All certifications / AI-200 / Lessons
AI-200 AI-200 (replaced AZ-204) lessons
Study AI-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the AI-200 study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Develop containerized solutions on Azure
- Dockerfiles for Python apps: base images, multi-stage builds, non-root users, .dockerignore
- Azure Container Registry: Basic, Standard and Premium tiers; geo-replication and private endpoints on Premium
- Build and push images with `az acr build` (quick tasks) and ACR Tasks triggered by commits, base-image updates or schedules
- Tags vs digests, stable vs unique tags, and cleaning up old images with `az acr repository` and purge tasks
- Pull images without passwords: managed identity with the AcrPull role instead of the admin user
- App Service custom containers on Linux: WEBSITES_PORT, continuous deployment and deployment slots
- Azure Container Apps: environments, ingress (external vs internal), secrets and managed identity
- Container Apps revisions: single vs multiple revision mode, traffic splitting and labels
- Container Apps scaling: HTTP rules, KEDA event rules (for example Service Bus queue length), min/max replicas and scale to zero
- Container Apps jobs: manual, scheduled and event-driven
- AKS basics for developers: Deployment and Service manifests, `kubectl apply`, requests and limits, ConfigMaps and Secrets, attaching ACR
Domain 2: Develop AI solutions by using Azure data management services
- Cosmos DB for NoSQL with the Python SDK (azure-cosmos): CosmosClient, create/upsert/read/delete items, parameterized queries
- Partition key design: high cardinality, even spread, point reads; hierarchical partition keys
- Request Units: point reads vs queries, indexing policy include/exclude paths, consistency levels and their RU cost
- Cosmos DB vector search: container vector policy (path, data type, dimensions, distance function), vector indexes (flat, quantizedFlat, diskANN) and VectorDistance()
- Change feed: change feed processor with a lease container, Azure Functions Cosmos DB trigger, latest-version mode vs all versions and deletes
- Azure Database for PostgreSQL flexible server: allow-listing and enabling the vector (pgvector) extension
- Pgvector: vector(n) columns, distance operators (<-> L2, <=> cosine, <#> inner product), HNSW vs IVFFlat indexes and tuning (m, ef_search, lists, probes)
- Retrieval-augmented generation: chunking, embedding, storing, top-k retrieval with metadata filters, adding results to the prompt
- Azure Managed Redis: cache-aside pattern, TTL and invalidation, eviction policies
- Redis vector indexes and semantic caching of model responses
- Choosing the store: Cosmos DB vs PostgreSQL + pgvector vs Redis for a given AI workload
Domain 3: Connect to and consume Azure services
- Service Bus queues vs topics and subscriptions; Basic tier has no topics
- Receive modes: peek-lock (complete, abandon, dead-letter, defer) vs receive-and-delete; lock duration and lock renewal
- Dead-letter queues: max delivery count, TTL expiry, reading the $DeadLetterQueue subqueue
- Sessions for ordered processing, duplicate detection, scheduled messages and subscription filters (SQL and correlation)
- Event Grid: system and custom topics, event subscriptions, filters (event type, subject begins/ends with, advanced)
- Event Grid delivery: retry policy, event time-to-live, dead-lettering to Blob Storage, webhook validation, CloudEvents schema
- Picking Service Bus, Event Grid or Event Hubs for a scenario
- Azure Functions Python v2 model: function_app.py, decorators, triggers and input/output bindings
- Common triggers: HTTP (auth levels), timer (six-field NCRONTAB), Service Bus, Cosmos DB, Blob, Event Grid
- Hosting plans: Flex Consumption, Premium and Dedicated; cold starts, scale limits and VNet integration
- Configuration and deployment: app settings, local.settings.json, host.json, identity-based connections, `func azure functionapp publish`
Domain 4: Secure, monitor, and troubleshoot Azure solutions
- Managed identities: system-assigned vs user-assigned; DefaultAzureCredential in azure-identity
- Azure RBAC data-plane roles: Key Vault Secrets User, Service Bus Data Sender/Receiver, AcrPull, Cosmos DB built-in data roles
- Key Vault: secrets, keys and certificates, versions, soft delete and purge protection, RBAC vs access policies
- Secret rotation and Key Vault events (SecretNearExpiry) through Event Grid
- Key Vault references in App Service, Functions and Container Apps settings
- Azure App Configuration: key-values, labels, feature flags, Key Vault references, sentinel-key refresh and snapshots
- Application Insights with the Azure Monitor OpenTelemetry Distro for Python: connection strings, traces, spans, custom metrics
- Distributed tracing across services, sampling and live metrics
- KQL: where, project, summarize, bin(), join and render against requests, dependencies, exceptions and traces
- Alerts: metric vs log search alerts and action groups
- Troubleshooting: App Service log stream, Container Apps console and system logs, Functions invocation logs