Certified Administrator Flashcards

1
Q

What feature gives you command line access to an IaaS VM in the portal?

A

Serial console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the earliest Windows Server supported in Azure?

A

2008 R2 SP1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Public and private IP addresses are configured at what level?

A

vNIC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

To support WinRM, which TCP port needs an NSG allowance?

A

5985

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Availability zones represent high availability at what level?

A

Datacenter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Availability sets represent high availability at what level?

A

Server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the 2 kinds of locks that you can apply to a resource group?

A

DoNotDelete and ReadOnly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 3 Azure Storage disk types

A

OS, Data, Temporary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What service needs to be enabled on a vm in order to access the Serial Console?

A

Boot diagnostics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does AAA stand for in the context of security?

A

Authentication, Authorization, Accounting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the difference between a policy and RBAC rules in Azure?

A

A policy checks resource properties during deployment, RBAC checks user actions for different scopes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

To support RDP, which TCP port needs an NSG allowance?

A

3389

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

To support SSH, which TCP port needs an NSG allowance?

A

22

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

If network isolation is a MUST HAVE when using App Service, what tier must be used?

A

Isolation tier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which Windows server features can App Services not access?

A

Registry, Event Logs, Graphics systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What settings are automatically swapped between Deployment Slots in App Services?

A

General settings, Handler mappings, Monitoring and Diagnostic settings, WebJobs content, Application Settings, and Connection Strings (* can be set to not slot in the Portal)

17
Q

What settings are NOT automatically swapped between Deployment Slots in App Services?

A

Publishing endpoints, Custom Domains, SSL certs, Service Scale settings, and WebJob schedulers

18
Q

What 4 conditions must be met when uploading a 3rd Party SSL Cert to Azure?

A

Signed by Trusted Certificate Authority, Password protected .pfx file, Private Key length of at least 2048 bits, Must contain all intermediate Certificates

19
Q

What is the only replication method for Premium disk storage?

A

Locally Redundant Storage (LRS)

20
Q

What is Azure Site Recovery (ASR)?

A

A DRaaS (Disaster Recovery as a Service) providing easy failover management for cloud and hybrid-cloud resources

21
Q

What does Storage Service Encryption provide?

A

Encrypted data at rest, 128 bit AES encryption, and key management by Azure (or self managed in Azure Key Valut)

22
Q

What does Azure Disk Encryption provide?

A

Bitlocker (Windows) or DM-crypt (Linux) encryption for all OS and DATA disks

23
Q

What is Azure Security Center?

A

A service provided by Azure with centralized policy management, continuous assessment and actionable recommendations

24
Q

What is JIM VM Access?

A

Just-in-time VM access: locks down Admin port access (WinRM, RDP, SSH) until requested, then provided time-restricted access to a set of specific IP addresses

25
Q

What tier of Azure Security Center must be used in order to utilize JIM VM Access?

A

Standard Tier

26
Q

What are the ways a Function App can be triggered?

A

HTTP request, Timer, Storage Account event, CosmosDB event, Event Grids/Hubs, or Webhooks

27
Q

Should load testing of Service Apps be done in the same Service App Plan as your Production app, but on a different deployment slot?

A

No - any load tests should be conducted in their own Service App Plan. All deployment slots in a SAP rely on the same infrastructure as the Production slot - any load tests could severely impact the performance of Production, even if done on a different deployment slot

28
Q

tcping simulate ping by using which protocol?

A

TCP

29
Q

How is an Azure VM on-boarding into the Log Analytics workspace and Network Performance Monitor?

A

Microsoft Monitoring Agent