storage

    Flip card

    A feature that allows data to be stored in a Write Once, Read Many (WORM) state, preventing modification or deletion for a configurable retention period, even by administrators.

    • Ensures data integrity and tamper-proofing.
    • Supports time-based retention and legal hold.
    • Meets regulatory compliance requirements (e.g., FINRA, SEC 17a-4).
    Study this card →
  • Azure Stream Analytics

    Flip card

    A real-time analytics service that is designed for processing large streams of data from various sources.

    • Processes high volumes of streaming data with low latency.
    • Supports complex event processing (CEP) and anomaly detection.
    • Integrates with various input (e.g., IoT Hub) and output (e.g., Power BI, Azure Functions) sinks.
    Study this card →
  • Data Encryption in Azure Storage

    Flip card

    Azure provides multiple layers of encryption for data at rest and in transit to protect sensitive information stored within its services.

    • Data at rest is encrypted by default using Azure Storage Service Encryption.
    • Data in transit is protected using HTTPS/TLS.
    • Customer-managed keys can be used with Azure Key Vault for greater control over encryption keys.
    Study this card →
  • Azure Resource Locks

    Flip card

    Azure Resource Locks prevent accidental deletion or modification of Azure resources. They can be applied at the subscription, resource group, or individual resource level.

    • Supported lock types: CanNotDelete and ReadOnly.
    • Overrides RBAC permissions for protection.
    • Applied to critical resources or environments.
    Study this card →
  • Azure Cost Management + Billing

    Flip card

    A suite of tools that helps you analyze, manage, and optimize your cloud costs, including creating budgets and setting up alerts.

    • Provides cost analysis and reporting.
    • Allows setting up budgets and alerts.
    • Helps manage and optimize cloud spending.
    Study this card →
  • Azure Monitor Logs (Log Analytics)

    Flip card

    A feature of Azure Monitor that collects and aggregates log data from various sources into a central Log Analytics workspace, enabling powerful querying and analysis.

    • Centralizes logs and metrics from diverse Azure resources.
    • Uses Kusto Query Language (KQL) for powerful data analysis.
    • Supports custom dashboards and alerts.
    Study this card →
  • Azure Policy

    Flip card

    A service in Azure that helps enforce organizational standards and assess compliance at scale by defining rules for resource configurations.

    • Enforces standards and compliance.
    • Evaluates resource configurations.
    • Can restrict resource deployment locations.
    Study this card →
  • Azure Policy for Enforcement

    Flip card

    A service that enforces organizational standards and assesses compliance at scale. It can audit, deny, or modify resource deployments to ensure they meet predefined security configurations and other rules.

    • Enforces rules on resource properties and configuration.
    • Can prevent non-compliant deployments (Deny effect).
    • Integrates with CI/CD for automated governance.
    Study this card →
  • Azure Cost Management + Billing Budgets

    Flip card

    A feature within Azure Cost Management + Billing that allows users to create budgets to track spending against a specific financial threshold and receive alerts when costs exceed predefined percentages of the budget.

    • Proactively manages costs by setting spending limits.
    • Generates alerts when spending approaches or exceeds the budget.
    • Can be set for subscriptions, resource groups, or management groups.
    Study this card →
  • Azure Log Analytics

    Flip card

    A service within Azure Monitor that collects, indexes, and stores log data from various Azure resources for advanced querying, analysis, and alerting.

    • Collects logs from many sources.
    • Supports Kusto Query Language (KQL).
    • Centralizes operational and diagnostic logs.
    Study this card →
  • Azure Sentinel

    Flip card

    A scalable, cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.

    • Collects security data from multiple sources.
    • Uses AI and machine learning for advanced threat detection.
    • Enables automated responses (SOAR) to security incidents.
    Study this card →
  • Microsoft Sentinel

    Flip card

    A scalable, cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.

    • Collects security data across your organization.
    • Detects threats using analytics and threat intelligence.
    • Investigates threats with AI and automates responses.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.