StudyToCert

All certifications / AI-200 / Cheat sheet

AI-200 AI-200 (replaced AZ-204) cheat sheet

Every exam tip and key term from the free AI-200 lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Develop containerized solutions on Azure (24%)

Exam tips

Key terms

Base image
The image named in FROM that your image builds on, such as a slim Python image.
Multi-stage build
A Dockerfile with several FROM stages where the final stage copies only needed artifacts from earlier stages.
Build context
The set of files sent to the builder with a build; .dockerignore removes files from it.
Layer cache
Docker's reuse of unchanged instruction results, which makes instruction order matter for build speed.
USER instruction
Sets the user that later instructions and the running container use, so the app need not run as root.
Login server
The registry's DNS name, such as myregistry.azurecr.io, used as the prefix of every image reference.
Geo-replication
A Premium ACR feature that keeps copies of one registry in several regions behind a single login server.
Private endpoint
A network interface with a private IP in your VNet that connects privately to a service such as a Premium registry.
Repository
A named collection of related images in a registry, distinguished by tags and digests.
Quick task
A one-off cloud build started with az acr build that uploads the context, builds in ACR and pushes the image.
ACR task
A saved build definition in a registry that runs automatically on triggers such as commits, base-image updates or a schedule.
Base image update trigger
An ACR Tasks trigger that rebuilds your app image when the image in its FROM line is updated.
Run ID
The unique identifier of each ACR Tasks run, available as the {{.Run.ID}} placeholder for unique tags.
Tag
A mutable, human-readable label that points to an image manifest and can be moved to a newer image.
Digest
An immutable SHA-256 identifier of an image manifest that always refers to exactly the same content.
Unique tag
A tag used once and never reassigned, such as a build ID or commit hash, recommended for deployments.
Untagged manifest
An image whose tags have all been moved or removed; it still consumes storage until deleted.
acr purge
An ACR Tasks command that deletes tags and untagged manifests by filter and age, often run on a schedule.
Admin user
A registry-wide account with shared passwords and full push/pull rights; disabled by default and meant only for testing.
AcrPull
A built-in Azure RBAC role that grants permission to pull images from a registry and nothing more.
AcrPush
A built-in role that allows both pushing and pulling images, suited to build pipelines.
Managed identity
A Microsoft Entra identity for an Azure resource whose credentials Azure manages and rotates automatically.
WEBSITES_PORT
An App Service app setting that tells the platform which port the custom container listens on.
Continuous deployment (containers)
A setting that makes App Service pull and restart when a registry webhook reports a new image for the configured tag.
Deployment slot
A separate live instance of an app with its own host name that can be swapped with production.
Slot setting
An app setting or connection string marked sticky so it stays with its slot during a swap.
Container Apps environment
A boundary that groups container apps sharing a virtual network and Log Analytics workspace.
External ingress
Ingress that exposes the app outside the environment, typically with a public endpoint.
Internal ingress
Ingress that makes the app reachable only from within its environment.
secretref
The prefix used in a container app environment variable to take its value from an app-level secret.
Revision
An immutable snapshot of a container app's revision-scope configuration, created whenever the template changes.
Single revision mode
The default mode where one revision is active and a new revision replaces the old one once ready.
Multiple revision mode
A mode that keeps several revisions active and splits ingress traffic among them by weight.
Revision label
A named pointer to a revision that gives it a stable URL independent of its generated name.
Replica
One running instance of a container app revision; scaling changes the replica count.
KEDA
Kubernetes Event-driven Autoscaling, the open-source engine behind Container Apps scale rules.
Scale to zero
Running zero replicas when idle, possible with a minimum of 0 and HTTP or event-driven rules.
Scaler
A KEDA component that reads a metric from an event source, such as Service Bus message count, to drive scaling.
Container Apps job
A Container Apps resource that runs containers to completion rather than continuously.
Execution
A single run of a job, containing one or more replicas that must finish successfully.
Trigger type
How a job starts: Manual, Schedule (cron) or Event (KEDA scale rules).
Replica timeout
The maximum number of seconds a job replica may run before it is stopped and treated as failed.
Deployment
A Kubernetes object that keeps a specified number of identical pods running and manages rolling updates.
Service
A Kubernetes object that gives a set of pods, selected by labels, a stable IP, DNS name and load balancing.
Requests and limits
Per-container CPU and memory settings: requests are reserved for scheduling, limits cap usage.
ConfigMap
A Kubernetes object that stores non-secret configuration data for pods.
Kubernetes Secret
An object for sensitive data that is base64-encoded, not encrypted by that encoding, and should be access-controlled.

Domain 2: Develop AI solutions by using Azure data management services (28%)

Exam tips

Key terms

CosmosClient
The azure-cosmos entry point that connects to an account; create one and reuse it for the app's lifetime.
Upsert
An operation that inserts an item if it does not exist or replaces it if it does.
Point read
Reading one item by id and partition key with read_item, the cheapest Cosmos DB operation.
Parameterized query
A query whose values are passed separately as @name parameters instead of string concatenation.
Logical partition
All items sharing one partition key value; limited to 20 GB of storage.
Physical partition
An internal unit of storage and throughput that hosts many logical partitions.
Hot partition
A partition receiving a disproportionate share of requests, causing 429 throttling despite spare total throughput.
Hierarchical partition key
A partition key of up to three levels, such as tenant then user, that lets one top-level value span physical partitions.
Request Unit (RU)
The normalized cost unit for Cosmos DB operations; a 1 KB point read costs about 1 RU.
Indexing policy
Container settings that choose which paths are indexed, the indexing mode and composite or vector indexes.
Session consistency
The default level, guaranteeing that a client reads its own writes within its session.
HTTP 429
The status returned when requests exceed provisioned throughput; clients should retry after the indicated delay.
Vector embedding policy
Container setting that defines each vector path, data type, dimension count and distance function.
flat index
An exact, brute-force vector index with perfect recall, suited to small datasets and limited dimensions.
quantizedFlat index
A vector index that compresses vectors and scans them, lowering cost with a small accuracy trade-off.
diskANN index
A graph-based approximate nearest neighbor index designed for low latency at large scale.
VectorDistance()
The Cosmos DB query function that returns the similarity score between two vectors.
Change feed
An ordered, persistent log of creates and updates (and, in one mode, deletes) to a Cosmos DB container.
Lease container
A container that stores change feed checkpoints and partition ownership for processors and Functions triggers.
Latest version mode
The default change feed mode that returns the latest state of changed items and does not include deletes.
All versions and deletes mode
A change feed mode that records every change, including deletes, and requires continuous backup.
Flexible server
The deployment option of Azure Database for PostgreSQL that offers managed PostgreSQL with configurable compute, HA and networking.
azure.extensions
The server parameter that allow-lists which extensions may be created on a flexible server.
pgvector
An open-source PostgreSQL extension, created as vector, that adds a vector type, distance operators and ANN indexes.
azure_pg_admin
A role on flexible server whose members can perform administrative actions such as creating allow-listed extensions.
vector(n)
The pgvector column type holding an embedding of exactly n dimensions.
<=> operator
pgvector's cosine distance operator; smaller values mean more similar vectors.
HNSW
A graph-based ANN index with strong recall and speed, tuned with m, ef_construction and hnsw.ef_search.
IVFFlat
A cluster-based ANN index built after loading data, tuned with lists at build time and ivfflat.probes at query time.
Operator class
The index setting, such as vector_cosine_ops, that must match the distance operator used in queries.
RAG
Retrieval-augmented generation: retrieving relevant data at query time and adding it to the model prompt to ground answers.
Chunking
Splitting source documents into passages, often with overlap, before embedding them.
Top-k retrieval
Returning the k items whose vectors are most similar to the query vector.
Metadata filter
A condition on chunk properties, such as tenant or language, applied alongside vector search.
Grounding
Constraining a model's answer to supplied source content, often with instructions and citations.
Cache-aside
A pattern where the app checks the cache, loads from the database on a miss and populates the cache itself.
TTL
Time to live: the number of seconds a key exists before Redis expires it automatically.
Invalidation
Removing or refreshing a cached entry when the underlying data changes.
Eviction policy
The rule Redis follows to free memory when full, such as allkeys-lru or volatile-lru.
FT.CREATE
The Redis search command that defines an index over hashes or JSON keys, including vector fields.
KNN query
A Redis search query that returns the K nearest vectors to a supplied query vector.
Semantic cache
A cache that returns stored model responses for prompts whose embeddings are similar enough to the new prompt.
Similarity threshold
The maximum distance at which a cached prompt is considered a match in a semantic cache.
System of record
The authoritative, durable store for data, as opposed to a cache that can be rebuilt.
Operational data
The live application data, such as orders or profiles, that vectors may be stored alongside.
Global distribution
Replicating a database across regions for local reads and writes, a core Cosmos DB feature.
In-memory store
A data store such as Redis that keeps data in RAM for very low latency at a higher cost per gigabyte.

Domain 3: Connect to and consume Azure services (24%)

Exam tips

Key terms

Namespace
The Service Bus container resource that holds queues and topics and defines the tier.
Queue
A point-to-point entity where each message is received by exactly one consumer.
Topic
A publish-subscribe entity where each matching subscription receives its own copy of a message.
Subscription
A named, queue-like view of a topic with its own filter rules and receivers.
Competing consumers
Multiple receivers reading from the same queue so work is spread among them.
Peek-lock
The default receive mode that locks a message until the receiver completes, abandons, defers or dead-letters it.
Receive-and-delete
A receive mode that removes the message on delivery, giving at-most-once processing.
Lock duration
How long a received message stays locked to one receiver before becoming visible again; default one minute, maximum five.
Defer
Settling a message so it stays in the queue but can only be received again by its sequence number.
AutoLockRenewer
A Python SDK helper that renews message locks in the background during long processing.
Dead-letter queue
A built-in subqueue of each queue or subscription that holds messages that could not be delivered or processed.
Max delivery count
The number of delivery attempts after which Service Bus automatically dead-letters a message; default 10.
Poison message
A message that fails processing every time and would loop forever without dead-lettering.
Dead-lettering on expiration
An entity setting, off by default, that moves expired messages to the DLQ instead of dropping them.
Session
A group of messages sharing a session ID that Service Bus delivers in order to one receiver at a time.
Duplicate detection
A queue or topic setting that drops messages whose message ID was already seen within a history window.
Scheduled message
A message that is accepted immediately but becomes available to receivers only at a specified UTC time.
SQL filter
A subscription rule using a SQL-like expression over message properties.
Correlation filter
A subscription rule that matches exact values of system or user properties, cheaper than a SQL filter.
System topic
An Event Grid topic that represents events published automatically by an Azure service.
Custom topic
An Event Grid topic you create and publish your own application events to.
Event subscription
The configuration linking a topic to a handler, with filters deciding which events are delivered.
Subject filter
A filter matching the beginning or end of an event's subject path, such as a container or file extension.
Advanced filter
A filter on event data or envelope fields using operators like NumberGreaterThan or StringContains.
Retry policy
Per-subscription limits on delivery attempts and event time-to-live that govern Event Grid retries.
Event time-to-live
The number of minutes Event Grid keeps retrying an event before giving up; default 1,440.
Dead-letter destination
A Blob Storage container where Event Grid writes events it could not deliver.
Validation handshake
The process by which a webhook proves it owns the endpoint before Event Grid delivers events.
CloudEvents
An open specification for describing event data in a common format across services and clouds.
Discrete event
An event reporting a single state change that is meaningful on its own, well suited to Event Grid.
Event stream
A continuous sequence of events, such as telemetry, analyzed in aggregate and suited to Event Hubs.
Consumer group
An independent view of an Event Hubs stream that lets several applications read it at their own positions.
Load leveling
Using a queue to absorb bursts so workers process at a steady rate, a Service Bus strength.
Trigger
The event that starts a function; every function has exactly one.
Binding
A declarative connection to another service that supplies input data or writes output without SDK code.
function_app.py
The entry file of a Python v2 function app that creates FunctionApp and defines decorated functions.
func.Out
The parameter type for an output binding; calling set() provides the value to write.
Blueprint
A v2 model feature for defining functions in separate modules and registering them with the app.
Authorization level
HTTP trigger setting (anonymous, function or admin) that decides which key, if any, a caller must supply.
NCRONTAB
The six-field cron format used by timer triggers, starting with a seconds field.
Past due
A timer flag indicating the scheduled run happened later than planned, for example after downtime.
Event Grid-based blob trigger
A blob trigger that uses Event Grid notifications instead of polling for lower latency.
Flex Consumption
A Linux serverless Functions plan with event-driven scale to zero, per-function scaling, always-ready instances and VNet integration.
Premium plan
An elastic Functions plan with pre-warmed instances, no cold start for minimum instances, and VNet support.
Dedicated plan
Running functions on an App Service plan with manual or autoscale scaling and fixed cost.
Cold start
Startup latency when a function is invoked with no warm instance available.
Always On
An App Service setting that keeps a Dedicated-plan function app loaded so triggers keep firing.
App settings
Environment variables for a function app in Azure, read by code and referenced by bindings.
local.settings.json
A local-only file whose Values section Core Tools loads as environment variables; not deployed by default.
host.json
An app-wide runtime configuration file for logging, extensions, timeouts and sampling, deployed with the code.
Identity-based connection
A binding connection defined by settings like Prefix__fullyQualifiedNamespace that authenticates with a managed identity.

Domain 4: Secure, monitor, and troubleshoot Azure solutions (24%)

Exam tips

Key terms

System-assigned identity
A managed identity tied to one resource's lifecycle and deleted with it.
User-assigned identity
A standalone managed identity resource that can be attached to many resources and outlives them.
DefaultAzureCredential
An azure-identity credential that tries environment, workload identity, managed identity and developer sign-ins in order.
AZURE_CLIENT_ID
The environment variable that tells azure-identity which user-assigned managed identity to use.
Data plane
Operations on the data inside a service, such as reading secrets or sending messages, as opposed to managing the resource.
Key Vault Secrets User
A built-in role that can read secret contents in an RBAC-enabled Key Vault.
Azure Service Bus Data Sender
A built-in role allowing an identity to send messages to queues and topics in its scope.
Cosmos DB Built-in Data Contributor
A Cosmos DB native data role that allows item reads and writes, assigned with Cosmos DB SQL role assignments.
Secret
A small sensitive value, such as a password or connection string, that an app reads from Key Vault.
Key
A cryptographic key stored in Key Vault that performs operations inside the vault without exposing private material.
Soft delete
Retention of deleted vaults and objects for 7 to 90 days so they can be recovered.
Purge protection
A setting that prevents permanent deletion until the retention period ends; it cannot be disabled once on.
Access policy
The legacy Key Vault authorization model granting per-vault permissions, as opposed to Azure RBAC.
Secret rotation
Periodically replacing a secret with a new value and retiring the old one to limit exposure.
SecretNearExpiry
A Key Vault event published through Event Grid 30 days before a secret's expiration date.
SecretNewVersionCreated
A Key Vault event raised when a new version of a secret is created.
Dual-credential rotation
Alternating between two valid keys so one can be regenerated while apps use the other.
Key Vault reference
An app setting or secret value that points to a Key Vault secret, which the platform resolves at runtime.
@Microsoft.KeyVault(...)
The reference syntax used in App Service and Functions app settings, with VaultName/SecretName or SecretUri.
keyVaultReferenceIdentity
The App Service site property that selects a user-assigned identity for resolving Key Vault references.
keyvaultref
The Container Apps secret syntax that sources a secret's value from a Key Vault secret URI with an identity.
Label
A value that distinguishes versions of the same key, commonly used for environments such as Dev and Prod.
Feature flag
A key-value that turns a feature on or off at runtime, optionally with filters like percentage or targeting.
Sentinel key
A single watched key whose change signals the app to reload all its configuration at once.
Snapshot
An immutable, named copy of selected key-values that always returns the same configuration.
Azure Monitor OpenTelemetry Distro
The azure-monitor-opentelemetry package that configures OpenTelemetry to send Python telemetry to Application Insights.
Connection string
The setting that tells telemetry where to go, including the instrumentation key and ingestion endpoint.
Span
A timed unit of work within a trace, with attributes, status and a parent span.
Custom metric
An application-defined measurement such as a counter or histogram, stored in the customMetrics table.
Trace context
The W3C standard for propagating trace and span IDs between services, carried in the traceparent header.
operation_Id
The Application Insights field holding the trace ID shared by all telemetry for one operation.
Sampling
Keeping only a portion of telemetry, decided per trace, to reduce cost while staying representative.
Live Metrics
A near-real-time view of request, failure and resource metrics that is not affected by sampling.
Application map
An Application Insights view showing components and their dependencies with performance and failure data.
KQL
Kusto Query Language, the pipe-based query language for Log Analytics and Application Insights.
summarize
The KQL operator that aggregates rows into groups with functions such as count, avg and percentile.
bin()
A function that rounds values into fixed-size buckets, often used with timestamp to build time series.
join
An operator that combines rows from two tables on matching columns, such as operation_Id.
render
An operator that displays query results as a chart, for example a timechart.
Metric alert
An alert rule on a numeric metric with static or dynamic thresholds, evaluated frequently and resolving automatically.
Log search alert
An alert rule that runs a KQL query on a schedule and fires based on the results.
Action group
A reusable set of notifications and automated actions that alert rules trigger.
Dynamic threshold
A metric alert condition that learns normal behavior and fires on significant deviations.
Alert processing rule
A rule that suppresses or adds actions to fired alerts across a scope, for example during maintenance.
Log stream
A real-time view of an app's log output in the portal or CLI.
Console logs
In Container Apps, the stdout and stderr output of your containers.
System logs
In Container Apps, platform-generated events such as provisioning, image pulls, probe failures and scaling.
Invocations view
The Functions monitoring page listing recent executions with status, duration and logs from Application Insights.
Study AI-200 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the AI-200 study plan