AZ-900 Learning Portal

Last-Minute Review

The most-tested facts across AZ-900 — read this the morning of your exam

Domain 1 — Cloud Concepts

1

CapEx vs OpExOn-prem = capital expenditure (upfront). Cloud = operational expenditure (pay-as-you-go). AZ-900 loves this distinction.

2

Consumption-based modelYou pay only for the resources you use. No upfront cost, no wasted idle capacity.

3

High availabilityUptime guarantee expressed as an SLA percentage (e.g. 99.9%). Azure achieves this through redundancy and geo-replication.

4

Scalability vs ElasticityScalability = ability to grow. Elasticity = automatically scaling up AND down in response to demand.

5

IaaS / PaaS / SaaSIaaS: you manage OS and up. PaaS: you manage app and data only. SaaS: you just use the software (e.g. Microsoft 365).

6

Shared responsibilityThe cloud provider always owns physical security. Identity and data always remain the customer's responsibility regardless of model.

7

Public vs Private vs Hybrid cloudPublic = hosted by provider, open to all. Private = dedicated to one org. Hybrid = both connected together.

Domain 2 — Azure Architecture & Services

1

Regions and Availability ZonesA region is a geographic area with multiple datacenters. Availability Zones are physically separate buildings within a region (min. 3 per region).

2

Region PairsAzure pairs regions within the same geography for disaster recovery. Updates are rolled out to one region at a time.

3

Azure Resource Manager (ARM)Every action in Azure goes through ARM. It's the management layer that authenticates and routes all requests.

4

Azure Virtual Machines vs Azure App ServiceVMs = IaaS (you control the OS). App Service = PaaS (you only deploy your app code).

5

Azure Blob Storage tiersHot (frequent access) → Cool (infrequent, 30-day min) → Cold (rare access, 90-day min) → Archive (offline, 180-day min). Lower tiers = cheaper storage, higher retrieval cost.

6

Azure Entra ID vs Active DirectoryEntra ID is cloud identity (OAuth 2.0/OIDC). On-prem AD uses Kerberos/LDAP. They are different products — Entra ID is NOT AD in the cloud.

7

Azure Defender for CloudProvides security posture management (CSPM) and workload protection (CWPP). Shows a Secure Score based on recommendations.

Domain 3 — Azure Management & Governance

1

Azure PolicyEnforces organizational standards and assesses compliance. Can audit, deny, or auto-remediate non-compliant resources.

2

Management hierarchyManagement Groups > Subscriptions > Resource Groups > Resources. Policies applied at a Management Group flow down to everything beneath it.

3

Azure Cost ManagementFree tool for analyzing spend, setting budgets, and creating alerts. Use cost analysis to see breakdowns by service, resource, or tag.

4

Azure Monitor vs Azure AdvisorMonitor = collects metrics and logs, sets alerts. Advisor = gives personalized best-practice recommendations across cost, security, reliability, performance, and operational excellence.

5

Azure Service HealthThree components: Azure Status (global outages), Service Health (your subscription's services), Resource Health (individual resources).

6

TagsKey-value pairs applied to resources for billing, governance, and automation. Tags are NOT inherited by resources inside resource groups by default.

7

Microsoft PurviewUnified data governance platform. Key use: classifying and governing data across your entire estate. Not just a compliance tool.

If you score ≥80% on the final mock, you're ready.

Go pass it.

Go to Practice →