AZ-900 Flashcards

1
Q

What is the Azure Resource Manager?

A

A manager layer that is able to create, update, and delete resources accepting requests from Azure resources or APIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Azure Service Health?

A

Helps keep track of Azure resources by offering Azure status, Service Health, and Resource Health
- provides RCA reports after an outage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Service Health?

A

A service that provides information about services and regions you are using
- notifies of Azure related service issues
- contains information about planned outages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Resource Health

A

A service that provides a view of your individual resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are factors that affect costs in Azure?

A
  • resource type
  • consumption
  • maintenance
  • geography
  • subscription type
  • Azure marketplace
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Application Insights?

A

A service that monitors web applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the SLA of a VM

A

99.9%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the SLA of a VM Availability scale set?

A

99.95%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the SLA of an Availability Zone

A

99.99%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the SLA of geo-redundant storage

A

99.99…99% (sixteen 9s)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Azure virtual networking?

A

A service that enables VMs, web apps, and DBs to communicate with each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Azure ExpressRoute?

A

A service that provides private connectivity that is not over the internet
- can extend on-prem network into the cloud over a private connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a Network Security Group?

A

A service that provides inbound and outbound security rules to filter traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Locally Redundant Storage (LRS)?

A

replicates data 3x within a single availability zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Zone Redundant Storage (ZRS)?

A

replicates data across 3 availability zones in a primary region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Geo-Redundant Storage?

A

replicates data 3x in a single availability zone in primary region (LRS) AND replicates data 3x in a single availability zone in secondary region (LRS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is Geo-Zone-Redundant Storage?

A

replicates data across 3 availability zones in a primary region (ZRS) AND replicates data 3x in a single availability zone in secondary region (LRS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the dependent resources a VM must have?

A
  • Azure Virtual Network
  • NIC card
  • OS disks
  • resource group
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Up to how many levels can management groups support?

A

6 levels of depth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Does Azure Cloud Shell provide a way to run Azure CLI and Azure PowerShell on IOS and Android devices?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

When a resource group is deleted, are the resources deleted?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What resource is required to use Azure Cloud Shell?

A

Azure storage account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What are characteristics of Azure DNS?

A
  • Uses anycast networking
  • You cannot buy the domain in Azure DNS
  • supports private DNS domains
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is Microsoft Entra External ID

A

refers to all the ways you can securely interact with users outside of your organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
What are User Defined Routes
allows you to control the routing tables between subnets within a virtual network or between virtual networks
26
Business to business (B2B) collaboration
Collaborate with external users by letting them use their preferred identity to sign-in to your Microsoft applications or other enterprise applications, guest users in AD
27
B2B direct connect
Establish a mutual, two-way trust with another Microsoft Entra organization for seamless collaboration
28
Microsoft Entra business to customer (B2C)
Publish modern SaaS apps or custom-developed apps (excluding Microsoft apps) to consumers and customers
29
What are the benefits of Azure Virtual Networking?
- isolation and separation - internet communications - communicate between Azure resources - communicate with on-prem resources - route network traffic - filter network traffic - connect virtual networks
30
virtual private network
uses encrypted tunnel within another network
31
VPN gateway
deployed in a dedicated subnet of the virtual network to enable connection to: - on-prem to virtual networks - individual devices to virtual network - virtual network to another
32
What are the types of VPN
policy based and route based
33
policy based VPN
specify statically the IP address of packets that should be encrypted
34
route based VPN
decides which tunnel interface to use when sending each packet
35
Is the archive access tier set at the storage account level?
No, it needs to be set at the blob level
36
Does Azure Advisor give security recommendations to Azure AD?
No
37
Microsoft Defender for Identity
helps secure your identity monitoring across your organization
38
Microsoft Entra Connect
on-premises Microsoft application that's designed to meet and accomplish your hybrid identity goals
39
Azure File Sync
enables centralizing your organization's file shares in Azure Files, while keeping the flexibility, performance, and compatibility of a Windows file server
40
Virtual network peering
enables you to seamlessly connect two or more Virtual Networks in Azure
41
Site-to-Site VPN Connection
used to connect your on-premises network to an Azure virtual network over an IPsec/IKE (IKEv1 or IKEv2) VPN tunnel
42
point-to-site connection
connect individual devices to virtual network
43
RBAC Contributor role
all access to manage resources, cannot assign roles
44
RBAC Reader role
read only access to resources
45
RBAC Owner role
all access to manage resources and ability to assign roles
46
RBAC VM Contributor role
manage VM, cannot access them
47
elasticity vs. scalability
elasticity: dynamic adjust to meet demand fluctuations scalability: expand capacity to meet growing demands
48
What is the minimum amount of availability zones a region must have if it is zone enabled?
3
49
How many regions does a region pair have?
1
50
Do all Azure regions have a pair?
Yes
51
Is a resource group required when creating a resource?
Yes
52
What are the use cases for VMs?
- testing/development - running apps in cloud - extend datacenter to cloud during disaster recovery
53
Iaas use cases
- lift and shift - testing/development
54
PaaS use cases
- development framework - analytics/business intelligence
55
SaaS use cases
- email/messaging - business productivity apps - finance and expense tracking
56
What are container instances?
Portable environment for virtualized applications
57
Which services allow for even distribution of traffic across multiple servers?
Azure Application Gateway, Azure Load Balancer
58
In a SaaS solution, what are you responsible for?
Configuring the solution
59
Do resources inherit tags from subscriptions and resource groups?
No
60
Are Azure policies inherited?
Yes
61
What is the storage space amount for basic service tier?
10GB
62
Azure IoT Hub
Enable highly secure and reliable communication between your Internet of Things (IoT) application and the devices it manages
63
Azure data lake
a scalable data storage and analytics service
64
Azure Synapse Analytics
a limitless analytics service that brings together enterprise data warehousing and Big Data analytics
65
What is the structure of Azure Cosmos DB?
NoSQL, items are stored as JSON
66
If Microsoft plans to end support for a service, they will provide a notification __________ before
12 months
67
Azure AD Identity Protection
calculates a risk score based on previous logon behavior by the user
68
Microsoft Entra Privileged Identity Management
a service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization
69
Azure AD Connect Health
monitors your on-premises identity infrastructure in real time
70
Trust Center
used to show Azure's compliance
71
Azure Logic App
create and run automated workflows with little to no code
72
Azure Queue
storing large number of messages
73
Azure disks
block level storage volumes
74
How is the data accessed from archive tiers of storage accounts?
must be rehydrated before the data can be accessed
75
Can you create group policies in AD?
No
76
Azure DevTest Labs
helps developers and testers quickly create and delete environments to deploy and test
77
Can an Azure subscription only be managed using a Microsoft Account?
No
78
Does Azure AD let you set dynamic membership rules?
Yes
79
Hot tier
data that is accessed or modified frequently
80
Cool tier
storing data that is infrequently accessed or modified ~ 30
81
Archive tier
storing data that is rarely accessed ~ 180
82
DDoS Protection plan
used to protect against DDoS attacks
83
Azure Firewall
provides threat protect for cloud workloads
84
Azure Traffic Manager
DNS load balancing solution
85
Can you create multiple domains for a single Azure AD directory?
False
86
Azure Active Directory Domain Services
part of Microsoft Entra that enables you to use managed domain services
87
Are locks inherited?
Yes
88
Do can multiple locks be applied to a resource?
Yes
89
cold tier
storing data that is infrequently accessed or modified ~ 90
90
What version of storage accounts supports GZRS?
general purpose v2 storage
91
What Azure storage services supports GZRS?
all Azure storage services
92
Is data copied to an Azure storage account automatically backed up to another data center?
No, depends on storage replication option
93
How much data and files can a storage account contain?
limit ~2PB of data
94
Does Windows PowerShell support Bash CLI or Azure CLI?
Both
95
Does every Azure region have multiple data centers?
Yes, an Azure region is made up of data centers
96
Availability zones
areas in a region with a physical separation of ~75 miles and is used to protect your apps and data from datacenter failures
97
regional pairs
tie regions that have a physical separation of at least 300 miles
98
Which performance option (premium or standard) should you choose for low latency scenarios while creating Azure Storage account?
Premium
99
Microsoft Defender for Cloud
streamlines the process for meeting regulatory compliance requirements - monitors Azure resources and on-prem resources
100
For general purpose v2 Azure storage accounts, are you charged for read and write operations?
Yes, the amount of data is stored is also charged
101
Does copying data from on-prem network over VPN generate additional data transfer costs?
No, traffic coming into the cloud is not charged. Traffic out of the cloud is charged
102
VM
provide OS virtualization
103
blob storage
storage service for large objects (video files and bitmaps)
104
What layer is ExpressRoute at in the OSI Layer?
3
105
What are the length of terms for Azure Reserved VMs?
1 and 3 years
106
What is the longest term you can purchase Azure Reserved VM instances?
3 years
107
What resources can be used as a source for a NSG inbound security rule?
IP address, Service Tags, and Application service groups
108
Azure Arc
set of technologies that helps manage cloud environment, specifically by extending Azure compliance and monitoring to hybrid and multi cloud configurations
109
Azure Kubernetes Service (AKS)
manages the lifecycle of containers
110
AzCopy
used to copy blobs or files to or from storage account
111
What levels can policies be set at?
Any
112
Microsoft Purview
family of data governance, risk, and compliance solutions that helps get single view of data
113
What is a use case for a VPN gateway?
connecting an on-premises datacenter to an Azure virtual network
114
VM availability sets?
ensures staggered updates and varied power and network connectivity
115
VM update domain
VMs that update at the same time
116
VM fault domain
VMs with the same power source and network switch
117
Azure CLI
CLI installable on Windows, macOS, Linux - runs in Windows PowerShell, Cmd, Bash, other Unix Shells - commands are like bash
118
Azure PowerShell
PowerShell module installable on Windows, macOS, Linux - runs in Windows PowerShell or PowerShell - commands are verbs