Azure Fundamentals: Describe Azure Architecture and Services Flashcards
You are required to deploy an app on two VMs. The following is required: High availability access, Separate fault and update zones, Minimal latency between instances.
Choose the best configuration below:
- Separate resource groups in the same region
- Separate availability sets
- Separate availability zones
- Separate regions in a regional pair.
Separate Availability Zones
Where are availability zones deployed ?
In separate data centers in the same region
What are the benefits of availability zones ?
Same region therefor low latency
Separate locations hence separate fault and update zones
What is an availability set ?
Separate deployments in the same data center
How do you lock all resource contained within a resource group ?
Set the lock to read-only
Can a resource group contain resources from a different region ?
Yes
Can resources from one resource group comunicate with another ?
Yes Resource groups are primarily for management purposes
You need to deploy templates based on existing resources across some new additional resources. What should you use ?
Azure Resource manager to automate resource deployments using templates.
What are Resource Groups used for ?
Managing resources as a set.
What is Azure Monitor used for ?
Analyzing and acting on data.
Are Regions always paired with other regions ?
Yes
How may data centers will a region contain
One or more
What specifies the location of resources ?
Regions
What allows you to control the type of resources that can be deployed ?
Azure Policy
When a resource group is deleted, what happens to the resources ?
They are deleted too.
How many subscriptions can an Azure account create ?
Multiple. Billing occurs at the subscription level
If you have three departments that must each receive a bill, how many subscriptions should you create ?
Three. Billing occurs at the subscription level.
Can you transfer an existing subscription to a new Azure AD tenant ?
Yes
How are quotas for resource groups managed ?
By Region
How do you organize multiple subscriptions ?
Management Groups
What is an organizations top level Azure Hierarchy category ?
Azure AD Tenants
What does a Network Security Group do ?
It defines rules that allow or deny inbound/outbound traffic.
What prevents excess, malicious HTTP traffic to Azure resources ?
DDoS Protection
How do you restrict network traffic across subscriptions ?
Use Azure Firewall to create rules.
What does the traffic manager do ?
Uses DNS to direct requests to the appropriate geographical location endpoint.
What is an Application gateway
A load balancer that manages traffic to your web applications.
What remote desktop clients does Azure Virtual Desktop support ?
MacOS, iOS, Windows, Web, Android.
Name two things which you can use to connect Azure Virtual Networks to one another
VPN Gateways and VNet Peering
What is VNet peering ?
The proccess to connect two or more VNets in Azure
What is Azure Front Door ?
A global entry point for customers accessing web apps, APIs, content and cloud services.
In what scope are Vnets created ?
The scope of a region
Can Vnets from different regions be connected ?
Yes via Global Vnet peering
What is a container instance ?
A lightweight, virtualized app enviroment
What are Azure functions ?
A way to run small pieces of code in the cloud
What kind of data transfer does Virtual network peering support ?
Transfer between:
Tenants
Subscriptions
Deployment models
What should you use to provision virtual machines automatically ?
Scale Sets
you need to bring azure storage into you virtual network with a dedicated IP address. Which solution should you use ?
Create a private endpoint (IP address) then connect to the azure storage with an Azure Private link.
Why would file storage be beneficial for network sharing across Azure cloud, windows, linux and mac OS ?
File storage allows access via SMB protocol, REST and native client libraries. This meets the requirements.
Do Azure SQL database and SQL Server (on VM) directly support NoSQL ?
No
Which Azure database product supports key-value, document data models, native supports for NoSQL ?
Azure Cosmos DB
What storage option supports persistent storage for Azure Container Instances ?
Azure Files
What is AzCopy used for ?
A command line tool used to upload and download data to and from Azure Blob storage
Can you use Azure Storage explorer to transfer an on premises virtual hard disk to azure ?
Yes
How does Locally redundant storage replicate data ? DELETE
Writes locally to three disks within one datacenter
How does Azure geo-redundant storage store data ? DELETE
Three copies of your data are written in two regions
Is the archive storage tier available at the account level ?
No
What type of storage incurs a penalty if data is deleted within 30 days ?
Cool
What kind of storage account supports Blob, queue and table storage services ?
Standard general-purpose (v2)
Is Azure DDoS Protection shield enabled automatically ?
No
Does Azure DDoS protection cover multiple subscriptions ?
Yes
What is authentication?
The process of proving that somebody is who they say they are.
What is authorization ?
The process of verifying that an authenticated user has access to certain functions
What license is required to publish on premises web apps ?
Premium
What tier license allows users to reset their own passwords ?
Premium
How does Azure AD support authorization ?
Role Based Access Control
What authentication types are supported by SSPR and MFA ?
Password, SMS, Voice call
What solution provides provisions, manages and deploys public and private SSL/TLS certificates ?
Key Vault stores cryptographic keys.
Is Microsoft defender limited to just Windows OS ?
No. Works with Server 2008 and some Linux distros
What does Microsoft sentinel do ?
Simplifies security operations.
What is Azure dedicated Hosts ?
Isolated servers where you run your organizations workload only.
Define Defense in depth
Implementing multiple layers of security to slow down an attack and provide early telemetry to act upon.
What is a Application Security Group ?
Allows you to define network security policies based on groups of instances.
Your company is planning on using Azure AD for authentication to the resources defined in Azure. Does Azure AD have built-in capabilities for securing authentication and authorization to resources?
Yes No
Yes
A company is planning on purchasing Azure AD Basic for their Azure account. Does the Azure AD Basic tier come with an SLA of 99.9%?
Yes No
Yes
A company wants to try out some services which are being offered by Azure in Public Preview. Do the services in Public Preview in Azure come with an SLA?
Yes No
No
A company needs to create around 50 customized Virtual Machines. Out of these 20 are Windows based Virtual machines and 30 are Ubuntu Machines. Which of the following would help reduce the administrative effort required to deploy the machines?
Azure Load Balancer Azure Web Apps Azure Traffic Manager Azure ScaleSets
Azure Scale Sets
An IT administrator for a company has been given a powershell script. This powershell script will be used to create several Virtual Machines in Azure. You have to provide a machine to the IT administrator for running the powershell script.You decide to provide a computer that has MacOS and Powershell Core 6.0 installed.Would this solution fit the requirement?
Yes No
Yes
A company is planning on setting up a solution in Azure. The solution would have the following key requirement: A tool that provides guidance and recommendations to improve an Azure environment. Which of the following would be best suited for this requirement?
Azure Advisor Azure Cognitive Services Azure Application Insights Azure Devops
Azure advisor
A company is planning on setting up a solution in Azure. The solution would have the following key requirement A tool used to monitor Web applications hosted in production based environments Which of the following would be best suited for this requirement?
Azure Advisor Azure Cognitive Services Azure Application Insights Azure Devops
Azure Application Insights
A company needs to implement a solution in Azure. Below are the key requirements for this solution Ability to store JSON documents Ensure low latency access to data from around the world Which of the following data solution would you consider for this requirement?
Azure SQL Database Azure CosmosDB Azure SQL Datawarehouse SQL Server Stretch database
Azure CosmosDB
When assigning tags to a resource groups, Would the resources in the resource group also inherit the same tags?
Yes No
NO
Would resources in a resource group inherit the same permissions applied to a resource group?
Yes No
Yes
Heirachy
A company has a requirement to deploy 10 Azure resources for several departments. All of the resource types and configurations are the same. Which of the following could be used to automate the deployment of the resources using infrastructure as code?
Azure Resource Manager templates Virtual machine scale sets Azure API Management service Management groups
Azure Resource Manager templates
A company has deployed their solutions on to Azure. They have users that connect to Azure AD via the Internet. They have the requirement that if users try to login from an anonymous IP address, they are then prompted to change their password. Which of the following should the company consider for this requirement?
Azure AD Connect Health Azure AD Privileged Identity Management Azure AD Identity Protection
Azure AD Identity Protection
A company plans to setup multiple resources in their Azure subscription. They want to implement tagging of resources in Azure. But they want to ensure that when resource groups are created, they have to contain a tag with a name of “organization” and value of “ipspecialist”. You recommend using Azure policies for implementing this requirement Would this recommendation fulfil the requirement?
Yes
You to ensure that resources within a resource group don’t get accidentally deleted. Which of the following would you use for this purpose?
Access Control Policies Locks Diagnostics settings
Locks
A company wants to purchase an Azure support plan. Below is a key requirement from the support plan Regular architecture reviews from Microsoft for the company’s Azure environment Which of the following plan would the company need to purchase to fulfil this requirement?
Premier Developer Professional Direct Standard
Premier
A company wants to host a mission critical application on a set of Virtual Machines in Azure. They want to ensure they can setup the infrastructure in Azure to guarantee the maximum possible uptime for the application. Which of the following can you make use of in Azure to fulfil this requirement? Choose 2 answers from the options given below
Resource Groups Availability Zones Availability Sets Resource Tags
Availability Zones
Availability Sets
A company wants to create multiple data stores in Azure. They want to have storage layers that can be used to store data that is infrequently used. Which of the following storage tiers for Azure BLOB storage would be suitable for this type of requirement? Choose 2 answers from the options given below
Premium storage Hot storage Cool storage Archive storage
Cool storage
Archive storage
You have the following data storage requirements: Data must be stored on multiple nodes. Data must be stored on nodes in separate geographic locations. Data can be read from the secondary location as well as from the primary location Which of the following Azure stored redundancy options should you recommend?
A. Geo-redundant storage
B. Read-only geo-redundant storage
C. Zone-redundant storage
D. Locally redundant storage
Read-only geo-redundant storage
Must be read and seperate geographic locations
The web tier plan must meet the following requirements: The web apps will use custom domains. The web apps each require 10 GB of storage. The web apps must each run in dedicated compute instances. Load balancing between instances must be included. Costs must be minimized. Which web tier plan should you use?
A. Standard
B. Basic
C. Free
D. Shared
Basic
A company wants to setup users in their Azure Account. They have segregated their users into groups. They now want to ensure they set the right permissions for users and administrators accordingly. They need to manage the permissions effectively. You recommend using Azure Role Based Access Does this recommendation meet the requirement?
Yes
A company wants to host their applications on Azure using serverless components. They don’t want to manage the underlying infrastructure for the application. Which of the following could be used to implement a workflow that could be run on a serverless infrastructure?
Azure Logic Apps Azure Service Bus Azure Function App Azure Storage
Azure Logic Apps