StudyToCert

All certifications / Azure Administrator / Cheat sheet

Azure Administrator AZ-104 cheat sheet

Every exam tip and key term from the free Azure Administrator lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Manage Azure identities and governance (24%)

Exam tips

Key terms

User principal name (UPN)
The sign-in name of an Entra user in email-address format, whose suffix must be a verified domain of the tenant.
Security group
An Entra group used to grant access to resources; it can contain users, devices, service principals and other groups.
Microsoft 365 group
A collaboration group with a shared mailbox, calendar, SharePoint site and optional Teams team; members can only be users.
Assigned membership
Group membership that an administrator or group owner maintains by adding and removing members by hand.
Dynamic membership
Group membership calculated automatically from a rule on user or device attributes; it requires Entra ID P1.
Bulk create
A portal operation that creates many users from an uploaded CSV template and reports per-row results.
Microsoft Entra Connect
The tool that synchronizes users and groups from on-premises AD DS into Entra ID, keeping on-premises as the source of authority.
Usage location
The country property on a user that must be set before a license can be assigned.
Group-based licensing
Assigning a license to a group so that all members inherit it and lose it when they leave the group.
Service plan
An individual component of a license product that can be turned off during assignment.
B2B guest user
An external identity invited into your tenant with user type Guest who signs in with credentials from their own organization or account.
External collaboration settings
Tenant settings that control who can invite guests, what guests can see and which domains are allowed.
Self-service password reset (SSPR)
A feature that lets registered users reset their own password using verified authentication methods.
Password writeback
A sync feature that writes passwords reset in the cloud back to on-premises Active Directory.
Role assignment
The binding of a security principal to a role definition at a specific scope.
Security principal
The identity receiving access: a user, group, service principal or managed identity.
Scope
The level at which access applies: management group, subscription, resource group or resource; lower levels inherit it.
NotActions
Operations removed from the Actions list of a role definition; it is not a deny and can be granted back by another role.
User Access Administrator
A built-in role that can manage role assignments but cannot manage the resources themselves.
Custom role
A role definition you create with your own Actions, DataActions and assignable scopes when no built-in role fits.
Deny assignment
A block on specific actions that overrides role assignments; created by Azure features, not directly by administrators.
Microsoft Entra role
A directory role, such as User Administrator, that controls management of Entra objects and tenant settings.
Administrative unit
An Entra container that limits the scope of a directory role to a subset of users, groups or devices.
Control plane
Management operations on Azure resources through Azure Resource Manager, governed by Actions in RBAC roles.
Data plane
Operations on the data inside a resource, such as reading blobs, governed by DataActions in RBAC roles.
Storage Blob Data Reader
A built-in data-plane role that allows reading and listing blob containers and blobs using Entra authorization.
Elevated access
The Global Administrator option that grants User Access Administrator at root scope to recover access to all subscriptions.
Policy definition
A JSON rule with a condition and an effect that describes an allowed or required resource configuration.
Initiative
A policy set definition that groups multiple policy definitions to be assigned and tracked together.
Assignment
The application of a definition or initiative to a scope, with parameter values and optional exclusions.
Exclusion
A child scope listed on an assignment that the assignment does not evaluate.
Exemption
A separate object that excuses a scope or resource from an assignment for a Waiver or Mitigated reason, optionally with an expiry.
DeployIfNotExists
An effect that deploys a related resource when it is missing, using a managed identity for the assignment.
Remediation task
A job that brings existing non-compliant resources into compliance for Modify and DeployIfNotExists policies.
CanNotDelete lock
A lock that allows reading and modifying a resource but blocks deleting it.
ReadOnly lock
A lock that allows reading a resource but blocks both updates and deletion.
Lock inheritance
The rule that a lock on a subscription or resource group applies to all resources beneath it, including ones created later.
Microsoft.Authorization/locks/*
The permission needed to create or delete locks, held by Owner and User Access Administrator among built-in roles.
ScopeLocked
The error Azure returns when an operation is blocked by a resource lock.
Tag
A name and value pair of metadata attached to a subscription, resource group or resource.
Merge vs Replace
Tag update operations: Merge adds or changes the named tags, Replace overwrites the whole tag set.
Tag Contributor
A built-in role that allows managing tags on entities without granting access to the entities themselves.
Require a tag on resources
A built-in Deny policy that blocks creating or updating resources that lack a specified tag.
Inherit a tag from the resource group
A built-in Modify policy that copies a tag from the parent resource group onto resources that lack it.
Cost Management tag inheritance
A billing setting that applies parent tags to usage records for reporting without changing the resources.
Resource group
A logical container for Azure resources that share a lifecycle; every resource belongs to exactly one.
Resource group location
The region where the group's metadata is stored; it does not restrict where its resources are deployed.
Move validation
A check Azure runs before a move to confirm the resource types, dependencies and target are supported.
Resource ID
The full path of a resource, including subscription and resource group, which changes when the resource is moved.
Resource provider registration
Enabling a namespace such as Microsoft.Web in a subscription so its resource types can be created or moved there.
Azure Resource Mover
A service that helps relocate resources to another Azure region, which a resource group move cannot do.
Management group
A container above subscriptions used to apply policy and RBAC to many subscriptions at once.
Tenant Root Group
The single top-level management group in every tenant, from which all management groups and subscriptions descend.
Subscription
A billing, quota and management boundary for Azure resources that trusts one Entra tenant.
Inheritance
The flow of RBAC and policy assignments from a parent scope to all child scopes.
Default management group
The management group where newly created subscriptions are placed, the root unless changed in hierarchy settings.
Landing zone
A design pattern that places shared guardrails high in the hierarchy and gives teams their own subscriptions beneath it.
Cost analysis
The Cost Management view for exploring actual and forecasted costs by scope, grouped and filtered by dimensions such as tag.
Budget
A spending threshold for a scope and period with alert conditions; it notifies but does not stop spending.
Action group
A reusable set of notification and automation actions that budgets and alerts can trigger.
Azure Advisor
A service that analyzes your resources and gives Cost, Security, Reliability, Operational Excellence and Performance recommendations.
Reservation
A one- or three-year commitment to a resource type in exchange for a billing discount on matching usage.
Savings plan for compute
A commitment to an hourly compute spend that discounts usage across services and regions.
Azure Hybrid Benefit
A licensing benefit that lets you use existing Windows Server or SQL Server licenses with Software Assurance in Azure.

Domain 2: Implement and manage storage (19%)

Exam tips

Key terms

LRS
Locally redundant storage: three synchronous copies in one datacenter in the primary region.
ZRS
Zone-redundant storage: three synchronous copies across three availability zones in the primary region.
GRS / GZRS
Geo-redundant options that replicate asynchronously to the paired secondary region, using LRS or ZRS in the primary respectively.
RA-GRS / RA-GZRS
Read-access geo-redundant options that allow reads from the secondary endpoint at any time.
Last Sync Time
A property showing the point up to which data has been replicated to the secondary region.
Standard general-purpose v2
The recommended storage account kind that supports all services, access tiers and redundancy options.
Customer-initiated failover
An action that promotes the secondary region to primary when the primary region is unavailable.
Storage firewall
Network rules on a storage account that allow only listed public IP ranges, subnets and exceptions to connect.
IP network rule
A firewall rule that allows a public IP address or CIDR range; private ranges are not allowed.
Service endpoint
A subnet setting that routes traffic to a service over the Azure backbone and identifies the subnet so it can be allowed by virtual network rules.
Trusted Microsoft services
A firewall exception that lets specific Azure platform services access the account even when public access is restricted.
Private endpoint
A network interface with a private IP in your subnet that connects to a specific storage sub-resource through Private Link.
Private DNS zone
A DNS zone such as privatelink.blob.core.windows.net that resolves the account name to the private endpoint's IP inside linked networks.
Account key
One of two secrets that give full access to a storage account's data and are used to sign account and service SAS.
Account SAS
A SAS signed with an account key that can span several services and service-level operations.
Service SAS
A SAS signed with an account key that grants access to resources in a single storage service.
User delegation SAS
A blob SAS signed with a key obtained through Microsoft Entra credentials, limited by that identity's permissions.
Stored access policy
A named set of SAS constraints on a container, share, queue or table that lets you revoke linked service SAS tokens.
Key rotation
Regenerating access keys on a schedule, using the second key to keep applications running during the change.
AD DS authentication
Azure Files authentication where the storage account is joined to on-premises Active Directory and users present AD Kerberos tickets.
Microsoft Entra Domain Services
A managed Azure domain that can authenticate SMB access to Azure Files for clients joined to it.
Microsoft Entra Kerberos
An Azure Files option where Entra ID issues Kerberos tickets, so clients need no domain controller line of sight.
Share-level permission
An Azure RBAC role, such as Storage File Data SMB Share Contributor, that controls access to a whole file share.
Default share-level permission
A setting that grants a chosen share role to all authenticated identities without per-user assignments.
NTFS permissions
Windows access control lists on directories and files in the share that provide fine-grained access.
Storage File Data SMB Share Elevated Contributor
The share-level role that adds the ability to change NTFS permissions on files and folders.
Azure Storage encryption
Automatic, always-on AES-256 encryption of data at rest in Azure Storage.
Microsoft-managed key
The default option in which Microsoft creates, stores and rotates the storage encryption keys.
Customer-managed key (CMK)
A key you control in Key Vault or Managed HSM that protects a storage account's data encryption keys.
Purge protection
A Key Vault setting that prevents deleted keys from being permanently removed during the retention period; required for CMK.
Infrastructure encryption
An optional second layer of encryption at the infrastructure level that must be enabled at account creation.
Encryption scope
A named key configuration within a storage account that can be applied to containers or individual blobs.
Object replication
Asynchronous, policy-based copying of block blobs from a source container to a destination container in another account.
Blob versioning
A feature that keeps previous versions of blobs automatically; required on both accounts for object replication.
Change feed
An ordered log of changes to blobs in an account, required on the source account for object replication.
AzCopy
A command-line tool for copying and synchronizing data with Blob Storage and Azure Files.
azcopy sync
An AzCopy command that copies only new or changed files and can optionally delete extra files at the destination.
Azure Storage Explorer
A free desktop GUI for browsing and managing storage accounts that uses AzCopy for transfers.
Container
A grouping of blobs inside a storage account, with its own anonymous access level.
Access tier
The Hot, Cool, Cold or Archive setting of a block blob that determines storage and access costs.
Online tier
Hot, Cool or Cold, in which blob data can be read immediately.
Archive tier
An offline tier for rarely accessed data; blobs must be rehydrated before they can be read.
Rehydration
Moving an archived blob back to an online tier, by changing its tier or copying it, with Standard or High priority.
Early deletion charge
A fee for removing or re-tiering a blob before the tier's minimum retention period ends.
Lifecycle management policy
A set of JSON rules on a storage account that automatically tier or delete blobs based on conditions.
prefixMatch
A rule filter that limits a rule to blobs whose names start with a container name and optional path.
blobIndexMatch
A rule filter that selects blobs by their blob index tags.
daysAfterModificationGreaterThan
A condition that triggers an action when a blob has not been modified for more than the given number of days.
Last access time tracking
An account setting that records blob reads so rules can act on days since last access.
baseBlob, version and snapshot actions
Separate action sections for current blobs, previous versions and snapshots in a lifecycle rule.
Blob soft delete
A setting that retains deleted blobs and snapshots for a set number of days so they can be undeleted.
Container soft delete
A setting that retains deleted containers and their contents for a set number of days.
Snapshot
A manually created read-only point-in-time copy of a blob.
Point-in-time restore
A feature that rolls block blobs in chosen containers back to a past time using versioning, change feed and soft delete.
Immutable storage
WORM policies, time-based retention or legal hold, that prevent blobs from being changed or deleted.
Azure file share
A managed SMB or NFS share hosted in a storage account that clients mount like a network drive.
FileStorage account
The premium storage account kind for file shares on SSD, required for NFS shares.
Share snapshot
An incremental, read-only point-in-time copy of a whole file share.
File share soft delete
A setting that retains deleted file shares for a period so they can be undeleted.
Port 445
The TCP port SMB uses, often blocked by ISPs and firewalls, which prevents mounting Azure file shares from outside.
Azure File Sync
A service that caches an Azure file share on local Windows Servers for fast access.

Domain 3: Deploy and manage Azure compute resources (24%)

Exam tips

Key terms

Infrastructure as code (IaC)
Describing infrastructure in version-controlled files that a deployment engine turns into real resources.
ARM template
A JSON file that declares Azure resources, parameters, variables and outputs for Azure Resource Manager to deploy.
Bicep
A domain-specific language for Azure that compiles to ARM JSON with simpler syntax and automatic dependencies.
Parameter
A value supplied at deployment time so one template can be reused with different inputs.
Output
A value a template returns after deployment, such as an endpoint URL.
Export template
A portal feature that generates a template from existing resources or shows a past deployment's template.
Decompile
Converting an ARM JSON template to Bicep with az bicep decompile.
Incremental mode
The default deployment mode that creates or updates template resources and leaves other resources in the group untouched.
Complete mode
A deployment mode that also deletes resources in the resource group that are not declared in the template.
What-if
A preview operation that shows what a deployment would create, change or delete without making changes.
Idempotent
Producing the same result no matter how many times it is run, which is how template deployments behave.
Deployment scope
The level a deployment targets: resource group, subscription, management group or tenant, each with its own command.
Deployment stack
A resource that tracks the resources a deployment manages so they can be cleaned up or protected as a group.
VM size
The combination of vCPUs, memory, temporary storage and disk and network limits for a VM.
Azure Compute Gallery
A service for storing and sharing custom VM images across subscriptions and regions.
Temporary disk
Non-persistent local storage on the VM host that is lost when the VM is deallocated or moved.
Ultra Disk
The highest-performance managed disk type, with independently adjustable IOPS and throughput, usable only as a data disk.
Disk encryption set
A resource that links managed disks to a customer-managed key in Key Vault for server-side encryption.
Encryption at host
A platform feature that encrypts the temporary disk and disk caches on the host, providing end-to-end encryption.
Azure Disk Encryption
In-guest volume encryption using BitLocker or DM-Crypt with keys in Azure Key Vault.
Deallocate
Stopping a VM so it releases its host hardware and stops compute billing, allowing it to be placed on different hardware.
Resize
Changing a VM's size, which restarts the VM and may require deallocation if the size is not available on the current cluster.
Resource move
Moving a VM and its dependent resources to another resource group or subscription without changing its region.
Azure Resource Mover
A service that moves VMs and related resources between Azure regions with dependency checks and commit steps.
Disk snapshot
A point-in-time copy of a managed disk, which can be incremental.
Unattached disk
A managed disk not connected to any VM, which still incurs storage cost.
Fault domain
A group of hardware sharing power and network that can fail together, like a rack.
Update domain
A group of hosts that may be rebooted together during planned maintenance; only one is updated at a time.
Availability set
A grouping that spreads VMs across fault and update domains within one datacenter.
Availability zone
A physically separate datacenter location within a region with independent power, cooling and networking.
Zone-redundant
A service configuration that spans all zones in a region automatically, such as a Standard load balancer frontend.
SLA
Service level agreement: Microsoft's committed uptime percentage for a configuration.
Virtual Machine Scale Set (VMSS)
An Azure resource that deploys and manages a group of identical or mixed VMs as one unit with built-in scaling.
Flexible orchestration
The recommended scale set mode that manages standard VMs, allows mixed sizes and lets you manage each VM individually.
Uniform orchestration
A scale set mode that creates identical instances from one model, managed through the scale set APIs.
Autoscale rule
A condition on a metric, such as average CPU over a time window, that adds or removes instances when met.
Cool down
The waiting period after a scale action during which autoscale takes no further action so metrics can settle.
Scale-in policy
The setting (Default, NewestVM or OldestVM) that decides which instances are deleted when the set shrinks.
Instance protection
A per-instance flag that prevents a VM from being removed by scale-in or affected by scale set actions.
Azure Container Registry (ACR)
A managed private registry for container images and related artifacts, secured with Entra ID and RBAC.
Login server
The registry's fully qualified name, such as contosoacr.azurecr.io, used as the prefix for image names.
Geo-replication
A Premium feature that replicates one registry to several regions for local pulls and regional resilience.
AcrPull
A built-in role that allows an identity to pull images from a registry but not push them.
ACR Tasks
A registry feature that builds, tests and patches images in Azure, triggered manually, by commits or by base image updates.
Image digest
An immutable content hash that identifies exactly one image manifest, unlike a tag which can move.
Admin user
A single shared username and password for a registry, disabled by default and not recommended for production.
Container group
The ACI deployment unit: containers on one host sharing lifecycle, network, IP address and volumes.
Restart policy
The ACI setting (Always, OnFailure or Never) that decides whether containers restart when they exit.
Container Apps environment
A shared boundary that provides networking and logging for a set of container apps.
Revision
An immutable snapshot of a container app version, created when revision-scoped settings change.
Multiple revision mode
A Container Apps setting that runs several revisions at once so traffic can be split between them.
Ingress
The Container Apps setting that exposes an app internally or externally over HTTP or TCP on a target port.
KEDA
Kubernetes Event-driven Autoscaling, the component Container Apps uses for scale rules based on events such as queue length.
App Service plan
The set of compute resources (region, OS, tier, size and instance count) that one or more App Service apps run on.
Scale up
Moving to a larger instance size or higher tier to get more resources per instance or extra features.
Scale out
Increasing the number of instances that run the apps in a plan, with requests load balanced across them.
Rule-based autoscale
Azure Monitor autoscale rules on a plan (Standard and above) that add or remove instances based on metrics or schedules.
Automatic scaling
A Premium plan feature where the platform scales on HTTP traffic without you writing rules.
App Service Environment (ASE)
A single-tenant deployment of App Service inside your virtual network, used by the Isolated tier.
Custom domain
Your own DNS name mapped to an App Service app with a CNAME or A record plus an asuid TXT verification record.
App Service managed certificate
A free, automatically renewed TLS certificate for non-wildcard custom domains on an app.
SNI SSL
A TLS binding that uses Server Name Indication so many certificates can share one IP address.
VNet integration
An outbound feature that lets an app reach resources in a virtual network through a delegated subnet.
Private endpoint
An inbound feature that gives the app a private IP in a VNet so clients can reach it privately.
Deployment slot
A separate live instance of an app, such as staging, that can be swapped with production.
Deployment slot setting
An app setting or connection string marked sticky so it stays with its slot during a swap.

Domain 4: Implement and manage virtual networking (19%)

Exam tips

Key terms

Virtual network (VNet)
A private, isolated network in one Azure region and subscription that spans the region's availability zones.
Address space
The CIDR block or blocks assigned to a VNet, from which all its subnets are carved.
CIDR
Classless Inter-Domain Routing notation, such as 10.1.0.0/24, where the suffix gives the number of network bits.
Subnet
A range inside a VNet's address space where NSGs, route tables, service endpoints and delegations are applied.
Reserved addresses
The five addresses Azure keeps in every subnet: network, default gateway, two for Azure DNS, and broadcast.
Subnet delegation
Dedicating a subnet to a specific Azure service, such as App Service VNet integration, so it can inject resources there.
GatewaySubnet
The exact subnet name required for VPN and ExpressRoute virtual network gateways.
Virtual network peering
A private, low-latency connection between two VNets over the Microsoft backbone.
Global peering
Peering between VNets in different Azure regions.
Non-transitive
The property that peering does not pass through a third VNet: A-B and B-C does not give A-C.
Allow gateway transit
A peering setting on the VNet that owns a gateway, letting peers use that gateway.
Use remote gateways
A peering setting on the VNet without a gateway, telling it to use the peer's gateway.
Allow forwarded traffic
A peering setting that accepts traffic not originating in the peer VNet, such as traffic routed via an appliance.
Hub-and-spoke
A topology where spoke VNets peer with a central hub that holds shared services such as gateways and firewalls.
Public IP address
A standalone Azure resource that gives an associated resource an internet-routable address.
Standard SKU
The current public IP SKU: always static, secure by default and zone aware.
Static allocation
An address assigned at creation that does not change until the public IP resource is deleted.
Zone-redundant
A public IP served from all availability zones in a region so it survives a single zone failure.
Zonal
A public IP pinned to one availability zone, which fails if that zone fails.
Public IP prefix
A reserved contiguous block of static public IP addresses.
NAT gateway
A managed service that provides outbound internet connectivity for a subnet through shared public IPs or prefixes.
System route
A default route Azure creates automatically for every subnet, such as the VNet range and 0.0.0.0/0 to the internet.
User-defined route (UDR)
A custom route in a route table that overrides system routes for associated subnets.
Route table
An Azure resource holding UDRs, associated with one or more subnets (at most one table per subnet).
Next hop type
Where matching traffic is sent: Virtual appliance, Virtual network gateway, Virtual network, Internet or None.
Longest prefix match
The rule that the most specific matching route, such as a /24 over a /16, is chosen.
IP forwarding
A NIC setting that lets a VM receive and forward traffic not addressed to itself, required for NVAs.
Forced tunneling
Redirecting all internet-bound traffic from Azure to on-premises for inspection.
Network security group (NSG)
A stateful set of allow and deny rules that filters traffic for subnets and network interfaces.
Priority
A number from 100 to 4096; lower numbers are processed first and the first match wins.
Default rules
Built-in NSG rules at 65000 and above, such as AllowVnetInBound and DenyAllInBound, that cannot be deleted.
Service tag
A named group of IP prefixes for an Azure service or scope, such as Internet or AzureLoadBalancer, maintained by Microsoft.
Application security group (ASG)
A logical grouping of NICs by role that can be used as a source or destination in NSG rules.
Effective security rules
The combined view of all NSG rules from subnet and NIC that actually apply to a network interface.
Stateful filtering
Automatically allowing return traffic for a connection that a rule already allowed.
Azure Bastion
A managed PaaS service that provides RDP and SSH to VMs over TLS without exposing public IPs on the VMs.
AzureBastionSubnet
The exact subnet name, at least /26, required for a dedicated Bastion deployment.
Native client support
A Standard and Premium feature that lets you connect with your local RDP or SSH client via the Azure CLI.
Host scaling
Adding Bastion instances (Standard and above) to support more concurrent sessions.
IP-based connection
A Standard feature for connecting to a private IP address, including machines on-premises reachable from the VNet.
Shareable link
A Standard feature that lets a user connect to a specific VM through a URL without portal access.
Developer SKU
A free, shared-infrastructure Bastion option for dev and test with one connection at a time and no dedicated subnet.
Service endpoint
A subnet setting that routes traffic to a PaaS service over the Azure backbone and identifies the subnet to the service's firewall.
Private endpoint
A network interface with a private IP in your subnet that connects to one specific resource through Private Link.
Azure Private Link
The platform technology that exposes Azure services on private IP addresses inside your VNet.
Private DNS zone
An Azure DNS zone resolvable only from linked VNets, used for privatelink names.
Virtual network link
The association that lets a VNet resolve records in a private DNS zone.
Service endpoint policy
A policy that limits service endpoint traffic to specific Azure Storage accounts.
Azure DNS Private Resolver
A managed service with inbound and outbound endpoints that lets on-premises DNS resolve Azure private zones and vice versa.
DNS zone
A container for the DNS records of one domain, hosted in Azure DNS as public or private.
Delegation
Pointing a domain or subdomain to specific name servers with NS records at the registrar or parent zone.
Record set
All DNS records with the same name and type in a zone, sharing one TTL.
TTL
Time to live, the number of seconds resolvers may cache a DNS answer.
Alias record
An A, AAAA or CNAME record set that references an Azure resource and updates automatically when its address changes.
Auto-registration
A virtual network link option that automatically maintains A records for VMs in that VNet; one zone per VNet.
Azure Load Balancer
A layer 4 service that distributes TCP and UDP flows across healthy backend instances.
Internal load balancer
A load balancer with a private front-end IP that balances traffic inside a VNet or connected networks.
Backend pool
The set of VM NICs or IP addresses that receive traffic from a load balancer.
Health probe
A periodic TCP, HTTP or HTTPS check that removes failing backend instances from rotation.
Load-balancing rule
A mapping from a front-end IP and port to a backend pool and port, using a health probe.
Inbound NAT rule
A rule that forwards one front-end port to a specific backend VM and port.
Session persistence
A setting that keeps a client's connections on the same backend instance, based on client IP.
Network Watcher
A regional Azure service with diagnostic and monitoring tools for virtual network resources.
IP flow verify
A tool that tests whether a specific packet is allowed or denied to or from a VM and names the NSG rule responsible.
Next hop
A tool that shows where Azure will send a packet from a VM, including next hop type, IP and route table.
Effective routes
The full list of system, user-defined, BGP and peering routes applied to a network interface.
Connection troubleshoot
A tool that tests an actual connection from a source to a destination and reports reachability, latency, hops and issues.
Network Watcher agent
A VM extension required for connection troubleshoot, packet capture and Connection Monitor from Azure VMs.

Domain 5: Monitor and maintain Azure resources (14%)

Exam tips

Key terms

Azure Monitor
The Azure platform service that collects, stores, analyzes and alerts on metrics and logs.
Platform metrics
Numeric time-series data collected automatically for Azure resources and kept for 93 days.
Log Analytics workspace
The Azure Monitor store for log data, queried with KQL and used for log alerts and insights.
Activity log
A subscription-level record of control-plane operations and service health events, collected automatically.
Resource logs
Data-plane logs emitted by a resource, collected only when a diagnostic setting is configured.
Diagnostic setting
A per-resource configuration that sends selected logs and metrics to a workspace, storage account, event hub or partner.
Event hub
A streaming ingestion service used as a diagnostic destination to forward data to external tools such as a SIEM.
KQL
Kusto Query Language, the read-only pipeline query language used by Log Analytics and related services.
where
The KQL operator that filters rows by a condition.
summarize
The KQL operator that aggregates rows into groups with functions such as count() and avg().
project
The KQL operator that selects, renames or orders output columns.
render
The KQL operator that displays results as a chart such as a timechart or barchart.
bin()
A KQL function that rounds values, typically timestamps, into fixed-size buckets for time series.
ago()
A KQL function that returns a time relative to now, such as ago(1d) for one day ago.
Alert rule
A definition of scope, condition and actions that fires an alert when the condition is met.
Metric alert
An alert rule that evaluates a metric against a static or dynamic threshold at regular intervals.
Log search alert
An alert rule that runs a KQL query on a schedule and fires based on the results.
Activity log alert
An alert rule that fires on administrative, service health or resource health events in the activity log.
Action group
A reusable set of notifications and automated actions that alert rules call when they fire.
Alert processing rule
A rule that suppresses or adds action groups for fired alerts matching a scope and filters, optionally on a schedule.
Dynamic threshold
A metric alert option that uses machine learning to learn normal behaviour and alert on deviations.
Insights
Curated Azure Monitor experiences that combine metrics, logs and workbooks for a resource type.
VM insights
An insight showing VM performance charts and, with the Dependency agent, a map of processes and connections.
Azure Monitor Agent (AMA)
The current agent that collects guest OS logs and performance data from VMs and Arc-enabled servers.
Data collection rule (DCR)
An Azure resource defining what data to collect, how to transform it and where to send it.
Data collection rule association
The link between a DCR and a VM or other resource that makes the agent apply that rule.
Dependency agent
An agent required for the VM insights Map view to discover processes and network connections.
Transformation
A KQL statement in a DCR that filters or modifies incoming data before it is stored.
Network Watcher
A regional service offering monitoring, diagnostic and traffic logging tools for Azure networks.
Connection Monitor
A Network Watcher feature that continuously tests connectivity, latency and packet loss between endpoints.
Test group
A Connection Monitor unit combining sources, destinations and test configurations.
Test configuration
The protocol, port, frequency and success thresholds used for Connection Monitor checks.
Flow logs
Records of IP traffic flows through NSGs or virtual networks, stored in a storage account.
Traffic analytics
A feature that processes flow logs in Log Analytics to show traffic patterns and top talkers.
VPN troubleshoot
A diagnostic tool that checks the health of a VPN gateway or connection and reports issues.
Azure Backup
The Azure service that takes scheduled, policy-driven backups and stores recovery points in a vault.
Recovery Services vault
The vault type for Azure VMs, SQL and SAP HANA in VMs, Azure Files, MARS, MABS and Azure Site Recovery.
Backup vault
The newer vault type for data sources such as managed disks, blobs, Azure Database for PostgreSQL and AKS.
MARS agent
The Microsoft Azure Recovery Services agent that backs up files, folders and system state from Windows machines.
Backup storage redundancy
The vault's LRS, ZRS or GRS setting, which must be chosen before the first item is protected.
Business Continuity Center
The portal hub that manages backup and disaster recovery across vault types, subscriptions and regions.
Backup policy
A reusable schedule and retention definition applied to many protected items.
Enhanced policy
An Azure VM backup policy supporting multiple backups per day and required for some newer VM types.
On-demand backup
A manual backup taken outside the schedule with its own retain-until date.
Instant restore
Keeping recent recovery points as snapshots so they can be restored quickly.
Soft delete
Retaining deleted backup data for a period, 14 days by default, so it can be recovered.
Cross-region restore (CRR)
Restoring from backup data replicated to the paired region, requiring GRS and the CRR setting.
Multi-user authorization (MUA)
A protection using Resource Guard that requires a second authorized person for critical backup operations.
Recovery point
A point-in-time copy of protected data from which you can restore.
Create new virtual machine
A restore type that quickly builds a new VM from a recovery point with basic settings.
Restore disks
A restore type that creates managed disks and a customizable template instead of a finished VM.
Replace existing
A restore type that overwrites an existing VM's disks while keeping its configuration.
File Recovery
A feature that mounts a recovery point as drives through a downloaded script so individual files can be copied.
iSCSI
Internet Small Computer Systems Interface, the protocol File Recovery uses to attach recovery point disks as volumes.
Azure Site Recovery (ASR)
A service that continuously replicates workloads to a secondary location so they can fail over during an outage.
RPO
Recovery point objective, the maximum acceptable data loss measured in time.
RTO
Recovery time objective, the maximum acceptable time to restore service.
Test failover
A non-disruptive failover drill into an isolated network, removed afterwards with Cleanup test failover.
Commit
The step that finalizes a failover and discards the other recovery points.
Re-protect
Reversing replication after failover so the running VMs replicate back to the other region.
Recovery plan
An ordered group of VMs, with optional scripts and runbooks, that fail over together.
Backup reports
Azure Monitor workbooks that show backup items, jobs, usage, policies and optimization data from a Log Analytics workspace.
Resource-specific tables
Dedicated Log Analytics tables such as AddonAzureBackupJobs that vault diagnostic settings write to.
Built-in backup alerts
Azure Monitor alerts generated automatically for backup failures and security-relevant backup events.
Policy adherence
A report view showing whether each item had a successful backup in every period.
Study Azure Administrator for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Azure Administrator study plan