Azure Cloud Flashcards
Prepare for AZ900 Azure Fundamentals Certification
Which tool is used by Azure Active Directory to provide access to resources based on organizational policies?
A. multi-factor authentication (MFA)
B. single sign-on (SSO)
C. administrative units
D. Conditional Access
D. Conditional Access
Conditional Access is the tool used by Azure Active Directory to allow (or deny) access to resources based on identity signals. Conditional access ia a more refined MFA (multifactor authentication method.
Single Sign On (SSO) is a ______________ method that enables users to sign in the first time and access various applications and resource by using the same password.
A. a validation
B. an authentication
C. a configuration
D. an authorization
B. an authentication.
Single Sign-On is an authentication method that allows users to sign in using one set of credentials to login across applications. Single sign-on makes it easier to manage passwords and increases security capabilities.
Describe the Azure Pricing Calculator Service.
- Estimates workload costs
- Estimates the cost savings by comparing datacenter costs to running the same workload on Azure.
- Helps control, analyze and optimize workload costs.
Pricing Calculator
- Helps you estimate workload costs.
Describe the Azure TCO Calculator Service.
- Estimates workload costs
- Estimates the cost savings by comparing datacenter costs to running the same workload on Azure.
- Helps control, analyze and optimize workload costs.
Total Cost of Ownership.
- Estimates the cost savings by comparing datacenter costs to running the same workload on Azure.
Provided approximate cost savings of operating similar workload on Azure to on premise datacenter.
Describe the Azure Cost Management Service.
- Estimates workload costs
- Estimates the cost savings by comparing datacenter costs to running the same workload on Azure.
- Helps control, analyze and optimize workload costs.
Cost Management
- Helps to control, analyze and optimize workload costs.
Azure Cost Management helps to understand Azure bill, managed account.
____________ is a repeatable set of governance tools that helps development teams quickly build out and create new environments while adhering to organizational compliance to speed up development and deployment.
A. Azure DevOps
B. A Continuous Integration / Continuous Deployment (CI/CD) pipeline configuration.
C. Azure Blueprints
D. Azure Policy
Azure Blueprints
Sometimes cloud environment grows beyond just one subscription. In that case Azure Blueprints help to scale the configuration. Azure Blueprints help with repeatable tasks so that development teams rapidly build and deploy new environments and speed the overall development and deployment phases.
Blueprints are a declarative way to orchestrate the deployment of various resource templates.
Infrastructure as a Service (IAAS) is described as:
- Provides hosting and management of an application and its underlying infrastructure, as well as any maintenance, upgrades and security patching.
- Provides a fully managed environment for developing, testing, delivering and managing cloud based applications.
- Provides servers and virtual machines, storage, networks and operating systems on a pay-as-you-go basis.
- IAAS offers necessary compute, storage and networking assets on demand on a pay-as-you-go basis.
Platform as a Service (PAAS) is described as:
- Provides hosting and management of an application and its underlying infrastructure, as well as any maintenance, upgrades and security patching.
- Provides a fully managed environment for developing, testing, delivering and managing cloud based applications.
- Provides servers and virtual machines, storage, networks and operating systems on a pay-as-you-go basis.
- PAAS provides complete development and deployment environment in the cloud, with assets that enable to deliver simple cloud-based apps to cloud-enabled enterprise applications.
Software as a Service (SAAS) is described as:
- Provides hosting and management of an application and its underlying infrastructure, as well as any maintenance, upgrades and security patching.
- Provides a fully managed environment for developing, testing, delivering and managing cloud based applications.
- Provides servers and virtual machines, storage, networks and operating systems on a pay-as-you-go basis.
- SAAS - Host and manage the software application and underlying infrastructure.
Which cloud approach is used by organizations to take full advantage of on-premise technology investments and allows data and applications to be shared between two environments?
A. public cloud
B. private cloud
C. hybrid cloud
D. on-premise datacenter
C. hybrid cloud
Public clouds, such as MS Azure, owned and operated by third party cloud service providers, to deliver their computing resources such as servers and storage over the internet. Cloud providers manage all hardware, software and other supporting infrastructure.
A Private Cloud refers to cloud computing resources used exclusively by an individual business. A private cloud can be located on the company’s on site datacenter.
A Hybrid Cloud is a type of cloud computing that combines on premise infrastructure or a private cloud with a public cloud. Hybrid clouds allow data and apps to move between the two environments.
_______________ copies data to a secondary region from the primary region across multiple datacenters that are located many miles apart.
A. Read-access geo-redundant storage (RA_GRS)
B. Zone Redundant Storage (ZRS)
C. Geo-Redundant Storage (GRS)
D. Locally Redundant Storage (LRS)
C. Geo-Redundant Storage Replicates your data to a secondary region that is in different geographic locations from the primary region.
What option is used to set the communication between an on premise VPN device and an Azure VPN gateway through an encrypted tunnel over the internet?
A. ExpressRoute
B. Point to Site (P25) VPN
C. Site to Site VPN
C. Site to Site VPN. Established between on premise VPN device and an Azure VPN Gateway that is deployed in a virtual network. This connection type allows communication between any on premise authorize resource to access a virtual network through an encrypted tunnel.
____________ enables the secure communication of messages between millions of IOT devices and a cloud based solution.
A. Azure IoT Hub
B. Azure Digital Twins
C. Azure IoT Edge
D. Azure IoT Central
A. Azure IoT Hub
The Azure IoT Hub service enables reliable two way message communications between IoT devices and a cloud based solution. These capabilities enable customers to provision millions of devices in a secure and scalable manner.
Which Azure service protects against attacks in which an attacker sends multiple requests to a web resource to exceed a website’s capacity and prevent the web resource from functioning correctly?
A. Azure Defender
B. Azure DDOS Protection
C. Azure Sentinel
D. Azure Firewall
B. DDOS Protection
Distributed denial of service, or DDOS, is a type of attack where an attacker sends multiple requests to an application. This results into the resources becoming exhausted, impacting the application’s availability. DDOS attacks can be targeted at any endpoint that is publicly reachable through the internet.
What serverless computing technology provides the ability to execute workflows to automate business scenarios by using triggers without writing any code?
A. Azure Functions
B. Azure Logic Apps
C. Azure Front Door
D. Azure DevOps
B. Azure Logic Apps
Logic Apps are designed in a web based designer and can execute logic triggered by Azure services without writing any code.
A team is developing a new cloud based application that leverages the Gremlin API. Which Azure database option is the most suitable for the new application?
A. Azure Cosmos DB
B. Azure SQL Managed Instance
C. Azure Database for PostgreSQL
D. Azure Database for MySQL
A. Azure Cosmos DB
Azure Cosmos DB is the best colution. It supports Gremlin API as well as SQL, Cassandra, MongoDB and Tables.
_____________ enables you to scale to thousands of virtual machines for high performance computing and large scale parallel jobs.
A. An Azure virtual machine scale set
B. An availability set
C. Azure Batch
D. An availability zone
C. Azure Batch
Azure Batch allows you to scale to thousands of virtual machines for high performance computing (HPC) and large scale parallel jobs. Other functionalities allow you to scale multiple VMs but only Azure Batch will allow for thousands of VMs for HPC.
Azure IoT Central is described as:
- Used to quickly create a web based dashboard to enable reporting and communication with IoT devices.
- Used to communicate to IoT devices by sending and receiving messages.
- Used to provide the highest degree of security to ensure that the device was not tempered with.
- Azure IoT Central
To quickly create a web based dashboard to enable reporting and communication with IoT devices.
Azure IoT Hub is described as:
- Used to quickly create a web based dashboard to enable reporting and communication with IoT devices.
- Used to communicate to IoT devices by sending and receiving messages.
- Used to provide the highest degree of security to ensure that the device was not tempered with.
- Azure IoT Hub
To communicate with IoT devices by sending and receiving messages.
Azure Sphere is described as:
- Used to quickly create a web based dashboard to enable reporting and communication with IoT devices.
- Used to communicate to IoT devices by sending and receiving messages.
- Used to provide the highest degree of security to ensure that the device was not tempered with.
- Azure Sphere
Used to provide the highest degree of security to ensure that the device was not tempered with.
____________ enables you to provision a group of matching and load balanced virtual machines in Azure.
A. Azure Logic Apps
B. An Availability set
C. An Azure virtual machine scale set
D. Azure Load Balancer
C. Azure virtual machine scale set
Enables you to provision a group of matching and load balanced virtual machines in Azure.
Azure Machine Learning is described as:
- Used to predict future results by using historical data and training models.
- Used to implement a virtual agent that can respond to human inquiries by using natural language.
- Used to identify content based on images.
- Azure Machine Learning
To predict future results by using historical data and training models.
Azure machine learning allows you to connect to data to train and test models to find one that will most accurately predict a future result.
Azure bot Service is described as:
- Used to predict future results by using historical data and training models.
- Used to implement a virtual agent that can respond to human inquiries by using natural language.
- Used to identify content based on images.
- Azure bot Service
To implement a virtual agent that can respond to human inquiries by using natural language.
Azure bot service allows you to create a virtual agent solution that uses natural language to respond to customer inquiries.
Azure Cognitive Services are described as:
- Used to predict future results by using historical data and training models.
- Used to implement a virtual agent that can respond to human inquiries by using natural language.
- Used to identify content based on images.
- Azure Cognitive Services
To identify content based on images.
The vision services in Azure Cognitive services add recognition and identification capabilities when you are analyzing pictures and other visual content.
___________ is NOT supported by ExpressRoute for connecting an on premise network to Azure.
A. A Point-to-Site VPN
B. A Point-to-Point Ethernet Connection
C. A Site-to-Site VPN
D. Azure Peering Service
C. A Site-to_Site VPN
The three models that ExpressRoute supports are:
CloudExchange colocation
Point-to-Point Ethernet Connection
Any-to-Any Connection
Which Azure feature enables you to organize multiple subscriptions into hierarchies for unified policies and compliance?
A. Resource Groups
B. Management Groups
C. Azure Active Directory (Azure AD)
D. Azure Container Instances
B. Management Groups
Management Groups help you manage access, policy and compliance for multiple subscriptions. All subscriptions in a management group automatically inherit the conditions applied to the management group.
Alerts you when service issues occur in an Azure environment, such as a regional Azure outage that affects all Azure customers.
A. Azure Monitor
B. Azure Advisor
C. Azure Service Health
D. Azure Application Insights
C. Azure Service Health
Azure Service Health alerts you about service issues that happen in Azure itself such as a regional Azure outage.
Authorization is described as:
- Confirms the identity of a person who wants access.
- Grants the proper access to a legitimate user.
- Grants the proper access to a legitimate user.
Authorization is the process of understanding what level of access a legitimate user or service should have.
Authentication is described as:
- Confirms the identity of a person who wants access.
- Grants the proper access to a legitimate user.
- Confirms the identity of a person who wants access.
Authentication is the process of establishing the identity of a person or service that wants access to a resource.
Which of the following statements is NOT tue about Cloud Computing?
- All cloud computing resources are usually limited to specific geographic regions.
- IAAS, PAAS, SAAS are examples of cloud computing service models.
- IAAS, PAAS, SAAS are common cloud computing service models and are respectively infrastructure as a service, platform as a service and software as a service.
- All cloud computing resources are usually limited to specific geographic regions.
Most cloud computing resources can be distributed to global datacenters.
True or False. You need to purchase an Azure Account before you can use any Azure resources.
False. You can use a free account or a Microsoft Learn Sandbox to create resources.
True or False. In an IAAS environment, the cloud tenant is responsible for routine hardware maintenance.
False. In a IAAS environment the cloud provider is responsible for any hardware maintenance.
Which of the following is NOT a cloud computing category?
- Platform as a Service (PAAS)
- Networking as a Service (NAAS)
- Infrastructure as a Service (IAAS)
- Software as a Service (SAAS)
- Networking as a Service (NAAS) is not a cloud computing category.
Which of the following options is NOT a type cloud computing?
- Hybrid Cloud
- Private Cloud
- Public Cloud
- Distributed Cloud
- Distributed Cloud is not a valid type of cloud computing.
Which of the following choices is NOT a benefit of using cloud services?
- Scalability
- Disaster Recovery
- Geographic Isolation
- High Availability
- Geographic Isolation. You can choose to create resources in a single region; however, one of the primary advantages to cloud computing is geographic distribution.
Which of the following is a logical unit of Azure services that links to an Azure account?
- Management Group
- Resource Group
- Azure Subscription
- Azure Subscription is a logical unit of Azure services that links to an Azure account.
Which of the following statements is True?
- With Operating Expenses (OpEx), you are only responsible for the computing resources that you use.
- With Operating Expenses (OpEx), you are responsible for purchasing and maintaining your computing resources.
- With Capital Expenses (CapEx), you are only responsible for the computing resources that you use.
- With Operating Expenses (OpEx), you are only responsible for the computing resources that you use.
What is meant by LAMP Stack?
One of the oldest and most utilized software development methods, the LAMP stack allows web developers to build, deploy, and manage web applications. LAMP is an acronym that stands for Linux, Apache, MySQL, and PHP, and provides the components needed to host and manage web content
Tailwind Traders uses the LAMP Stack for several of its websites. Which option would be ideal for migration?
- Azure Database for MySQL?
- Azure Cosmos DB
- Azure SQL Database
- Azure Database for PostgreSQL
- Azure Database for MySQL?
Azure Database for MySQL is the logical choice for existing LAMP stack applications.
Which Azure compute resource can be deployed to manage a set of identical virtual machines?
- Virtual machine availability sets
- Virtual machine scale sets
- Virtual machine availability zones.
- Virtual machine scale sets lets you deploy and manage a set of identical virtual machines.
Which of the following services should be used when the primary concern is to perform work in response to an event (often vis a REST command) that needs a response in a few seconds?
- Azure Functions
- Azure App Service
- Azure Container Instances
- Azure Functions is used when you need to perform work in response to an event (often via a REST request), timer, or message from another Azure service, and when that work can be completed quickly, within seconds or less.
Your company has a team of remote workers that need to use Windows based software to develop your company’s applications, but your team members are using various operating systems like MacOS, Linux and Windows. Which Azure compute service would help resolve this scenario?
- Azure App Service
- Windows Virtual Desktop
- Azure Container Instance
- Windows Virtual Desktop enables your team members to run Windows in the cloud, with access to the required applications for your company’s needs.
What is the first step you would take in order to share an image file as a blob in Azure Storage?
- Create an Azure Storage Container to store the image.
- Upload the image file and create a container
- Use a Shared Access Signature (SAS) token to restrict access to the image.
- Create an Azure Storage account.
- Create an Azure Storage account.
You must create an Azure Storage account before you can use any Azure Storage features.
Which Azure Storage option is better for storing data for backup and restore, disaster recovery and archiving?
- Azure Blob storage
- Azure Files storage
- Azure Disk Storage
- Azure Blob storage is your best option for for storing disaster recovery files and archives.
Tailwind Traders wants to create a secure communication tunnel between its branch offices. Which of the following technologies CANNOT be used?
- Point-to-Site virtual private network
- Implicit FTP over SSL
- Azure ExpressRoute
- Site-to-Site virtual private network
- Implicit FTP over SSL CANNOT be used to create a secure communication tunnel
Tailwinds Traders wants to use Azure ExpressRoute to connect to its on premise network to the Microsoft Cloud. Which of the following choices isn’t an ExpressRoute model that Tailwind Traders can use?
- Site-to-Site virtual private network
- Any-to-Any connection
- Point-to-Point Ethernet connection
- CloudExchange colocation
- Site-to-Site virtual private network is NOT an ExpressRoute model.
Which of the following options can you use to link virtual networks?
- Network Address Translation
- Multi-chassis link aggregation
- Dynamic Host Control Protocol
- Virtual Network Peering
- Virtual Network Peering can be used to link virtual networks.
Which of the following is NOT a benefit of ExpressRoute?
- Redundant Connectivity
- Consistent network throughput
- Encrypted network communication
- Access to Microsoft Cloud Services
- Encrypted network communication
ExpressRoute does provide private communications but it is NOT encrypted.
You need to predict future behavior based on previous actions. Which product option should you eliminate as a candidate?
- Azure Machine Learning
- Azure Bot Service
- Azure Cognitive Services
- Azure Bot Service will not help with prediction. It should be eliminated as a candidate.
You need to create a computer-human interface that uses natural language to answer customer questions. Which product option should you eliminate as a candidate?
- Azure Machine Learning
- Azure Cognitive Services
- Azure Bot Service
- Azure Machine Learning
Although Azure Machine Learning could be used to create a natural language model it would likely be cost and time prohibitive. It should be eliminated as a candidate.
You need to identify the content of product images to automatically create alt tags for images formatted properly. Which production option is the best candidate?
- Azure Machine Learning
- Azure Cognitive Services
- Azure Bot Services
- Azure Cognitive Services includes Vision services that can identify the content of an image. Azure Cognitive Services is the best candidate.
Which of the following choices would NOT be used to automate a (CI/CD) process?
- Azure Pipelines
- GitHub Actions
- Azure Boards
- Azure Boards is an Agile project management tool. It would not be used to automate a CI/CD process.
Which service could help you manage the VMs that your developers and testers need to ensure that your new app works across various operating systems?
- Azure DevTest Labs
- Azure Test Labs
- Azure Repos
- Azure DevTest Labs is used to manage VMs for testing, including configuration, provisioning, and automatic deprovisioning.
Which service lacks features to assign individual developers tasks to work on?
- Azure Boards
- GitHub
- Azure Pipelines
- Azure Pipelines is a CI/CD tool for building an automated tool chain. It lacks the features to assign tasks for individual developers to work on. However, it can automate other tools to assign tasks to users.
You want to be alerted when new recommendations to improve your cloud environment are available. Which service will do this?
- Azure Advisor
- Azure Monitor
- Azure Service Health
- Azure Advisor can alert you when new recommendations are available.
Which service provides official outage root cause analyses (RCAs) for Azure incidents?
- Azure Advisor
- Azure Monitor
- Azure Service Health
- Azure Service Health provides incident history and RCAs to share with your stakeholders.
Which service is a platform that powers Application insights, monitoring for VMs. containers and Kubernetes?
- Azure Advisor
- Azure Monitor
- Azure Service Health
- Azure Monitor is the platform used by Application Insights.
As an administrator you need to retrieve the IP address from a particular VM by using Bash. Which of the following tools should you use?
- ARM Templates
- Azure Powershell
- The Azure Portal
- The Azure CLI
- The Azure CLI enables you to use Bash to run one-off tasks on Azure