AZ-104 Stormwind Studio Certification Course Notes
Day 1.1 - Introduction
AZ-104 Exam
Exam Page (opens in a new tab)
You
- Microsoft Says:
- "As a candidate for this exam, you should have subject matter expertise in implementing, managing, and monitoring an organization's Microsoft Azure environment, including virtual networks, storage, compute, identity, security, and governance. As an Azure administrator, you often serve as part of a larger team dedicated to implementing an organization's cloud infrastructure. You also coordinate with other roles to deliver Azure networking, security, database, application development, and DevOps solutions."
You - Microsoft Recommended Prerequisites
- You should be familiar with:
- Operating systems
- Networking
- Servers
- Virtualization
- PowerShell
- Azure CLI
- The Azure portal
- Azure Resource Manager templates
- Microsoft Entra ID
AZ-104 Exam Objectives
- Manage Azure Identities and Governance 20-25%
- Implement and manage storage 15-20%
- Deploy and manage Azure compute resources 20-25%
- Implementing and manage virtual networking 15-20%
- Monitor and maintain Azure Resources 10-15%
Manage Azure Identities and Governance 20-25%
- Entra ID Users and Groups
- Creation
- Management
- Roles
- Licenses
- Authentication
- Azure Resources
- Azure Roles
- Azure Scopes
- Azure Subscriptions and Governance
- Azure Policies
- Resource Locks
- Tags
- Resource Groups
- Subscriptions
- Costs and Budgeting
- Management Groups
Implement and Manage Storage 15-20%
- Configure Access to Storage
- Configure Azure Storage firewalls and virtual networks
- Create and use Shared Access Signature tokens
- Configure Stored Access policies
- Manage Access Keys
- Configure identity-based access for Azure Files
- Configuring and Managing Data in Storage Accounts
- Create and Configure Storage Accounts
- Configure Azure Storage redundancy
- Configure object replication
- Configure storage account encryption
- Manage data by using Azure Storage Explorer and AzCopy
- Configure Azure Files and Azure Blob Storage
- Create and configure file shares in Azure Storage
- Configure a container in Azure Blob Storage
- Configure Storage tiers
- Configure snapshots and soft delete for Azure Files
- Configure blob Lifecycle management
- Configure Blob Versioning
Deploy and Manage Azure Compute Resources 20-25%
- Automate deployment of resources by using Azure Resource Manager (ARM) templates or Bicep files
- Interpret an Azure Resource Manager template or a Bicep file
- Modify an existing Azure Resource Manager template
- Modify an existing Bicep file
- Deploy resources by using an Azure Resource Manager template or a Bicep file
- Export a deployment as an Azure Resource Manager template or convert an Azure Resource Manager template to a Bicep file
- Create and configure virtual machines
- Create a virtual machine
- Configure Azure Disk Encryption
- Move a virtual machine to another resource group, subscription, or region
- Manage virtual machine sizes
- Manage virtual machine disks
- Deploy virtual machines to availability zones and availability sets
- Deploy and configure an Azure Virtual Machine Scale Sets
- Provision and manage containers in the Azure portal
- Create and manage an Azure container registry
- Provision a container by using Azure Container Instances
- Provision a container by using Azure Container Apps
- Manage sizing and scaling for containers, including Azure Container Instances and Azure Container Apps
- Create and configure Azure App Services
- Provision an App Service plan
- Configure scaling for an App Service plan
- Create an App Service
- Configure certificates and Transport Layer Security (TLS) for an App Service
- Map an existing custom DNS name to an App Service
- Configure backup for an App Service
- Configure networking settings for an App Service
- Configure deployment slots for an App Service
Implement and Manage Virtual Networking 15-20%
- Configure and manage virtual networks in Azure
- Create and configure virtual networks and subnets
- Create and configure virtual network peering
- Configure public IP addresses
- Configure user-defined network routes
- Troubleshoot network connectivity
- Configure secure access to virtual networks
- Create and configure network security groups (NSGs) and application security groups
- Evaluate effective security rules in NSGs
- Implement Azure Bastion
- Configure service endpoints for Azure platform as a service (PaaS)
- Configure private endpoints for Azure PaaS
- Configure name resolution and load balancing
- Configure Azure DNS
- Configure an internal or public load balancer
- Troubleshoot load balancing
Monitor and Maintain Azure Resources 10-15%
- Monitor Resources in Azure
- Interpret metrics in Azure Monitor
- Configure log settings in Azure Monitor
- Query and analyze logs in Azure Monitor
- Set up alert rules, action groups, and alert processing rules in Azure Monitor
- Configure and interpret monitoring of virtual machines, storage accounts, and networks by using Azure Monitor Insights
- Use Azure Network Watcher and Connection Monitor
- Implement Backup and Recovery
- Create a Recovery Services vault
- Create an Azure Backup vault
- Create and configure a backup policy
- Perform backup and restore operations by using Azure Backup
- Configure Azure Site Recovery for Azure resources
- Perform a failover to a secondary region by using Site Recovery
- Configure and interpret reports and alerts for backups
AZ-104 Exam Objectives
- Manage Azure Identities and Governance 20-25%
- Implement and manage storage 15-20%
- Deploy and manage Azure compute resources 20-25%
- Implement and manage virtual networking 15-20%
- Monitor and maintain Azure Resources 10-15%