← Back to Portal
AZ-104 Study Material
Flashcards
20 flip-card flashcards from the validated question bank, plus per-domain summary anchors.
Question → Answer Cards
Monitor & Maintain
Recovery Point Objective (RPO) in ASR indicates:
Click to reveal answer
Monitor & Maintain
RPO is the maximum age of data that can be lost during a failure.
Click to flip back
Monitor & Maintain
Instant restore for Azure VM backup provides:
Click to reveal answer
Monitor & Maintain
Instant restore uses snapshot tier for faster RTO while full backup processes.
Click to flip back
Identity & Governance
Entra Connect is configured in staging mode on a standby server. What happens if the primary server fails?
Click to reveal answer
Identity & Governance
Staging mode server holds a copy of synced objects; failover requires manual activation of the staging server.
Click to flip back
Storage
Contoso needs zone redundancy in the primary region AND geo-replication to a secondary region. Which SKU?
Click to reveal answer
Storage
Geo-zone-redundant storage (GZRS/RA-GZRS) combines ZRS in primary with async replication to secondary.
Click to flip back
Compute
When upgrading VMSS instances with minimal downtime, you use:
Click to reveal answer
Compute
Rolling upgrades update instances in batches to maintain availability.
Click to flip back
Storage
A stored access policy on a container allows you to:
Click to reveal answer
Storage
Stored access policies group SAS permissions; revoking the policy invalidates associated SAS tokens.
Click to flip back
Networking
Global VNet peering connects VNets in:
Click to reveal answer
Networking
Global peering spans regions; traffic stays on Microsoft network.
Click to flip back
Compute
Always On setting in App Service prevents:
Click to reveal answer
Compute
Always On keeps the app loaded; without it, idle apps may be unloaded on Basic+ plans.
Click to flip back
Networking
When using private endpoints for Storage, you should also:
Click to reveal answer
Networking
Private DNS zone linked to VNet resolves storage FQDN to private endpoint IP.
Click to flip back
Identity & Governance
You need a custom role that allows starting and stopping VMs but not deleting them. What is the first step?
Click to reveal answer
Identity & Governance
Custom roles define granular Actions/NotActions. VM start/stop/restart/deallocate actions without delete meet the requirement.
Click to flip back
Monitor & Maintain
Log query alert (scheduled query rule) triggers when:
Click to reveal answer
Monitor & Maintain
Log alerts run KQL on a schedule and fire based on result count/threshold.
Click to flip back
Networking
Active-active VPN gateway configuration provides:
Click to reveal answer
Networking
Active-active uses two gateway instances and multiple tunnels for resilience.
Click to flip back
Identity & Governance
An admin should have Global Administrator rights only when activated, with MFA and approval required. Which PIM configuration?
Click to reveal answer
Identity & Governance
PIM eligible assignments require just-in-time activation with configurable MFA, approval, and duration limits.
Click to flip back
Compute
Azure Disk Encryption (ADE) for Windows VMs uses:
Click to reveal answer
Compute
ADE integrates BitLocker (Windows) or DM-Crypt (Linux) with Key Vault.
Click to flip back
Monitor & Maintain
Workspace-based Application Insights links telemetry to:
Click to reveal answer
Monitor & Maintain
Workspace-based App Insights stores data in Log Analytics for KQL queries.
Click to flip back
Compute
Proximity placement groups ensure:
Click to reveal answer
Compute
PPGs colocate VMs for lowest network latency between them.
Click to flip back
Networking
Application Security Groups (ASGs) allow you to:
Click to reveal answer
Networking
ASGs simplify NSG rules by using application-centric group membership.
Click to flip back
Storage
Large file shares in Azure Files support up to:
Click to reveal answer
Storage
Large file shares scale up to 100 TiB per share when the feature is enabled on the account.
Click to flip back
Storage
Infrastructure encryption on a storage account provides:
Click to reveal answer
Storage
Infrastructure encryption adds a second layer of encryption at the storage service infrastructure.
Click to flip back
Identity & Governance
A policy should block legacy authentication protocols tenant-wide. Which condition should you configure?
Click to reveal answer
Identity & Governance
Legacy authentication is blocked by targeting 'Other clients' and Exchange ActiveSync under Client apps in Conditional Access.
Click to flip back
Domain Summary Cards
Domain Summary
Identity & Governance
High-yield exam facts
- Entra ID, RBAC, Policy, locks, tags, PIM, management groups
Domain Summary
Storage
High-yield exam facts
- Redundancy tiers, SAS, lifecycle, Files, private endpoints, immutability
Domain Summary
Compute
High-yield exam facts
- VMs, disks, VMSS, ARM/Bicep, ACI, Container Apps, App Service
Domain Summary
Networking
High-yield exam facts
- VNets, NSGs, peering, LB, Bastion, private endpoints, DNS
Domain Summary
Monitor & Maintain
High-yield exam facts
- Azure Monitor, Backup, ASR, Advisor, cost management