John Saville - Gemini Pro Flashcards

1
Q

What is the new name for Azure AD?

A

entra ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the key difference between entra ID and Active Directory Domain Services?

A

entra ID speaks Cloud while ADDS speaks on-premises protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the standard way to interact with entra ID?

A

Microsoft Graph

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the two technologies for replicating from Active Directory to entra ID?

A

entra Connect and entra Connect Cloud Sync

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which way does the replication flow?

A

From Active Directory to entra ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the purpose of having a Cloud identity?

A

To allow applications to trust it for authentication and authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the name of the particular instance of entra ID for an organization?

A

Tenant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the default domain name for a new entra ID tenant?

A

something.onmicrosoft.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the purpose of external users?

A

To allow interaction with users from other organizations without creating separate accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the difference between a guest and an external user?

A

Guests are external users by default, but they can be made members of the tenant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the different ways to provision accounts in entra ID?

A

Synchronization, manual creation, bulk creation, and provisioning from external systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the two types of groups in entra ID?

A

Security groups and Microsoft 365 groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the difference between registering and joining a device in entra ID?

A

Registering is for personal devices, while joining is for corporate devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the different levels of entra ID licenses?

A

Free, P1, P2, and Governance add-on

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the purpose of conditional access?

A

To enforce additional security checks based on factors such as device, location, and risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the purpose of privileged identity management?

A

To manage and monitor privileged accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the purpose of self-service password reset?

A

To allow users to reset their own passwords without contacting the help desk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Who should have the global administrator role?

A

Only a few trusted individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Is entra ID a hierarchical structure?

A

No, it is a flat structure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the difference between the Azure commercial cloud and other clouds?

A

They have different URLs, tenants, regions, and availability zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the purpose of availability zones?

A

To provide redundancy and resilience within a region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

How many availability zones are exposed to a subscription?

A

Three

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the goal of using multiple regions?

A

To avoid single points of failure and improve disaster recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is the purpose of subscription?

A

To organize and manage resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What is the purpose of management groups?

A

To organize subscriptions and apply policies, access control, and budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What are the three core things that management groups can be used for?

A

Access control, policy, and budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

How are policies and budgets inherited?

A

They are inherited from parent management groups to child management groups and subscriptions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What is the purpose of a management group?

A

To organize subscriptions and apply policies, access control, and budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What is the purpose of a subscription?

A

To organize and manage resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is the purpose of a resource group?

A

To group related resources that will be provisioned, run, and decommissioned together

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What is Azure Hybrid Benefit?

A

A program that allows customers to use existing Windows Server and SQL Server licenses in the cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is Azure Reservation?

A

A one or three-year commitment to use a specific service in a specific region, which results in a discount

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is Azure Savings Plan?

A

A flexible one or three-year commitment to spend a certain amount on included compute services, which results in a discount

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

How does Azure Savings Plan apply to resources?

A

It applies the best discount to the resource that is running and then moves on to the next resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Can a resource have both a Savings Plan and a Reserved Instance?

A

No, it can only have one or the other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What is the purpose of cost analysis?

A

To provide insights into spending and identify areas for optimization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What is the purpose of a budget?

A

To set a financial limit and receive alerts when it is reached or exceeded

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What are tags?

A

Key-value pairs that can be applied to resources, resource groups, and subscriptions for organization and filtering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Do tags get inherited?

A

No, by default, tags are not inherited from parent to child resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What is the purpose of Azure policy?

A

To set guard rails and configure requirements for resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

What is the difference between a policy and an initiative?

A

A policy is a specific condition and effect, while an initiative is a set of policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What is the benefit of using initiatives?

A

Easier assignment and compliance tracking for multiple policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What is the Microsoft Cloud Security Benchmark?

A

A free set of initiatives for security best practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What is role-based access control (RBAC)?

A

A mechanism for assigning permissions to users and groups at different scopes (management group, subscription, resource group, resource)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What is the principle of least privilege?

A

Giving users and groups the minimum amount of permissions necessary to perform their tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

What is the difference between owner, contributor, and reader roles?

A

Owner: Full access, contributor: All access except changing permissions, reader: Read-only access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

Can you create custom roles?

A

Yes, you can create custom roles by cloning existing roles and adding or removing permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What is the difference between control plane and data plane?

A

Control plane: Managing Azure resources, data plane: Interacting with data (e.g., writing to a database)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

What is a virtual network (vnet)?

A

A private network within Azure that provides IP addresses to resources and defines subnets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

What is the purpose of a subnet?

A

To divide a vnet into smaller IP address ranges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

How many IP addresses are lost in each subnet?

A

Five (network address, broadcast address, gateway, and two for DNS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

What is the difference between standard and basic public IPs?

A

Standard: Static, basic: Dynamic (retiring on 30th September 2025)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

What is a public IP address?

A

An IP address that allows resources to communicate with the public internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

What is a prefix?

A

A contiguous block of IP addresses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Can you bring your own IP addresses to Azure?

A

Yes, but it requires a specific process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

What is a peering?

A

A connection between two virtual networks that allows resources to communicate using private IP addresses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

What is the difference between Gateway Transit and Use Remote Gateway?

A

Gateway Transit: Allows a virtual network to use the Gateway of another virtual network for connectivity, Use Remote Gateway: Allows a virtual network to use the Gateway of another virtual network for egress

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

What is Azure Virtual Network Manager?

A

A tool for managing virtual networks and configuring connectivity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

What are Network Groups in Azure Virtual Network Manager?

A

Groups of virtual networks that can be used to define connectivity configurations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

What are Security Admin Rules in Azure Virtual Network Manager?

A

Rules that apply before local virtual network rules and can be used to allow or deny traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

What is a Network Security Group (NSG)?

A

A set of rules that control network traffic to and from a virtual network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

What is a Service Tag?

A

A tag that represents a range of IP addresses for Azure services

63
Q

What is an Application Security Group?

A

A tag that can be applied to a network interface to control access to resources

64
Q

What is the default rule for inbound traffic in an NSG?

A

Deny all traffic except traffic from the virtual network itself

65
Q

What is the default rule for outbound traffic in an NSG?

A

Allow all traffic

66
Q

What is a Network Security Group (NSG)?

A

A set of rules that control network traffic to and from a virtual network

67
Q

What is a Service Tag?

A

A tag that represents a range of IP addresses for Azure services

68
Q

What is an Application Security Group?

A

A tag that can be applied to a network interface to control access to resources

69
Q

What is the difference between Azure Firewall Basic, Standard, and Premium?

A

Basic: Low performance, Standard: Up to 30 Gbps, Premium: Up to 100 Gbps, Additional features such as intrusion detection and URL filtering

70
Q

What is Azure DNS?

A

A public and private DNS service provided by Microsoft

71
Q

What is the difference between public and private DNS zones in Azure?

A

Public zones are accessible from the internet, while private zones are only accessible within virtual networks

72
Q

What is automatic registration in Azure Private DNS?

A

A feature that automatically creates DNS records for resources in a virtual network

73
Q

What is Azure Private DNS Resolver?

A

A service that allows resources outside of a virtual network to resolve records in private DNS zones

74
Q

What is the default DNS zone for a virtual network?

A

internal.cloudapp.net

75
Q

Can custom DNS servers be used with virtual networks?

A

Yes, but they must also be able to resolve to the Azure DNS IP address (168.63.129.16)

76
Q

What are the two types of VPN gateways?

A

Policy-based (static routing) and Route-based (dynamic routing)

77
Q

What is the difference between policy-based and route-based VPN gateways?

A

Policy-based: One tunnel, restrictive, Legacy only, Route-based: Multiple tunnels, point-to-site VPN

78
Q

What is Express Route?

A

A private connectivity service that extends a customer’s network into Microsoft’s backbone

79
Q

What is private peering in Express Route?

A

A type of connectivity that connects private IP spaces within virtual networks

80
Q

What is Express Route Global Reach?

A

Enables connectivity between different Express Route circuits and locations using the Microsoft backbone

81
Q

What is Microsoft peering?

A

A type of connectivity that allows customers to connect to Azure PaaS services over Express Route

82
Q

What is Azure Virtual WAN?

A

A managed service that provides connectivity and routing for virtual networks and other Azure resources

83
Q

What is the difference between Azure Virtual WAN Basic and Standard?

A

Basic: Site-to-site VPN only, Standard: Express Route, intra-VNet connectivity, Azure Firewall integration, Network Virtual Appliance deployment

84
Q

What are User Defined Routes (UDRs)?

A

Custom routing policies that override default routing tables

85
Q

What are service endpoints?

A

Enable specific subnets to communicate with Azure PaaS services

86
Q

How do service endpoints work?

A

Create a private connection between a subnet and a service, allowing only resources in the subnet to access the service

87
Q

What is a private endpoint?

A

Creates an IP address in a subnet that connects to a specific instance of a service, providing a secure and direct communication channel

88
Q

How does a private endpoint differ from a service endpoint?

A

A private endpoint provides an IP address in a subnet that can be accessed from outside the subnet, while a service endpoint only allows communication from within the subnet

89
Q

What is Azure Bastion?

A

A managed jump box service that allows secure access to virtual machines from the internet

90
Q

What are the different Azure Bastion SKUs?

A

Basic: Same VNet only, Developer: Same VNet only, Standard: Peered VNets, RDP to Linux, SSH to Windows, Azure CLI support, Sharable link, Copy/paste disable

91
Q

What is Azure Application Gateway?

A

A Layer 7 load balancer that understands HTTP/S and websockets

92
Q

What is Azure Load Balancer?

A

A Layer 4 load balancer that supports TCP and UDP

93
Q

What are the two SKUs of Azure Load Balancer?

A

Basic and Standard

94
Q

How does Azure Load Balancer work?

A

Has a front-end IP address and one or more backend pools, uses health probes to check backend pool instances

95
Q

What are the differences between Azure Load Balancer Free and Standard SKUs?

A

Free: 300 backend instances, no SLA, no outbound rules, Basic IP only, Standard: 1000 backend instances, SLA, outbound rules, Nicknames or IP addresses

96
Q

What is Azure Application Gateway?

A

A Layer 7 load balancer that understands HTTP/S, websockets, and other application-layer protocols

97
Q

What are the benefits of using Azure Application Gateway?

A

URL-based routing and redirection, SSL/TLS termination, session affinity, web application firewall protection

98
Q

What is Azure Traffic Manager?

A

A DNS-based global load balancer that distributes traffic based on performance, priority, and other factors

99
Q

What is a cross-region load balancer?

A

A global IP address that points to multiple regional load balancers, providing a single endpoint for clients to access

100
Q

What is the difference between Azure Storage General Purpose V2 and Premium Storage?

A

General Purpose V2 offers all types of blobs, queues, tables, and files, while Premium Storage is built on SSD technology and offers block blobs, page blobs, and files with higher performance

101
Q

What is the difference between Premium Files and regular files?

A

Premium Files are provisioned based on size, meaning users pay for the size of the share they create rather than the amount of data written to it

102
Q

What are the different types of Azure Storage services?

A

Blob, file shares, queues, tables

103
Q

What is the purpose of Azure Storage Explorer?

A

A tool for interacting with Azure Storage accounts, including viewing contents, writing items to queues, and adding data to tables

104
Q

What are the different redundancy options for Azure Storage accounts?

A

Locally redundant storage (LRS): Three copies within the same storage cluster, Zone redundant storage (ZRS): Three copies spread over three availability zones, Geo-redundant storage (GRS): Three copies within a storage cluster and three copies in a paired region, Geo-zone-redundant storage (GZRS): Three copies spread over three availability zones and three copies in a paired region’s storage cluster

105
Q

What are the different tiers available for Azure Blob storage?

A

Hot, Cool, Cold, Archive

106
Q

How does pricing for Azure Blob storage differ across tiers?

A

Hot: Highest capacity cost, lowest transaction cost; Cool: Lowest capacity cost, highest transaction cost; Cold: Low capacity cost, high transaction cost; Archive: Super cheap capacity cost, no interaction (offline)

107
Q

What is Azure Blob storage lifecycle management?

A

A feature that allows users to create rules for automatically moving data between tiers based on filters such as last access time or creation date

108
Q

What is Azure Blob storage object replication?

A

A feature that enables users to replicate data from a container in one storage account to a container in another storage account, regardless of region

109
Q

What is the difference between Azure Files tiers?

A

Transaction Optimized: Highest capacity cost, lowest transaction cost; Hot: Low capacity cost, high transaction cost; Cool: Lowest capacity cost, highest transaction cost; Premium: Different type of storage account with higher performance

110
Q

What are some of the features available for Azure Files?

A

Performance configuration, backup snapshots, soft delete, backup Vault integration, Azure AD integration

111
Q

What is Azure File Sync?

A

A service that enables synchronization of on-premises file shares with Azure Files

112
Q

What are the benefits of using Azure File Sync?

A

Infinite scale, data resilience, offloading of less-used data to the cloud

113
Q

How can I control access to Azure Storage data?

A

Using data plane role-based access control (RBAC) or shared access signatures (SAS)

114
Q

What is the difference between a storage account key and a shared access signature?

A

Storage account keys are powerful and should be rotated regularly; shared access signatures are more granular and can be used for specific services or resources

115
Q

What is encryption scope?

A

A feature that enables the use of different encryption keys for different containers or blobs within a storage account

116
Q

What are the different types of Azure managed disks?

A

Standard HDD, Standard SSD, Premium SSD, Premium SSD V2, Ultra Disk

117
Q

How is performance determined for Azure managed disks?

A

Performance is tied to the size of the disk, with larger disks providing better performance

118
Q

How can I modify the performance of a Premium SSD V2 or Ultra Disk?

A

By adjusting the IOPS and throughput settings

119
Q

How can I encrypt Azure managed disks?

A

By creating a disk encryption set that uses a key in Azure Key Vault

120
Q

What is the best way to provision Azure resources?

A

Using declarative templates such as ARM JSON or Azure Bicep

121
Q

What are the benefits of using templates for provisioning?

A

Ensures consistency, reduces errors, and allows for version control

122
Q

What is the difference between Infrastructure as a Service (IaaS) and Platform as a Service (PaaS)?

A

IaaS: Vendor manages hypervisor, physical servers, storage, networking; customer manages OS, patching, backup, etc.; PaaS: Vendor manages all of the above except customer application and data

123
Q

What is the ultimate level of service in the cloud?

A

Serverless offerings like Azure Functions and Logic Apps

124
Q

What are the different dimensions of a virtual machine?

A

CPU, memory, storage, network capabilities, special GPUs (e.g., ratio of CPU cores to memory)

125
Q

Why is it important to match the VM skew and size to the workload?

A

To optimize resource utilization and avoid wasting resources

126
Q

What is the concept of scaling in Azure?

A

Adding or removing VM instances based on changing workload requirements

127
Q

What are the different types of virtual machine storage?

A

Ephemeral, temporary, premium, standard

128
Q

What is the purpose of a virtual machine extension?

A

To add capabilities to a virtual machine, such as running scripts or integrating with Azure services

129
Q

What is Azure Bastion?

A

A service that provides secure access to virtual machines through a managed jumpbox environment

130
Q

What is the difference between a fault domain and an availability zone?

A

Fault domains are within a single data center, while availability zones are isolated across multiple data centers

131
Q

What is a virtual machine scale set?

A

A group of virtual machines that can be scaled up or down automatically based on demand

132
Q

What is the difference between uniform and flexible virtual machine scale sets?

A

Uniform scale sets have a fixed scaling profile, while flexible scale sets allow for more customization and the inclusion of spot instances

133
Q

What is a container registry?

A

A repository for container images

134
Q

What is the difference between a virtual machine and a container?

A

A virtual machine virtualizes the hardware, while a container virtualizes the operating system

135
Q

What is the purpose of a container registry?

A

To store and manage container images

136
Q

What is the role of the control plane in Kubernetes?

A

To manage the cluster and schedule containers

137
Q

What is a pod in Kubernetes?

A

A container instance

138
Q

What is persistent volume claim?

A

A request for storage that can be mapped to a persistent volume

139
Q

What is the purpose of the cluster autoscaler in Kubernetes?

A

To add or remove nodes as needed to meet the demand for pods

140
Q

What is the difference between Azure Container Instances and AKS?

A

Azure Container Instances is a managed service for running containers without the need for an orchestrator, while AKS is a managed Kubernetes service

141
Q

What is the purpose of an app service plan in Azure?

A

To define the resources and configuration for a group of app service instances

142
Q

What is the difference between standard and elastic scaling in app service plans?

A

Standard scaling requires manual configuration of scaling rules, while elastic scaling automatically adjusts the number of instances based on load

143
Q

What is the purpose of the activity log in Azure?

A

To record control plane operations at the subscription level

144
Q

What is the difference between metrics and logs in Azure Monitor?

A

Metrics are time-based signals, while logs are structured events

145
Q

What is the purpose of diagnostic settings in Azure Monitor?

A

To configure the collection and destination of logs

146
Q

What is the benefit of using a log analytics workspace for log storage?

A

Powerful analytics capabilities using KQL

147
Q

What is the purpose of Azure Monitor?

A

To collect and analyze metrics and logs from Azure resources

148
Q

What is the difference between metrics and logs in Azure Monitor?

A

Metrics are time-based signals, while logs are structured events

149
Q

What is the purpose of diagnostic settings in Azure Monitor?

A

To configure the collection and destination of logs

150
Q

What is the purpose of alerts in Azure Monitor?

A

To notify you when certain conditions are met

151
Q

What is the difference between alert processing rules and action groups?

A

Alert processing rules determine which action groups to call and when to suppress alerts, while action groups define the actions to be taken

152
Q

What is the difference between common and basic log analytics workspaces?

A

Common workspaces have full KQL capabilities and included data ingestion and storage costs, while basic workspaces have a subset of KQL capabilities and require payment for data ingestion and storage

153
Q

What is the purpose of Network Watcher?

A

To troubleshoot network-related issues

154
Q

What are some of the capabilities of Network Watcher?

A

IP flow verification, next hop determination, VPN troubleshooting, connection troubleshooting, packet capture, and NSG diagnostics