CBT Nuggets Flashcards

0.0(0)
studied byStudied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/218

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:26 PM on 6/1/23
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

219 Terms

1
New cards
The Azure support team will approve up to how many storage accounts?
250
2
New cards
If you have __**1000 unique users**__ in Active Directory,

600 users in one dynamic group,

and 800 users in another dynamic group,

what is the __**minimum number**__ of Azure AD Premium P1 licenses required?
1000
3
New cards
Which object is a __**pointer to an Azure file share**__

and represents an Azure fileshare

and one or more server endpoints?
A cloud endpoint

\
https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-deployment-guide?tabs=azure-portal%2Cproactive-portal
4
New cards
What type of group contains a list of __**security rules**__

that allow or deny __**network traffic**__

__**to resources**__ connected to Azure Virtual Networks (Vnet)?
Network Security Group (NSG)
5
New cards
If you accidentally delete or make changes to a file,

what can you use to __**restore individual files**__?
@@Recovery Point@@

\
https://learn.microsoft.com/en-us/azure/backup/backup-azure-restore-files-from-vm
6
New cards
Which object __**defines**__ the __**sync topology**__

for a __**set of files**__

in an @@Azure File Sync@@?
%%Sync Group%%
7
New cards
Which cmdlet

__**adds a network interface configuration**__

to the VM Scale Set configuration?
Add-AzRmVmssNetworkInterfaceConfiguration

\
https://learn.microsoft.com/en-us/powershell/module/az.compute/add-azvmssnetworkinterfaceconfiguration?view=azps-10.0.0
8
New cards
Horizontal Scaling
when you add more VMs
9
New cards
Vertical Scaling
when you increase the size (resources) on the VM
10
New cards
Which cmdlet uploads a VHD to a container

in your storage account?
Add-@@AzVhd@@

\
https://learn.microsoft.com/en-us/azure/devtest-labs/devtest-lab-upload-vhd-using-storage-explorer
11
New cards
Before deploying a __**web app**__,

you must create a ____________ in your ***resource group***

to support the deployment of the web app.
App Service plan.

\
https://learn.microsoft.com/en-us/azure/app-service/app-service-plan-manage
12
New cards
What type of license is required

to enable **dynamic group** membership

for users in Azure Active Directory?
Azure AD @@Premium P1@@ license.
13
New cards
Which admin **role** can **create** and **manage** all aspects of:

* enterprise applications,
* application registrations,
* application proxy settings?
%%Application%% Administrator
14
New cards
Can you move Azure resources

%%linked to an HDInsight cluster%%

across subscriptions?

(such as the virtual network, NIC, or load balancer)
No.

\
As of March 2021, you cannot. However, you can move HDInsight to a new subscription or resource group.
15
New cards
Why is there __no impact__ on production workloads

__during__ the __backup__ of an Azure VM?
As part of the backup process, a __**snapshot**__ is taken, and the __**data is transferred**__ to the @@*Recovery Services Vault*@@ with no impact on production workloads.
16
New cards
Which CLI command

will create an __app__ __service__ plan

to host your web app?
Az %%**appservice plan**%% create
17
New cards
Which CLI command is used

to create a new custom role?
az %%role definition%%
18
New cards
Which Azure CLI command

encryptes a running VM?
az %%vm encryption enable%%
19
New cards
Which ***tool*** enables you to

__**query role assignments**__ at a specific resource,

which includes role assignments for all resources?
Azure AD __**Privileged Identity Management**__
20
New cards
What authentication types are available

when creating a __**virtual network gateway**__
* Azure ==Certificate==
* RADIUS authentication
21
New cards
What tools can you use besides

Azure Portal and PowerShell

to move a DNS zone to another subscription?
* Azure CLI
* REST API
22
New cards
What feature allows you to __**share**__ resources

such as __**images**__ and __**applications**__ with everyone

or limit sharing to different users, service principals,

or AD groups within your organization?
Azure @@Compute Gallery@@

\
An Azure Compute Gallery (formerly known as Shared Image Gallery) simplifies sharing resources, like __**images**__ and __**application packages,**__ across your organization.

The Azure Compute Gallery lets you __**share**__ custom VM images and application packages with others in __**your organization**__, __**within or across regions**__, within a __**tenant**__.
23
New cards
Which Azure service manages

your hosted Kubernetes environment,

making it quick and easy to deploy, and

manages containerized applications

without container orchestration expertise?
Azure Kubernetes Service (AKS)
24
New cards
Which __**service**__ allows you to __**load balance services**__ on multiple ports, multiple IP addresses, or both?
Azure ==Load Balancer==
25
New cards
What are three different options

to distribute network traffic using Microsoft Azure?
* Azure Load Balancer,
* Application Gateway,
* Traffic Manager
26
New cards
Which Azure service

in the ==Operations Management Suite== (OMS)

__monitors__ your __on-premises__ environment and __cloud__ environment for ***availability*** and ***performance***?
Azure %%Log Analytics%%
27
New cards
Which **template** consists of __*JSON*__ and __*expressions*__ that you can use to __*construct values*__ for your Azure **deployment**?
Azure Resource Manager (***ARM***) template
28
New cards
What happens when you ==redeploy== a VM?
Azure will __**shut down**__ the VM, __**move**__ the VM __**to**__ a __**new node**__ within the Azure infrastructure,

and then power it back on, __*retaining*__ all your __*configuration*__ options and __*associated*__ __*resources*__.
29
New cards
Which built-in role for Azure resources allows you to **manage** __backup services,__ **except for:**

* the removal of backups,
* vault creation,
* giving access to others?
Backup Operator
30
New cards
Which RBAC (Role-Based Access Control) role has

permissions to everything a **Backup Contributor** does

except for removing backup and managing backup policies
Backup Operator

\
The __**Backup Contributor**__ can:

* Remove backups
* Manage backup policies
31
New cards
Which role can view backup services

but __*cannot*__ make changes?
Backup Reader
32
New cards
Which type of alerts

notify recipients when cost __*exceeds*__

a **predefined** or **forecasted** amount?
Budget alerts
33
New cards
Which user role has the same permissions as the Application Administrator role,

except for the ability to manage __*application*__ __*proxy*__ __*settings*__.
==Cloud Application== Administrator

\
cannot manage Application Proxy settings.
34
New cards
Users with which role have management permissions

within the ==Office 365 Security & Compliance Center==

and ^^Exchange Admin Center^^?
%%Compliance%% Administrator
35
New cards
What service in Azure is a __**global**__ solution

for __**delivering high-bandwidth content**__

that is __**hosted**__ in the local Azure region or any other location?
Content Delivery Network (CDN)
36
New cards
What type of connection in Azure uses a ==private==,

@@dedicated connection@@ through a ***third-party*** connectivity provider?
ExpressRoute
37
New cards
Which Azure service lets you create %%__**private connections**__%%

__**between**__ Microsoft __**datacenters**__ and infrastructure

that is __**on**__-__**premises**__ or in a colocation facility?
%%ExpressRoute%%
38
New cards
How many __**name-servers**__ does

Azure DNS __assign__ for __each zone__?
==Four==
39
New cards
Which element in the ARM template do you use to configure ==user-defined functions==?
Functions
40
New cards
Which role can manage

Azure Active Directory %%**B2B** **guest**%% user %%**invitations**%%

when the Members can invite user setting is set to No?
%%***Guest Inviter***%% admin role
41
New cards
What kind of Azure ==**VPN gateway**==

should you use to connect **25 on-premises sites**

to **one** Azure %%**site-to-site**%% **VPN gateway**?
==High-performance== %%VPN gateway%%
42
New cards
Which admin __Role__ can __monitor__

@@__notifications__@@ and %%__advisory health updates__ %%

in Office 365 Message Center

for their organization on

* Exchange,
* Intune,
* Microsoft Teams,
* and other configured services?
Message Center Reader
43
New cards
Which component of __Log Analytics__

is a @@cloud-based network monitoring solution@@

that monitors connectivity between

%%Azure cloud deployments%% and

on-premises locations (branch offices, etc.)?
^^Network Performance Monitor^^ (NPM),

now Connection Monitor
44
New cards
Which cmdlet allows you to __determine__ the __scope__ in which a @@policy definition can be used@@?
New-%%AzPolicyAssignment%%
45
New cards
Which cmdlet is used to create a __**snapshot**__ __**configuration**__?
New-%%AzSnapshotConfig%%
46
New cards
What cmdlet is used to create a __**file share**__ in Azure Files?
New-%%AzStorageShare%%
47
New cards
Can you create a __**device group**__

based on the

__**device owners' attributes**__?
No
48
New cards
Is it possible to __**disable**__

Azure Storage __**encryption**__?
No
49
New cards
Does an __**Application Gateway**__

support **multiple public IPs** on the gateway?
No, an application gateway supports __**only one**__ public IP address.
50
New cards
Does __object replication__ in Azure

synchronously ==**copy block blobs** ==between

a source %%**storage**%% **account** and a %%**destination**%% account?
**No**, it %%**asynchronously**%% copies block blobs between

a source storage account and a destination account.
51
New cards
For the __v2 SKU__,

are __UDRs__ supported on the __application gateway__ subnet?
No, __only__ in the __v1__ SKU
52
New cards
With Azure %%**Site Recovery**%%,

can you replicate data @@over a VPN@@?
**No**,

you can __only__ replicate data __over the public internet__ with

__ExpressRoute__ (Microsoft peering or an existing public peering).

VPN does not work.
53
New cards
Do __ExpressRoute__ connections

go over the __public__ __internet__?
No.
54
New cards
Is the Azure __**Compute Gallery**__ service

a __**global**__ resource?
**No**.

Although it supports global replication, it is a best practice to have at least two galleries in different regions for disaster recovery scenarios.
55
New cards
Does ==__**Azure Relay**__==

use the same %%network-level integration%% technologies

as VPN?
No.

An Azure relay is __**scoped to a** %%**single application endpoint**%% **on a** %%**single machine**%%__ while the VPN technology relies on altering the network environment.

\
https://learn.microsoft.com/en-us/azure/azure-relay/relay-what-is-it

https://www.youtube.com/watch?v=HBsCTqjo_lY
56
New cards
Are Azure Backup reports available for

Azure SQL Database, Azure File Shares, Data Protection Manager,

and Azure Backup server?
No.

At the time of this writing, Azure Backup reports are NOT available for Azure SQL Database, Azure File Shares, Data Protection Manager, and Azure Backup server.
57
New cards
Does @@Vnet-to-Vnet traffic@@ travel across the internet?
No.

It __only__ %%travels%% __across__

the @@Microsoft@@ Azure @@backbone@@.
58
New cards
Can you disable a printer

in Azure Active Directory?
No.

You cannot disable or enable a printer in Azure Active Directory
59
New cards
How often does Azure Storage

__check__ the @@key vault@@ for a __new__ __version__?
Once daily
60
New cards
Which resource allows Azure resources to

%%communicate%% with other resources

in a virtual network or an on-premises network

through a VPN gateway or ExpressRoute circuit,

__**without**__ using an __**Internet-reachable IP**__ address?
Private IP resource
61
New cards
What are the two options for configuring MFA to Azure resource role assignments in Azure AD @@Privileged Identity Management@@ (PIM)?

1. Require MFA on @@active assignment@@
2. Require MFA on %%activation%%
62
New cards
After using Azure Admin,

why is it recommended to @@apply resizing@@ to VMs

after business hours?
@@Resizing@@ %%requires%% an actively running VM to @@restart@@
63
New cards
In role-based access control (RBAC),

what is the term for the collection of operations

that can be performed,

such as read, write, and delete?
@@Role@@ %%definition%%
64
New cards
Which type of %%alerts%% notifies recipients about the @@latest costs@@ on a daily, weekly, or monthly __schedule__ based on a saved cost view
@@Scheduled@@ %%alerts%%
65
New cards
What cmdlet can you use to

@@redeploy@@ a Windows VM?
Set-@@AzureRmVM@@
66
New cards
Which __PowerShell__ cmdlet @@encrypts@@ a running VM?
Set-%%AzVMDiskEncryptionExtension%%
67
New cards
What PowerShell command

must you run on the target VM

to __enable__ @@inbound@@ connections

to port 5985 for WinRM

over HTTP for WinRM access?
Set-NetFirewallRule

\-Name WINRM-HTTP-In-TCP-PUBLIC

\-RemoteAddress Any
68
New cards
Which __type__ of __policy__ allows you to

__change__ the %%start time%%, %%expiry time%%, or %%permissions%%

for a @@Shared Access Signature@@ (SAS)?
@@Stored@@ %%Access%% policy
69
New cards
Method to setup __**Keys**__ and __**Values**__ around __**Labels**__,

such as intended use, projects, and cost centers,

to @@provide insight@@ into your environment

and %%track usage%%?
Tagging
70
New cards
A file used with the %%Azure Import/Export service%%

that lists __**disks**__ and corresponding __**drive letters**__

so that the %%Azure Import/Export%% can

correctly __**pick**__ the __**list**__ of __**disks**__ to be prepared
@@Driveset.csv@@
71
New cards
When creating a @@Recovery Services Vault@@

for replicating VMs,

which region cannot be used?
The @@same region@@

from which you want to

replicate the VMs.
72
New cards
Which tier for the __App Service plan__ allows each app to receive a quota of CPU minutes, and @@charges each app@@ %%for its portion%% of the CPU quota?
Shared tier
73
New cards
Which parameter should you use with the

***New-AzResourceGroupDeployment*** cmdlet

to __redeploy__ an %%earlier successful deployment%%

if your current deployment fails
To specify a redeployment,

use either the

@@-RollbackToLastDeployment@@

or

%%-RollBackDeploymentName%%

parameters in the deployment command
74
New cards
What is the __health status__

of your Standard load balancer

if the Datapath Availability metric

has reported @@less than 25% health@@

for at least %%two minutes%%?
Unavailable
75
New cards
Which __type__ of __routing__

allows you to route traffic

to %%back-end server pools%%

based on the __URL paths__ of the request?
@@URL-based@@ routing
76
New cards
To enable %%customer-managed keys%%

on a @@storage account@@,

where must you __store__ your __keys__?
Azure @@Key Vault@@
77
New cards
What are the __three types__ of

@@shared access signatures@@

supported by Azure Storage?

1. @@User delegation@@ SAS,
2. Service SAS,
3. %%Account%% SAS
78
New cards
When using the %%Azure Import/Export%% service,

which __tool__ would you use

to @@copy data to disk@@ drives?
WAImportExport
79
New cards
What type of traffic

can be __load balanced__ by an

%%application gateway%%?
%%Web traffic%% (HTTP, HTTPS, WebSocket, and HTTP/2)
80
New cards
Why does using

Azure CDN streaming endpoints

minimize data transfer costs?
When Azure CDN is enabled for a streaming endpoint, @@data transfer charges do not apply@@ because data transfers are charged at data transfer pricing, and Azure CDN is not enabled for a streaming endpoint by default.
81
New cards
What are the three methods for

deploying Azure AD Join?

1. ==Windows Autopilot==
2. Bulk Deployment
3. %%Self-Service Experience%%
82
New cards
Can ==virtual machines== with

certificates stored in Key Vault

be @@moved to a new resource group@@

in the %%same subscription%%?
Yes
83
New cards
Can %%virtual machines%% with ==managed disks==

be moved to a new resource group and subscription?
Yes
84
New cards
Can you create a %%copy of a managed disk%%

and then @@create a new virtual machine@@

from the newly created managed disk?
Yes
85
New cards
Can you move %%Azure-managed disks%%?
Yes
86
New cards
Can you use a %%free certificate%%

to secure your custom DNS name

in ==App Service==
Yes
87
New cards
Do you receive the %%single sign-on%% feature

for Active Directory

if you choose the ==Free Azure AD== edition

instead of a Premium P1 edition?
Yes
88
New cards
Can you use ExpressRoute

to replicate on-premises virtual machines to Azure?
Yes,

%%ExpressRoute%% can be used to replicate on-premises virtual machines to Azure
89
New cards
Can %%custom roles%% be assigned

at the scope of a single Azure AD resource?
Yes,

they can be assigned at the ==scope of a single Azure AD== resource,

or they can be assigned at the %%default organization-wide scope%%

to grant access permissions over all app registrations in your organization.
90
New cards
How many Custom Roles can you create?
There is a limit of 5,000 custom roles per tenant.

\
If the Azure built-in roles don't meet the specific needs of your organization, you can create your own custom roles. Just like built-in roles, you can assign custom roles to users, groups, and service principals at management group, subscription, and resource group scopes.
91
New cards
Do ==premium and Isolated tiers==

allow a %%greater number of daily backups%%

than Standard tier?
Yes.
92
New cards
Can you replicate VMs enabled through disk encryptions to another subscription with Site Recovery
Yes.

==Site Recovery== %%supports disaster recovery of VMs with Azure disk encryption%% (ADE) enabled. You can replicate Azure VMs to a different subscription as long as the subscription is within the same Azure AD tenant.
93
New cards
Can you only sync with other services and Azure file shares that use the same Storage Sync Service
TRUE

You can %%only sync Azure File Shares%%

and ==other services==

that use the same Storage Sync Service.
94
New cards
Each resource can only exist in one resource group
TRUE
95
New cards
True or False: When adding a network interface to an existing VM, the %%network interface cannot have accelerated networking enabled%%, ==cannot have an IPv6 address assigned== to it, and must exist in the same virtual network as the one that contains the network interface currently attached to the VM.
TRUE
96
New cards
You can create a dynamic group for devices or for users, but you cannot create a rule that contains create a rule that contains both users and devices.
TRUE
97
New cards
All the resources in your group MUST share the same lifecycle.

\
False
False, although it is highly recommended that all resources have the same lifecycle so that you can deploy, update, and delete them together, it is not required.
98
New cards
If you define action tierToCool and action tierToArchive on the same block, which action is applied?

\
Least expensive action wins
Action tierToArchive is applied since it is the least expensive action
99
New cards
Which option under Support+Troubleshooting

should you choose to view the logs

and see a screenshot of your VM from the hypervisor?
%%Boot Diagnotics%%
100
New cards
What does it mean

when a subscription is locked

with the level ReadOnly?
Authorized users can read a resource,

but they cannot %%delete%% or %%update%% the resource