StudyToCert

All certifications / Azure Fundamentals / Cheat sheet

Azure Fundamentals AZ-900 cheat sheet

Every exam tip and key term from the free Azure Fundamentals lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Describe cloud concepts (27%)

Exam tips

Key terms

Cloud computing
Delivering computing services such as servers, storage, databases and software over the internet on demand.
Shared responsibility model
The division of security and management tasks between the cloud provider and the customer, which depends on the service type.
Infrastructure as a service (IaaS)
A service type where the provider runs the physical infrastructure and you manage the operating system and everything above it.
Platform as a service (PaaS)
A service type where the provider also manages the operating system and runtime, and you manage your application and data.
Software as a service (SaaS)
A complete application run by the provider that you configure and use, such as Microsoft 365.
On-premises
Infrastructure you own and run in your own datacenter, where you are responsible for every layer.
Hypervisor
The software on a physical host that runs virtual machines; in Azure it is always Microsoft's responsibility.
Public cloud
Cloud services owned and run by a provider and offered to many customers over the internet.
Private cloud
Cloud resources dedicated to a single organization, whether in its own datacenter or hosted by a third party.
Hybrid cloud
A combination of private and public cloud that lets data and applications work across both.
Multicloud
Using services from two or more public cloud providers.
Azure Arc
A service that projects servers, Kubernetes clusters and data services outside Azure into Azure Resource Manager so they can be managed and governed from Azure.
Tenant
A customer's isolated slice of a shared cloud, with its own resources and identities.
Consumption-based model
A pricing approach where you pay for the resources you actually use rather than buying capacity in advance.
Pay-as-you-go
Azure's default billing option, where usage is metered and billed after the fact with no upfront commitment.
Meter
The measurement Azure uses to bill a resource, such as compute hours or gigabytes stored.
Deallocate
Stopping a VM so that its compute resources are released and compute billing stops, while its disks remain.
Azure Reservations
A one-year or three-year commitment to a resource type in exchange for a discounted price.
Economies of scale
Lower unit costs a provider achieves by operating at very large scale, which can be passed on to customers.
Capital expenditure (CapEx)
Upfront spending on physical assets that the organization owns and uses over several years.
Operational expenditure (OpEx)
Ongoing spending on services or products as they are used, recorded in the period it is incurred.
Depreciation
Spreading the cost of an owned asset over its useful life as its value declines.
Refresh cycle
The regular replacement of owned hardware every few years as it ages.
Budget
A spending limit in Azure Cost Management that sends alerts as costs approach or exceed thresholds.
Availability
The percentage of time a service is running and usable.
High availability
A design that keeps a service running when individual components fail, usually through redundancy.
Service-level agreement (SLA)
Microsoft's formal commitment to a service's uptime or connectivity, with credits if the target is missed.
Service credit
A discount on the affected service's bill that you can claim when an SLA is not met.
Composite SLA
The overall availability of an application that depends on several services, found by multiplying their SLAs.
Single point of failure
Any component whose failure stops the whole system because there is no redundant copy.
Redundancy
Running extra copies of a component so that one can take over if another fails.
Scalability
The ability to add or remove resources to match demand.
Vertical scaling (scale up/down)
Changing the size or power of an existing resource, such as more CPU or memory.
Horizontal scaling (scale out/in)
Changing the number of instances of a resource, such as adding VMs.
Autoscale
Automatic scaling driven by metric rules or schedules within a minimum and maximum instance count.
Elasticity
The ability to scale automatically in both directions as demand rises and falls.
Virtual machine scale set
A group of identical, load-balanced VMs that can scale out and in automatically.
Reliability
The ability of a system to recover from failures and keep functioning.
Performance predictability
Confidence that an application will have the resources it needs for a consistent user experience.
Cost predictability
The ability to forecast and control cloud spending.
Pricing Calculator
A tool that estimates the cost of Azure resources before you deploy them.
Total Cost of Ownership (TCO) Calculator
A tool that compares the cost of running workloads on-premises with running them in Azure.
Microsoft Cost Management
The Azure service for analysing, forecasting and budgeting actual cloud spending.
Azure Site Recovery
A service that replicates workloads to another location so they can fail over during an outage.
Governance
Setting rules for how resources may be created and used, and checking that they comply.
Azure Policy
A service that evaluates resources against rules and can audit or block non-compliant ones.
Resource lock
A setting that prevents a resource from being deleted or modified by accident.
Management of the cloud
Managing cloud resources themselves, for example with autoscale, templates, monitoring and alerts.
Management in the cloud
The tools used to reach and manage the environment, such as the portal, CLI, PowerShell and APIs.
Distributed denial-of-service (DDoS)
An attack that floods a service with traffic from many sources to make it unavailable.
Azure Cloud Shell
A browser-based shell with Azure CLI and Azure PowerShell already installed and signed in.
Virtual machine (VM)
A software-based computer running an operating system on shared physical hardware.
Lift-and-shift (rehost)
Moving existing servers to cloud VMs with little or no change to the application.
Image
A template containing an operating system, and sometimes software, used to create a VM.
VM size
The combination of virtual CPUs, memory and other capacity allocated to a VM.
Azure Migrate
A service that discovers and assesses on-premises servers and helps move them to Azure.
Azure App Service
A PaaS service for hosting web apps, REST APIs and mobile back ends without managing servers.
Azure SQL Database
A fully managed relational database service where Microsoft handles patching, backups and high availability.
Serverless computing
A model where the provider fully manages servers, scales automatically and bills only for execution.
Azure Functions
Event-driven serverless compute that runs code in response to triggers such as HTTP requests, queue messages or timers.
Azure Logic Apps
A low-code service for building automated workflows that connect apps and services.
Trigger
The event that causes a serverless function or workflow to run.
Microsoft 365
Microsoft's SaaS suite of email, office apps, file storage and collaboration tools.
Customer relationship management (CRM)
Software for managing interactions with customers and sales prospects.
Per-user licensing
A pricing model where you pay a recurring fee for each person who uses the application.
Service type
The category of cloud service, IaaS, PaaS or SaaS, which determines how responsibility is shared.
Configuration responsibility
The customer's duty to set a SaaS application's options, such as sharing and sign-in rules, securely.

Domain 2: Describe Azure architecture and services (38%)

Exam tips

Key terms

Region
A geographical area containing one or more Azure datacenters connected by a low-latency network.
Geography
A market, such as Europe or the United States, containing regions that share data-residency and compliance boundaries.
Region pair
Two regions in the same geography linked for disaster recovery, prioritized recovery and staggered updates.
Sovereign region
An Azure instance isolated from public Azure for legal or compliance reasons.
Azure Government
A sovereign cloud for US government agencies and their partners, run by screened US personnel.
Azure operated by 21Vianet
Azure in China, operated by a separate local company rather than directly by Microsoft.
Geo-redundant storage (GRS)
A storage option that replicates data to the paired region for protection against regional outages.
Datacenter
A physical facility of servers, storage and networking with its own power, cooling and security.
Availability zone
A physically separate location within a region, with independent power, cooling and networking.
Zonal service
A resource pinned to a single zone that you choose, such as a VM in zone 1.
Zone-redundant service
A service the platform replicates across zones automatically, such as ZRS storage.
Zone-redundant storage (ZRS)
A storage redundancy option that keeps copies of data in three zones in the region.
Non-regional service
A global service, such as Microsoft Entra ID, that is not tied to a single region.
Resource
A single manageable item in Azure, such as a VM, storage account or virtual network.
Resource group
A logical container for resources that share a lifecycle; it cannot be nested.
Subscription
A unit of billing, access control and scale that contains resource groups and trusts one Entra tenant.
Management group
A container above subscriptions used to apply policy and access to many subscriptions at once; it can be nested.
Root management group
The single top-level management group in a directory, above all other management groups and subscriptions.
Inheritance
The flow of policies and role assignments from a higher level of the hierarchy to everything below it.
Azure Resource Manager (ARM)
The deployment and management service through which all Azure resources are created and managed.
Virtual machine (VM)
An IaaS compute resource that runs a full Windows or Linux operating system you manage.
Virtual machine scale set
A set of identical, load-balanced VMs that can scale automatically and span zones.
Availability set
A grouping of VMs spread across fault and update domains to survive hardware failures and maintenance in one datacenter.
Fault domain
A group of hardware sharing power and network, so a single hardware failure affects only that group.
Update domain
A group of VMs that may be rebooted together during planned maintenance.
Azure Virtual Desktop
A service that delivers Windows desktops and apps running in Azure to users on almost any device.
Multi-session
A Windows edition that lets several users share one VM in Azure Virtual Desktop.
Container
A lightweight package of an application and its dependencies that shares the host OS kernel.
Azure Container Instances (ACI)
The simplest way to run a single container in Azure, with no VMs or orchestrator to manage.
Azure Container Apps
A serverless platform for containerized apps and microservices that hides Kubernetes and can scale to zero.
Azure Kubernetes Service (AKS)
A managed Kubernetes service where Azure runs the control plane and you manage nodes and workloads.
Orchestration
Automated deployment, scaling, networking and healing of many containers across a cluster.
Azure Functions
Event-driven serverless compute that runs code on triggers and bills per execution on consumption plans.
Deployment slot
A separate staging instance of an App Service app that can be swapped into production.
Virtual network (VNet)
An isolated private network in Azure, in one region and subscription, with its own address space.
Subnet
A range of addresses within a VNet used to group and secure resources.
Network security group (NSG)
A set of allow and deny rules that filters traffic to subnets or network interfaces.
VNet peering
A private connection between two VNets over Microsoft's backbone; global peering links VNets in different regions.
Azure DNS
A service that hosts DNS zones and records on Azure infrastructure; it does not register domain names.
Private endpoint
A network interface with a private IP in your VNet that connects privately to an Azure PaaS service.
Public endpoint
An address reachable from the internet, such as a public IP or a service's default public URL.
Virtual private network (VPN)
An encrypted tunnel that connects networks or devices across an untrusted network such as the internet.
Azure VPN Gateway
A virtual network gateway that sends encrypted traffic between a VNet and other locations over the internet.
Site-to-site (S2S) VPN
A VPN connecting an entire on-premises network to Azure through a VPN device.
Point-to-site (P2S) VPN
A VPN connecting an individual computer to an Azure VNet using client software.
Azure ExpressRoute
A private connection from on-premises to Microsoft's cloud through a connectivity partner that does not use the public internet.
GatewaySubnet
The dedicated subnet, with that exact name, where a VNet's gateway is deployed.
ExpressRoute Global Reach
A feature that links on-premises sites to each other through their ExpressRoute circuits.
Storage account
A container for Azure Storage data services that provides a globally unique namespace and endpoints.
Blob storage
Object storage for large amounts of unstructured data, organized into containers.
Azure Files
Fully managed cloud file shares that can be mounted over SMB or NFS.
Queue storage
A service for storing messages so application components can communicate asynchronously.
Table storage
A NoSQL store for structured, schema-less key-value data.
Access tier
A Hot, Cool, Cold or Archive setting on blob data that trades storage cost against access cost.
Rehydration
Changing an archived blob to an online tier so it can be read, which can take hours.
Lifecycle management
Rules that move blobs between tiers or delete them automatically based on age or access.
Locally redundant storage (LRS)
Three copies of data within a single datacenter in the primary region; the lowest-cost option.
Geo-zone-redundant storage (GZRS)
ZRS in the primary region plus asynchronous replication to LRS in the secondary region.
Read-access (RA-GRS, RA-GZRS)
Variants of the geo options that let you read the secondary copy at any time through a secondary endpoint.
Failover
Switching a storage account so the secondary region becomes the primary after a regional outage.
Last sync time
The point up to which data is guaranteed to have been replicated to the secondary region.
AzCopy
A command-line tool for copying data to, from and between Azure storage accounts, with one-way sync.
Azure Storage Explorer
A free graphical desktop app for managing storage accounts that uses AzCopy for transfers.
Azure File Sync
A service that synchronizes Windows file servers with Azure Files and can tier cold files to the cloud.
Cloud tiering
A File Sync feature that keeps frequently used files locally and stores rarely used files only in Azure.
Azure Migrate
A hub for discovering, assessing and migrating on-premises servers, databases and apps to Azure.
Azure Data Box
A physical device service for moving large volumes of data into or out of Azure offline.
Shared access signature (SAS)
A signed token appended to a storage URL that grants limited, time-bound access.
Microsoft Entra ID
Microsoft's cloud identity and access management service, formerly Azure Active Directory.
Tenant
A dedicated instance of Entra ID that represents one organization.
Microsoft Entra Domain Services
A managed domain providing domain join, Group Policy, LDAP and Kerberos without managing domain controllers.
Microsoft Entra Connect
A tool that synchronizes on-premises Active Directory identities to Entra ID for hybrid identity.
Single sign-on (SSO)
Signing in once to access many applications without re-entering credentials.
Multifactor authentication (MFA)
Requiring two or more different kinds of evidence (know, have, are) to sign in.
Passwordless authentication
Signing in without a password, using a device-bound credential plus biometrics or a PIN.
FIDO2 security key
A hardware key or passkey that uses public-key cryptography for phishing-resistant sign-in.
Microsoft Entra External ID
The set of capabilities that let external users, partners or customers, access your apps with their own identities.
B2B collaboration
Inviting external partners into your tenant as guest users who sign in with their own credentials.
Guest user
An external identity represented in your directory and granted access to specific resources.
Customer identity (B2C)
A service for consumer-facing apps providing branded sign-up and sign-in with local or social accounts.
Conditional Access
An Entra ID feature that uses signals in if-then policies to allow, block or require extra controls at sign-in.
Signal
Information such as user, location, device, app or risk that Conditional Access evaluates.
Report-only mode
A Conditional Access setting that logs what a policy would do without enforcing it.
Azure RBAC
The authorization system that grants access to Azure resources through role assignments.
Role assignment
The combination of a security principal, a role definition and a scope.
Scope
The level where a role applies: management group, subscription, resource group or resource.
Least privilege
Granting only the minimum access needed, for the minimum scope and time.
Zero Trust
A security model built on verify explicitly, least privilege access and assume breach.
Defense in depth
Layering multiple security controls so that one failure does not expose the data.
Microsoft Defender for Cloud
A service for security posture management and threat protection across Azure, other clouds and on-premises.
Secure score
A Defender for Cloud measure of security posture that rises as you apply recommendations.

Domain 3: Describe Azure management and governance (35%)

Exam tips

Key terms

Pay-as-you-go
Paying only for the resources you consume, with no upfront commitment.
Azure Reservations
A one-year or three-year commitment to a specific resource in return for a discounted rate.
Azure savings plan for compute
A commitment to a fixed hourly spend across eligible compute services in exchange for lower prices.
Spot virtual machine
A VM using spare capacity at a low price that can be evicted when Azure needs the capacity.
Ingress and egress
Data entering Azure (generally free) and data leaving Azure (billed).
Azure Hybrid Benefit
Using existing Windows Server, SQL Server or some Linux licenses on Azure to reduce cost.
Deallocate
Stopping a VM so its compute resources are released and compute billing stops.
Azure Pricing Calculator
A free web tool that estimates the cost of specific Azure services you plan to deploy.
Total Cost of Ownership (TCO) Calculator
A free web tool that compares on-premises infrastructure costs with running the same workloads in Azure.
Estimate
A projected cost based on your inputs, not a binding price or actual bill.
Assumptions
TCO inputs such as electricity cost, labor rates and datacenter space that shape the savings report.
Business case
A justification for a project, often built with the TCO Calculator for migrations.
Microsoft Cost Management
The service that reports actual and forecast Azure spending, unlike the calculators.
Cost analysis
The Cost Management view for exploring, grouping and filtering costs and forecasts.
Budget
A spending amount for a scope and period that triggers alerts at chosen thresholds.
Budget alert
A notification sent when actual or forecast cost crosses a budget threshold.
Action group
An Azure Monitor collection of notifications and automated actions triggered by alerts.
Tag
A name-value pair applied to resources, resource groups or subscriptions to organize and report on them.
Chargeback
Allocating cloud costs back to the departments or projects that incurred them.
Data governance
Knowing what data you have, where it is and how it is used, and applying rules to it.
Microsoft Purview
A family of solutions for data governance, risk and compliance across on-premises, multicloud and SaaS data.
Data lineage
A record of where data originated and how it moved and changed across systems.
Data classification
Automatically identifying and labeling data by type or sensitivity, such as credit card numbers.
Data loss prevention (DLP)
Policies that detect and prevent sensitive data from leaving the organization.
Service Trust Portal
Microsoft's site for audit reports, compliance documents and information about how Microsoft cloud services protect data.
Audit report
An independent assessment showing that a service meets a standard such as ISO/IEC 27001 or SOC 2.
Azure Policy
A service that enforces rules on resource configurations and reports compliance across scopes.
Policy definition
A JSON rule describing a condition and the effect to apply when a resource matches.
Effect
The action a policy takes, such as Deny, Audit, Modify or DeployIfNotExists.
Initiative (policy set)
A group of related policy definitions managed and assigned as one unit.
Assignment
The application of a definition or initiative to a scope, with parameters and optional exclusions.
Compliance state
Whether a resource meets the assigned policies, shown on the Compliance page.
Remediation task
A job that brings existing non-compliant resources into compliance using Modify or DeployIfNotExists.
Resource lock
A setting that prevents a resource from being deleted or modified regardless of the user's role.
CanNotDelete
A lock level that allows reading and modifying a resource but blocks deletion.
ReadOnly
A lock level that allows reading a resource but blocks updates and deletion.
Lock inheritance
A lock at a subscription or resource group applies to all resources within it, including new ones.
Control plane
Management operations on resources handled by Azure Resource Manager, which locks affect.
Data plane
Operations on the data inside a resource, such as reading or writing blobs, which locks do not block.
Azure portal
A web-based graphical console for creating, managing and monitoring Azure resources.
Azure Cloud Shell
A browser-based, pre-authenticated shell offering Bash or PowerShell with Azure tools preinstalled.
Azure CLI
A cross-platform command-line tool for Azure whose commands begin with az.
Azure PowerShell
The Az PowerShell module providing Verb-AzNoun cmdlets for managing Azure.
Cmdlet
A PowerShell command following a Verb-Noun pattern, such as Get-AzVM.
Azure mobile app
A phone app for monitoring Azure resources and running quick actions.
Azure Resource Manager
The management layer that every Azure tool sends its requests through.
Azure Arc
A service that extends Azure management and governance to resources running outside Azure.
Arc-enabled servers
Windows or Linux machines outside Azure that are projected into Azure Resource Manager for management.
Connected Machine agent
The lightweight agent installed on a server to connect it to Azure Arc.
Arc-enabled Kubernetes
Kubernetes clusters running anywhere that are connected to Azure for management and configuration.
Hybrid cloud
An environment that combines on-premises infrastructure with public cloud services.
Multicloud
Using services from more than one public cloud provider.
Single pane of glass
One console and toolset for managing resources across many environments.
Azure Resource Manager (ARM)
The deployment and management layer that processes every request to create, change or delete Azure resources.
Resource provider
An Azure service, such as Microsoft.Compute, that supplies a type of resource through Resource Manager.
Infrastructure as code (IaC)
Defining and deploying infrastructure from code files kept in source control.
ARM template
A JSON file that declaratively defines Azure resources to deploy.
Bicep
A concise Microsoft language for declarative Azure deployments that transpiles to ARM JSON.
Declarative
Describing the desired end state and letting the platform work out the steps.
Idempotent
Producing the same result no matter how many times a deployment is run.
Configuration drift
Environments that should match gradually becoming different through manual changes.
Azure Advisor
A free service that gives personalized best-practice recommendations for your Azure resources.
Advisor categories
Reliability, security, performance, operational excellence and cost.
Advisor score
A percentage showing how well your resources follow Advisor's recommendations.
Azure status
A public page showing widespread Azure outages across all regions.
Service Health
A personalized portal view of issues, planned maintenance and advisories for the services and regions you use.
Resource Health
A view of the current and past health of an individual resource and whether a platform event caused a problem.
Health advisory
A Service Health notice about changes that may require action, such as a feature retirement.
Azure Monitor
The platform for collecting, analyzing and acting on telemetry from Azure, on-premises and other clouds.
Metrics
Numeric values sampled at regular intervals, ideal for charts and fast alerts.
Logs
Detailed event records with rich properties, stored in a Log Analytics workspace.
Log Analytics
The portal tool for querying log data with Kusto Query Language (KQL).
Alert rule
A definition of the scope, condition and severity that triggers an alert.
Application Insights
An Azure Monitor feature for application performance monitoring of live web apps.
Activity log
A subscription-level log of management operations, showing who did what and when.
Study Azure Fundamentals for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Azure Fundamentals study plan