General Exam Strategy
-
Time management: 40–60 questions, ~100–120 minutes. Don’t overthink single-choice questions.
-
Keywords matter: Look for terms like classify, encrypt, enforce, scope, cost, scale, resiliency — they usually map directly to a specific service.
-
Eliminate distractors: If two answers look similar, one usually applies at the wrong scope (RG vs Mgmt Group, Budget vs Policy).
-
Think like Microsoft: Always lean towards secure, scalable, and automated solutions.
High-Frequency Exam Topics
Identities & Governance
-
Entra ID: MFA, Conditional Access, PIM.
-
RBAC vs Azure Policy vs Blueprints.
-
Guest access (B2B).
Storage
-
Redundancy options (LRS, ZRS, GRS, RA-GRS).
-
Shared access signatures (SAS).
-
Blob tiers (Hot, Cool, Archive).
Compute
-
VM sizes, scaling, availability sets/zones.
-
App Services vs Functions vs AKS.
-
Azure Arc for hybrid.
Networking
-
VNets, Subnets, Peering.
-
NSGs vs ASGs.
-
VPN vs ExpressRoute.
-
Load Balancer (L4) vs App Gateway (L7) vs Front Door vs Traffic Manager.
Monitoring & Backup
-
Azure Monitor, Log Analytics, Alerts.
-
Recovery Services Vault (backup + ASR).
-
Application Insights basics.
Security
-
Defender for Cloud vs Sentinel.
-
Key Vault (secrets, keys, certs).
-
Zero Trust principles.
-
Locks vs RBAC.
Automation
-
ARM templates = declarative, idempotent.
-
Runbooks (VM start/stop, patching).
-
CLI vs PowerShell.
-
GitHub Actions vs DevOps Pipelines.
Data Protection & Governance
-
Azure Information Protection (labels, encryption).
-
Encryption at rest (SSE, TDE, ADE).
-
Encryption in transit (TLS, VPN).
-
Retention policies, Tags, Locks, Mgmt Groups.
Cost Optimization
-
Budgets (alerts only).
-
Reserved Instances vs Spot VMs.
-
Cost breakdown by tags.
High Availability
-
SLA numbers (99.9%, 99.95%, 99.99%).
-
Availability Sets vs Zones.
-
Scale Sets for auto-scaling.
-
Combining SLAs (multiply).
Common Exam Traps 🚨
-
Tags don’t prevent deletion (Locks do).
-
Budgets don’t block resources (Policies do).
-
Load Balancer ≠ App Gateway (Layer 4 vs Layer 7).
-
Availability Set ≠ Availability Zone (rack vs datacenter).
-
Defender for Cloud ≠ Sentinel (recommendations vs SIEM).
-
ARM Templates ≠ Scripts (declarative vs imperative).
Readiness Checklist ✅
-
Can you explain scope hierarchy? (Mgmt Group → Subscription → RG → Resource)
-
Do you know when to use Availability Sets vs Zones vs Scale Sets?
-
Can you map services to exam keywords (classify → AIP, enforce → Policy, secrets → Key Vault)?
-
Have you practiced cost optimization scenarios (RIs, Spot, Budgets)?
-
Do you know backup vs retention vs ASR differences?
-
Can you answer at least 5–10 practice questions per domain confidently?