AZURE ADMINISTRATOR (AZ-104)
QUESTIONS AND ANSWERS
The billing unit of Azure Services that aggregates all the costs of the underlying res
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ources. - ans-Azure Subscriptions
sw swsw sw
An identity in Azure Active Directory (AAD) or a directory that is trusted by AAD, su
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ch as a work or school organization. - ans-Azure Accounts
sw sw sw sw sw sw sw swsw sw
Also known as the account owner, this person is responsible for paying the subscrip
sw sw sw sw sw sw sw sw sw sw sw sw sw
tion bill to Microsoft when it is due. Normally, this user has financial responsibilities i
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
n your company such as CFO, Accounts Payable Lead etc. - ans-
sw sw sw sw sw sw sw sw sw sw swsw
Account Administrator sw
Also known as the Service Owner. This user manages the services that run in Wind
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ows Azure. They will have access to and uses the Window Azure Developer Portal
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
or Service Management API to orchestrate the applications and data running in Azur
sw sw sw sw sw sw sw sw sw sw sw sw
e. Normally, the user is a developer, system administrator, or other IT person respo
sw sw sw sw sw sw sw sw sw sw sw sw sw
nsible for IT services in your company. - ans-Service Administrator
sw sw sw sw sw sw sw swsw sw
When an enterprise becomes to large for a single Service Administrator, the Service
sw sw sw sw sw sw sw sw sw sw sw sw s
Administrator can create this role for other IT administrators to help them out. They
w sw sw sw sw sw sw sw sw sw sw sw sw sw sw
will have complete access to the subscription services. They can even add or delete
sw sw sw sw sw sw sw sw sw sw sw sw sw
other users in the same role. However, they cannot remove the Service Owner nor
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
do they have access to payment/billing information. - ans-Co-Administrators
sw sw sw sw sw sw sw swsw
The Microsoft recommended way to manage the permissions of your resources. Ho
sw sw sw sw sw sw sw sw sw sw sw
wever this will not work with Azure's classic deployment model. - ans-Role-
sw sw sw sw sw sw sw sw sw sw swsw
Based Access Control sw sw
Global Administrator - ans-
sw sw swsw
Users who are assigned this role can read and modify every administrative setting i
sw sw sw sw sw sw sw sw sw sw sw sw sw
n your Azure AD organization. By default this role is given to the user that signed u
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
p for the Azure subscription. It is one of the two roles that has an ability to delegate
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw s
administrator roles. To reduce the risk to your business, it is recommended by Micr
w sw sw sw sw sw sw sw sw sw sw sw sw sw
osoft that you assign this role to the fewest possible people in your organization.
sw sw sw sw sw sw sw sw sw sw sw sw sw
Application Developer - ans- sw sw swsw
Users in this role can create application registrations when the "Users can register a
sw sw sw sw sw sw sw sw sw sw sw sw sw
pplications" setting is set to No. This role also grants permission to consent on one'
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
,s own behalf when the "Users can consent to apps accessing company data on thei
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
r behalf" setting is set to No. Users assigned to this role are added as owners when
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
creating new application registrations or enterprise applications.
sw sw sw sw sw sw sw
Application Administrator - ans- sw sw swsw
This role grants the ability to manage application credentials. Users assigned this rol
sw sw sw sw sw sw sw sw sw sw sw sw
e can add credentials to an application, and use those credentials to impersonate th
sw sw sw sw sw sw sw sw sw sw sw sw sw
e application's identity.
sw sw
Authentication Administrator - ans-Users with this role can set or reset non-
sw sw swsw sw sw sw sw sw sw sw sw
password credentials and can update passwords for all users. Authentication Admini
sw sw sw sw sw sw sw sw sw sw
strators can require users to re-register against existing non-password credential
sw sw sw sw sw sw sw sw sw
Azure gives you the ability to see the number of resources you've deployed into you
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
r subscription and what your limits are. This ability makes it easier for you to track c
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
urrent usage and plan for new deployments in the near future. - ans-
sw sw sw sw sw sw sw sw sw sw sw swsw
Azure Resource Limits sw sw
A good way to keep track of your resources is through tagging them. Each "Tag" co
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
nsists of a Name and a Key Value Pair, such as
sw sw sw sw sw sw sw sw sw sw sw
"Environment" : "Production" where you could tag all your resources that are in prod
sw sw sw sw sw sw sw sw sw sw sw sw sw
uction. Tags applied to the resource group are not inherited by the resources in that
sw sw sw sw sw sw sw sw sw sw sw sw sw sw s
wresource group. - ans-Tagging Resources sw sw swsw sw
A service used to create, assign and manage different policies. These policies enfor
sw sw sw sw sw sw sw sw sw sw sw sw
ce different rules over your resources so they stay compliant with your corporate sta
sw sw sw sw sw sw sw sw sw sw sw sw sw
ndards and service level agreements, The service does this by running evaluations
sw sw sw sw sw sw sw sw sw sw sw sw
against your resources and scanning for those that are not in compliance with your
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
policies. - ans-Azure Policy sw swsw sw
A policy definition that has been assigned to take place within a specific scope. This
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
swscope could range from a management group to a resource group. The term scope
sw sw sw sw sw sw sw sw sw sw sw sw sw s
wrefers to all the resource groups, subscriptions, or management groups that the poli
sw sw sw sw sw sw sw sw sw sw sw sw
cy definition is assigned to. Policy assignments are inherited by all child resources.
sw sw sw sw sw sw sw sw sw sw sw sw sw
This design means that a policy applied to a resource group is also applied to resou
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
rces in that resource group. However, you can exclude a sub-
sw sw sw sw sw sw sw sw sw sw
scope from the policy assignment. - ans-Policy Assignment
sw sw sw sw sw swsw sw
A way to help simplify your policy management by reducing the number of policy de
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
finitions you create. You can define parameters when creating a policy to make it m
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ore generic. Then you can reuse that policy definition for different scenarios. You do
sw sw sw sw sw sw sw sw sw sw sw sw sw s
wso by passing in different values when assigning the policy definition. - ans-
sw sw sw sw sw sw sw sw sw sw sw swsw
Policy Parameters sw
A collection of policy definitions that are tailored towards achieving a singular overar
sw sw sw sw sw sw sw sw sw sw sw sw
ching goal. Initiative definitions simplify managing and assigning policy definitions. Th
sw sw sw sw sw sw sw sw sw sw
, ey simplify by grouping a set of policies as one single item. For example, you could
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw s
create an initiative titled Enable Monitoring in Azure Security Center, with a goal to
w sw sw sw sw sw sw sw sw sw sw sw sw sw sw
monitor all the available security recommendations in your Azure Security Center. -
sw sw sw sw sw sw sw sw sw sw sw
ans-Initiative Definition
swsw sw
Give you an ability to take an action any time an alert is triggered. This ensures tha
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
t every time an alert is triggered the same action will fire off, this could include a m
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
essaging componet (SMS, Push Notification, Email or Phone Call), A Function, or ev
sw sw sw sw sw sw sw sw sw sw sw sw
en running an automation playbook. - ans-Action Groups
sw sw sw sw sw swsw sw
Enables core monitoring for Azure Services by monitoring and visualizing metrics, qu
sw sw sw sw sw sw sw sw sw sw sw
erying and analysing activity and diagnostic logs. It's also can help set-
sw sw sw sw sw sw sw sw sw sw sw
up alerts and help you take automated corrective actions. - ans-Azure Monitor
sw sw sw sw sw sw sw sw sw swsw sw
Logs that are provided by the Azure Service that give useful data about the operatio
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
n of Azure Resources and Services. The Logs are constantly updating in real time t
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
o provide an accurate assesment of what is going on in the infrastructure. - ans-
sw sw sw sw sw sw sw sw sw sw sw sw sw swsw
Diagnostic Logs sw
Logs that contain activity that occurs at the tenant level but is outside of the Azure
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
subscription. - ans-Tenant Logs sw swsw sw
Platform logs emitted by Azure resources that describe their internal operation. They
sw sw sw sw sw sw sw sw sw sw sw s
are automatically generated by supported Azure resources, but they aren't collected
w sw sw sw sw sw sw sw sw sw sw s
unless you configure them using a diagnostic setting. Once you create a diagnostic
w sw sw sw sw sw sw sw sw sw sw sw sw sw
setting you can ship them directly either to the Log Analytics Workspace, Event Hub
sw sw sw sw sw sw sw sw sw sw sw sw sw s
or Azure Storage. - ans-Resource Logs
w sw sw sw swsw sw
Alert - ans- sw swsw
When a specific event occurs and you would like to be notified of when the event h
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
appens.
Numerical values that describe some aspect of a system at a particular point in time
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
. They are collected at regular intervals and are identified with a timestamp, a name,
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
a value, and one or more defining labels. Metrics can be aggregated using a variet
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
y of algorithms, compared to other metrics, and analyzed for trends over time. -
sw sw sw sw sw sw sw sw sw sw sw sw sw
ans-Metrics
swsw
Events that occurred within the system. They can contain different kinds of data and
sw sw sw sw sw sw sw sw sw sw sw sw sw s
may be structured or free form text with a timestamp. - ans-Logs
w sw sw sw sw sw sw sw sw sw sw swsw
Your current average performance levels and should be used to compare against yo
sw sw sw sw sw sw sw sw sw sw sw sw
ur future performance levels. Once a proper baseline has been determined you can
sw sw sw sw sw sw sw sw sw sw sw sw sw
properly monitor the performance of your resources. - ans-Performance Baseline
sw sw sw sw sw sw sw swsw sw
QUESTIONS AND ANSWERS
The billing unit of Azure Services that aggregates all the costs of the underlying res
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ources. - ans-Azure Subscriptions
sw swsw sw
An identity in Azure Active Directory (AAD) or a directory that is trusted by AAD, su
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ch as a work or school organization. - ans-Azure Accounts
sw sw sw sw sw sw sw swsw sw
Also known as the account owner, this person is responsible for paying the subscrip
sw sw sw sw sw sw sw sw sw sw sw sw sw
tion bill to Microsoft when it is due. Normally, this user has financial responsibilities i
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
n your company such as CFO, Accounts Payable Lead etc. - ans-
sw sw sw sw sw sw sw sw sw sw swsw
Account Administrator sw
Also known as the Service Owner. This user manages the services that run in Wind
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ows Azure. They will have access to and uses the Window Azure Developer Portal
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
or Service Management API to orchestrate the applications and data running in Azur
sw sw sw sw sw sw sw sw sw sw sw sw
e. Normally, the user is a developer, system administrator, or other IT person respo
sw sw sw sw sw sw sw sw sw sw sw sw sw
nsible for IT services in your company. - ans-Service Administrator
sw sw sw sw sw sw sw swsw sw
When an enterprise becomes to large for a single Service Administrator, the Service
sw sw sw sw sw sw sw sw sw sw sw sw s
Administrator can create this role for other IT administrators to help them out. They
w sw sw sw sw sw sw sw sw sw sw sw sw sw sw
will have complete access to the subscription services. They can even add or delete
sw sw sw sw sw sw sw sw sw sw sw sw sw
other users in the same role. However, they cannot remove the Service Owner nor
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
do they have access to payment/billing information. - ans-Co-Administrators
sw sw sw sw sw sw sw swsw
The Microsoft recommended way to manage the permissions of your resources. Ho
sw sw sw sw sw sw sw sw sw sw sw
wever this will not work with Azure's classic deployment model. - ans-Role-
sw sw sw sw sw sw sw sw sw sw swsw
Based Access Control sw sw
Global Administrator - ans-
sw sw swsw
Users who are assigned this role can read and modify every administrative setting i
sw sw sw sw sw sw sw sw sw sw sw sw sw
n your Azure AD organization. By default this role is given to the user that signed u
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
p for the Azure subscription. It is one of the two roles that has an ability to delegate
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw s
administrator roles. To reduce the risk to your business, it is recommended by Micr
w sw sw sw sw sw sw sw sw sw sw sw sw sw
osoft that you assign this role to the fewest possible people in your organization.
sw sw sw sw sw sw sw sw sw sw sw sw sw
Application Developer - ans- sw sw swsw
Users in this role can create application registrations when the "Users can register a
sw sw sw sw sw sw sw sw sw sw sw sw sw
pplications" setting is set to No. This role also grants permission to consent on one'
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
,s own behalf when the "Users can consent to apps accessing company data on thei
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
r behalf" setting is set to No. Users assigned to this role are added as owners when
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
creating new application registrations or enterprise applications.
sw sw sw sw sw sw sw
Application Administrator - ans- sw sw swsw
This role grants the ability to manage application credentials. Users assigned this rol
sw sw sw sw sw sw sw sw sw sw sw sw
e can add credentials to an application, and use those credentials to impersonate th
sw sw sw sw sw sw sw sw sw sw sw sw sw
e application's identity.
sw sw
Authentication Administrator - ans-Users with this role can set or reset non-
sw sw swsw sw sw sw sw sw sw sw sw
password credentials and can update passwords for all users. Authentication Admini
sw sw sw sw sw sw sw sw sw sw
strators can require users to re-register against existing non-password credential
sw sw sw sw sw sw sw sw sw
Azure gives you the ability to see the number of resources you've deployed into you
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
r subscription and what your limits are. This ability makes it easier for you to track c
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
urrent usage and plan for new deployments in the near future. - ans-
sw sw sw sw sw sw sw sw sw sw sw swsw
Azure Resource Limits sw sw
A good way to keep track of your resources is through tagging them. Each "Tag" co
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
nsists of a Name and a Key Value Pair, such as
sw sw sw sw sw sw sw sw sw sw sw
"Environment" : "Production" where you could tag all your resources that are in prod
sw sw sw sw sw sw sw sw sw sw sw sw sw
uction. Tags applied to the resource group are not inherited by the resources in that
sw sw sw sw sw sw sw sw sw sw sw sw sw sw s
wresource group. - ans-Tagging Resources sw sw swsw sw
A service used to create, assign and manage different policies. These policies enfor
sw sw sw sw sw sw sw sw sw sw sw sw
ce different rules over your resources so they stay compliant with your corporate sta
sw sw sw sw sw sw sw sw sw sw sw sw sw
ndards and service level agreements, The service does this by running evaluations
sw sw sw sw sw sw sw sw sw sw sw sw
against your resources and scanning for those that are not in compliance with your
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
policies. - ans-Azure Policy sw swsw sw
A policy definition that has been assigned to take place within a specific scope. This
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
swscope could range from a management group to a resource group. The term scope
sw sw sw sw sw sw sw sw sw sw sw sw sw s
wrefers to all the resource groups, subscriptions, or management groups that the poli
sw sw sw sw sw sw sw sw sw sw sw sw
cy definition is assigned to. Policy assignments are inherited by all child resources.
sw sw sw sw sw sw sw sw sw sw sw sw sw
This design means that a policy applied to a resource group is also applied to resou
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
rces in that resource group. However, you can exclude a sub-
sw sw sw sw sw sw sw sw sw sw
scope from the policy assignment. - ans-Policy Assignment
sw sw sw sw sw swsw sw
A way to help simplify your policy management by reducing the number of policy de
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
finitions you create. You can define parameters when creating a policy to make it m
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
ore generic. Then you can reuse that policy definition for different scenarios. You do
sw sw sw sw sw sw sw sw sw sw sw sw sw s
wso by passing in different values when assigning the policy definition. - ans-
sw sw sw sw sw sw sw sw sw sw sw swsw
Policy Parameters sw
A collection of policy definitions that are tailored towards achieving a singular overar
sw sw sw sw sw sw sw sw sw sw sw sw
ching goal. Initiative definitions simplify managing and assigning policy definitions. Th
sw sw sw sw sw sw sw sw sw sw
, ey simplify by grouping a set of policies as one single item. For example, you could
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw s
create an initiative titled Enable Monitoring in Azure Security Center, with a goal to
w sw sw sw sw sw sw sw sw sw sw sw sw sw sw
monitor all the available security recommendations in your Azure Security Center. -
sw sw sw sw sw sw sw sw sw sw sw
ans-Initiative Definition
swsw sw
Give you an ability to take an action any time an alert is triggered. This ensures tha
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
t every time an alert is triggered the same action will fire off, this could include a m
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
essaging componet (SMS, Push Notification, Email or Phone Call), A Function, or ev
sw sw sw sw sw sw sw sw sw sw sw sw
en running an automation playbook. - ans-Action Groups
sw sw sw sw sw swsw sw
Enables core monitoring for Azure Services by monitoring and visualizing metrics, qu
sw sw sw sw sw sw sw sw sw sw sw
erying and analysing activity and diagnostic logs. It's also can help set-
sw sw sw sw sw sw sw sw sw sw sw
up alerts and help you take automated corrective actions. - ans-Azure Monitor
sw sw sw sw sw sw sw sw sw swsw sw
Logs that are provided by the Azure Service that give useful data about the operatio
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
n of Azure Resources and Services. The Logs are constantly updating in real time t
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
o provide an accurate assesment of what is going on in the infrastructure. - ans-
sw sw sw sw sw sw sw sw sw sw sw sw sw swsw
Diagnostic Logs sw
Logs that contain activity that occurs at the tenant level but is outside of the Azure
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
subscription. - ans-Tenant Logs sw swsw sw
Platform logs emitted by Azure resources that describe their internal operation. They
sw sw sw sw sw sw sw sw sw sw sw s
are automatically generated by supported Azure resources, but they aren't collected
w sw sw sw sw sw sw sw sw sw sw s
unless you configure them using a diagnostic setting. Once you create a diagnostic
w sw sw sw sw sw sw sw sw sw sw sw sw sw
setting you can ship them directly either to the Log Analytics Workspace, Event Hub
sw sw sw sw sw sw sw sw sw sw sw sw sw s
or Azure Storage. - ans-Resource Logs
w sw sw sw swsw sw
Alert - ans- sw swsw
When a specific event occurs and you would like to be notified of when the event h
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
appens.
Numerical values that describe some aspect of a system at a particular point in time
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
. They are collected at regular intervals and are identified with a timestamp, a name,
sw sw sw sw sw sw sw sw sw sw sw sw sw sw
a value, and one or more defining labels. Metrics can be aggregated using a variet
sw sw sw sw sw sw sw sw sw sw sw sw sw sw sw
y of algorithms, compared to other metrics, and analyzed for trends over time. -
sw sw sw sw sw sw sw sw sw sw sw sw sw
ans-Metrics
swsw
Events that occurred within the system. They can contain different kinds of data and
sw sw sw sw sw sw sw sw sw sw sw sw sw s
may be structured or free form text with a timestamp. - ans-Logs
w sw sw sw sw sw sw sw sw sw sw swsw
Your current average performance levels and should be used to compare against yo
sw sw sw sw sw sw sw sw sw sw sw sw
ur future performance levels. Once a proper baseline has been determined you can
sw sw sw sw sw sw sw sw sw sw sw sw sw
properly monitor the performance of your resources. - ans-Performance Baseline
sw sw sw sw sw sw sw swsw sw