John Saville - Gemini Pro Flashcards
What is the new name for Azure AD?
entra ID
What is the key difference between entra ID and Active Directory Domain Services?
entra ID speaks Cloud while ADDS speaks on-premises protocols
What is the standard way to interact with entra ID?
Microsoft Graph
What are the two technologies for replicating from Active Directory to entra ID?
entra Connect and entra Connect Cloud Sync
Which way does the replication flow?
From Active Directory to entra ID
What is the purpose of having a Cloud identity?
To allow applications to trust it for authentication and authorization
What is the name of the particular instance of entra ID for an organization?
Tenant
What is the default domain name for a new entra ID tenant?
something.onmicrosoft.com
What is the purpose of external users?
To allow interaction with users from other organizations without creating separate accounts
What is the difference between a guest and an external user?
Guests are external users by default, but they can be made members of the tenant
What are the different ways to provision accounts in entra ID?
Synchronization, manual creation, bulk creation, and provisioning from external systems
What are the two types of groups in entra ID?
Security groups and Microsoft 365 groups
What is the difference between registering and joining a device in entra ID?
Registering is for personal devices, while joining is for corporate devices
What are the different levels of entra ID licenses?
Free, P1, P2, and Governance add-on
What is the purpose of conditional access?
To enforce additional security checks based on factors such as device, location, and risk
What is the purpose of privileged identity management?
To manage and monitor privileged accounts
What is the purpose of self-service password reset?
To allow users to reset their own passwords without contacting the help desk
Who should have the global administrator role?
Only a few trusted individuals
Is entra ID a hierarchical structure?
No, it is a flat structure
What is the difference between the Azure commercial cloud and other clouds?
They have different URLs, tenants, regions, and availability zones
What is the purpose of availability zones?
To provide redundancy and resilience within a region
How many availability zones are exposed to a subscription?
Three
What is the goal of using multiple regions?
To avoid single points of failure and improve disaster recovery
What is the purpose of subscription?
To organize and manage resources
What is the purpose of management groups?
To organize subscriptions and apply policies, access control, and budgets
What are the three core things that management groups can be used for?
Access control, policy, and budgets
How are policies and budgets inherited?
They are inherited from parent management groups to child management groups and subscriptions
What is the purpose of a management group?
To organize subscriptions and apply policies, access control, and budgets
What is the purpose of a subscription?
To organize and manage resources
What is the purpose of a resource group?
To group related resources that will be provisioned, run, and decommissioned together
What is Azure Hybrid Benefit?
A program that allows customers to use existing Windows Server and SQL Server licenses in the cloud
What is Azure Reservation?
A one or three-year commitment to use a specific service in a specific region, which results in a discount
What is Azure Savings Plan?
A flexible one or three-year commitment to spend a certain amount on included compute services, which results in a discount
How does Azure Savings Plan apply to resources?
It applies the best discount to the resource that is running and then moves on to the next resource
Can a resource have both a Savings Plan and a Reserved Instance?
No, it can only have one or the other
What is the purpose of cost analysis?
To provide insights into spending and identify areas for optimization
What is the purpose of a budget?
To set a financial limit and receive alerts when it is reached or exceeded
What are tags?
Key-value pairs that can be applied to resources, resource groups, and subscriptions for organization and filtering
Do tags get inherited?
No, by default, tags are not inherited from parent to child resources
What is the purpose of Azure policy?
To set guard rails and configure requirements for resources
What is the difference between a policy and an initiative?
A policy is a specific condition and effect, while an initiative is a set of policies
What is the benefit of using initiatives?
Easier assignment and compliance tracking for multiple policies
What is the Microsoft Cloud Security Benchmark?
A free set of initiatives for security best practices
What is role-based access control (RBAC)?
A mechanism for assigning permissions to users and groups at different scopes (management group, subscription, resource group, resource)
What is the principle of least privilege?
Giving users and groups the minimum amount of permissions necessary to perform their tasks
What is the difference between owner, contributor, and reader roles?
Owner: Full access, contributor: All access except changing permissions, reader: Read-only access
Can you create custom roles?
Yes, you can create custom roles by cloning existing roles and adding or removing permissions
What is the difference between control plane and data plane?
Control plane: Managing Azure resources, data plane: Interacting with data (e.g., writing to a database)
What is a virtual network (vnet)?
A private network within Azure that provides IP addresses to resources and defines subnets
What is the purpose of a subnet?
To divide a vnet into smaller IP address ranges
How many IP addresses are lost in each subnet?
Five (network address, broadcast address, gateway, and two for DNS)
What is the difference between standard and basic public IPs?
Standard: Static, basic: Dynamic (retiring on 30th September 2025)
What is a public IP address?
An IP address that allows resources to communicate with the public internet
What is a prefix?
A contiguous block of IP addresses
Can you bring your own IP addresses to Azure?
Yes, but it requires a specific process
What is a peering?
A connection between two virtual networks that allows resources to communicate using private IP addresses
What is the difference between Gateway Transit and Use Remote Gateway?
Gateway Transit: Allows a virtual network to use the Gateway of another virtual network for connectivity, Use Remote Gateway: Allows a virtual network to use the Gateway of another virtual network for egress
What is Azure Virtual Network Manager?
A tool for managing virtual networks and configuring connectivity
What are Network Groups in Azure Virtual Network Manager?
Groups of virtual networks that can be used to define connectivity configurations
What are Security Admin Rules in Azure Virtual Network Manager?
Rules that apply before local virtual network rules and can be used to allow or deny traffic
What is a Network Security Group (NSG)?
A set of rules that control network traffic to and from a virtual network