AZ-900 Flashcards

1
Q

What is the Azure Resource Manager?

A

A manager layer that is able to create, update, and delete resources accepting requests from Azure resources or APIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Azure Service Health?

A

Helps keep track of Azure resources by offering Azure status, Service Health, and Resource Health
- provides RCA reports after an outage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Service Health?

A

A service that provides information about services and regions you are using
- notifies of Azure related service issues
- contains information about planned outages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Resource Health

A

A service that provides a view of your individual resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are factors that affect costs in Azure?

A
  • resource type
  • consumption
  • maintenance
  • geography
  • subscription type
  • Azure marketplace
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Application Insights?

A

A service that monitors web applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the SLA of a VM

A

99.9%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the SLA of a VM Availability scale set?

A

99.95%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the SLA of an Availability Zone

A

99.99%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the SLA of geo-redundant storage

A

99.99…99% (sixteen 9s)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Azure virtual networking?

A

A service that enables VMs, web apps, and DBs to communicate with each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Azure ExpressRoute?

A

A service that provides private connectivity that is not over the internet
- can extend on-prem network into the cloud over a private connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a Network Security Group?

A

A service that provides inbound and outbound security rules to filter traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Locally Redundant Storage (LRS)?

A

replicates data 3x within a single availability zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Zone Redundant Storage (ZRS)?

A

replicates data across 3 availability zones in a primary region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Geo-Redundant Storage?

A

replicates data 3x in a single availability zone in primary region (LRS) AND replicates data 3x in a single availability zone in secondary region (LRS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is Geo-Zone-Redundant Storage?

A

replicates data across 3 availability zones in a primary region (ZRS) AND replicates data 3x in a single availability zone in secondary region (LRS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the dependent resources a VM must have?

A
  • Azure Virtual Network
  • NIC card
  • OS disks
  • resource group
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Up to how many levels can management groups support?

A

6 levels of depth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Does Azure Cloud Shell provide a way to run Azure CLI and Azure PowerShell on IOS and Android devices?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

When a resource group is deleted, are the resources deleted?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What resource is required to use Azure Cloud Shell?

A

Azure storage account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What are characteristics of Azure DNS?

A
  • Uses anycast networking
  • You cannot buy the domain in Azure DNS
  • supports private DNS domains
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is Microsoft Entra External ID

A

refers to all the ways you can securely interact with users outside of your organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What are User Defined Routes

A

allows you to control the routing tables between subnets within a virtual network or between virtual networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Business to business (B2B) collaboration

A

Collaborate with external users by letting them use their preferred identity to sign-in to your Microsoft applications or other enterprise applications, guest users in AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

B2B direct connect

A

Establish a mutual, two-way trust with another Microsoft Entra organization for seamless collaboration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Microsoft Entra business to customer (B2C)

A

Publish modern SaaS apps or custom-developed apps (excluding Microsoft apps) to consumers and customers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What are the benefits of Azure Virtual Networking?

A
  • isolation and separation
  • internet communications
  • communicate between Azure resources
  • communicate with on-prem resources
  • route network traffic
  • filter network traffic
  • connect virtual networks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

virtual private network

A

uses encrypted tunnel within another network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

VPN gateway

A

deployed in a dedicated subnet of the virtual network to enable connection to:
- on-prem to virtual networks
- individual devices to virtual network
- virtual network to another

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What are the types of VPN

A

policy based and route based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

policy based VPN

A

specify statically the IP address of packets that should be encrypted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

route based VPN

A

decides which tunnel interface to use when sending each packet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Is the archive access tier set at the storage account level?

A

No, it needs to be set at the blob level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Does Azure Advisor give security recommendations to Azure AD?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Microsoft Defender for Identity

A

helps secure your identity monitoring across your organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Microsoft Entra Connect

A

on-premises Microsoft application that’s designed to meet and accomplish your hybrid identity goals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Azure File Sync

A

enables centralizing your organization’s file shares in Azure Files, while keeping the flexibility, performance, and compatibility of a Windows file server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Virtual network peering

A

enables you to seamlessly connect two or more Virtual Networks in Azure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Site-to-Site VPN Connection

A

used to connect your on-premises network to an Azure virtual network over an IPsec/IKE (IKEv1 or IKEv2) VPN tunnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

point-to-site connection

A

connect individual devices to virtual network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

RBAC Contributor role

A

all access to manage resources, cannot assign roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

RBAC Reader role

A

read only access to resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

RBAC Owner role

A

all access to manage resources and ability to assign roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

RBAC VM Contributor role

A

manage VM, cannot access them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

elasticity vs. scalability

A

elasticity: dynamic adjust to meet demand fluctuations
scalability: expand capacity to meet growing demands

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What is the minimum amount of availability zones a region must have if it is zone enabled?

A

3

49
Q

How many regions does a region pair have?

A

1

50
Q

Do all Azure regions have a pair?

A

Yes

51
Q

Is a resource group required when creating a resource?

A

Yes

52
Q

What are the use cases for VMs?

A
  • testing/development
  • running apps in cloud
  • extend datacenter to cloud during disaster recovery
53
Q

Iaas use cases

A
  • lift and shift
  • testing/development
54
Q

PaaS use cases

A
  • development framework
  • analytics/business intelligence
55
Q

SaaS use cases

A
  • email/messaging
  • business productivity apps
  • finance and expense tracking
56
Q

What are container instances?

A

Portable environment for virtualized applications

57
Q

Which services allow for even distribution of traffic across multiple servers?

A

Azure Application Gateway, Azure Load Balancer

58
Q

In a SaaS solution, what are you responsible for?

A

Configuring the solution

59
Q

Do resources inherit tags from subscriptions and resource groups?

A

No

60
Q

Are Azure policies inherited?

A

Yes

61
Q

What is the storage space amount for basic service tier?

A

10GB

62
Q

Azure IoT Hub

A

Enable highly secure and reliable communication between your Internet of Things (IoT) application and the devices it manages

63
Q

Azure data lake

A

a scalable data storage and analytics service

64
Q

Azure Synapse Analytics

A

a limitless analytics service that brings together enterprise data warehousing and Big Data analytics

65
Q

What is the structure of Azure Cosmos DB?

A

NoSQL, items are stored as JSON

66
Q

If Microsoft plans to end support for a service, they will provide a notification __________ before

A

12 months

67
Q

Azure AD Identity Protection

A

calculates a risk score based on previous logon behavior by the user

68
Q

Microsoft Entra Privileged Identity Management

A

a service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization

69
Q

Azure AD Connect Health

A

monitors your on-premises identity infrastructure in real time

70
Q

Trust Center

A

used to show Azure’s compliance

71
Q

Azure Logic App

A

create and run automated workflows with little to no code

72
Q

Azure Queue

A

storing large number of messages

73
Q

Azure disks

A

block level storage volumes

74
Q

How is the data accessed from archive tiers of storage accounts?

A

must be rehydrated before the data can be accessed

75
Q

Can you create group policies in AD?

A

No

76
Q

Azure DevTest Labs

A

helps developers and testers quickly create and delete environments to deploy and test

77
Q

Can an Azure subscription only be managed using a Microsoft Account?

A

No

78
Q

Does Azure AD let you set dynamic membership rules?

A

Yes

79
Q

Hot tier

A

data that is accessed or modified frequently

80
Q

Cool tier

A

storing data that is infrequently accessed or modified ~ 30

81
Q

Archive tier

A

storing data that is rarely accessed ~ 180

82
Q

DDoS Protection plan

A

used to protect against DDoS attacks

83
Q

Azure Firewall

A

provides threat protect for cloud workloads

84
Q

Azure Traffic Manager

A

DNS load balancing solution

85
Q

Can you create multiple domains for a single Azure AD directory?

A

False

86
Q

Azure Active Directory Domain Services

A

part of Microsoft Entra that enables you to use managed domain services

87
Q

Are locks inherited?

A

Yes

88
Q

Do can multiple locks be applied to a resource?

A

Yes

89
Q

cold tier

A

storing data that is infrequently accessed or modified ~ 90

90
Q

What version of storage accounts supports GZRS?

A

general purpose v2 storage

91
Q

What Azure storage services supports GZRS?

A

all Azure storage services

92
Q

Is data copied to an Azure storage account automatically backed up to another data center?

A

No, depends on storage replication option

93
Q

How much data and files can a storage account contain?

A

limit ~2PB of data

94
Q

Does Windows PowerShell support Bash CLI or Azure CLI?

A

Both

95
Q

Does every Azure region have multiple data centers?

A

Yes, an Azure region is made up of data centers

96
Q

Availability zones

A

areas in a region with a physical separation of ~75 miles and is used to protect your apps and data from datacenter failures

97
Q

regional pairs

A

tie regions that have a physical separation of at least 300 miles

98
Q

Which performance option (premium or standard) should you choose for low latency scenarios while creating Azure Storage account?

A

Premium

99
Q

Microsoft Defender for Cloud

A

streamlines the process for meeting regulatory compliance requirements
- monitors Azure resources and on-prem resources

100
Q

For general purpose v2 Azure storage accounts, are you charged for read and write operations?

A

Yes, the amount of data is stored is also charged

101
Q

Does copying data from on-prem network over VPN generate additional data transfer costs?

A

No, traffic coming into the cloud is not charged. Traffic out of the cloud is charged

102
Q

VM

A

provide OS virtualization

103
Q

blob storage

A

storage service for large objects (video files and bitmaps)

104
Q

What layer is ExpressRoute at in the OSI Layer?

A

3

105
Q

What are the length of terms for Azure Reserved VMs?

A

1 and 3 years

106
Q

What is the longest term you can purchase Azure Reserved VM instances?

A

3 years

107
Q

What resources can be used as a source for a NSG inbound security rule?

A

IP address, Service Tags, and Application service groups

108
Q

Azure Arc

A

set of technologies that helps manage cloud environment, specifically by extending Azure compliance and monitoring to hybrid and multi cloud configurations

109
Q

Azure Kubernetes Service (AKS)

A

manages the lifecycle of containers

110
Q

AzCopy

A

used to copy blobs or files to or from storage account

111
Q

What levels can policies be set at?

A

Any

112
Q

Microsoft Purview

A

family of data governance, risk, and compliance solutions that helps get single view of data

113
Q

What is a use case for a VPN gateway?

A

connecting an on-premises datacenter to an Azure virtual network

114
Q

VM availability sets?

A

ensures staggered updates and varied power and network connectivity

115
Q

VM update domain

A

VMs that update at the same time

116
Q

VM fault domain

A

VMs with the same power source and network switch

117
Q

Azure CLI

A

CLI installable on Windows, macOS, Linux
- runs in Windows PowerShell, Cmd, Bash, other Unix Shells
- commands are like bash

118
Q

Azure PowerShell

A

PowerShell module installable on Windows, macOS, Linux
- runs in Windows PowerShell or PowerShell
- commands are verbs