Looking for your active Pro access before showing Course Notes. This usually takes just a moment.
Course Notes preview
Unlock Pro for the full per-exam reference guide.
Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.
Includes full Course Mode and Course Notes.
Section 1Networking FoundationsPreview
More in this section
2 more summary sections in Pro version
11 more key points in Pro version
5 more common mistakes in Pro version
5 more exam tips in Pro version
41 more related questions in Pro version
Summary
The exam tests the foundational networking components within Azure, critical for designing secure and scalable solutions. Understanding how to isolate workloads, manage IP addressing, and control DNS resolution is essential for architecting reliable Azure environments.
Key Points
**Azure Virtual Network Isolation:** Virtual networks provide logical isolation for your Azure resources, allowing you to define address spaces, subnets, and network security groups (NSGs) to control traffic flow. Think of them as your own private networks within Azure.
Common Mistakes
**Virtual Network vs. NSG:** Virtual networks provide isolation; NSGs control traffic *within* that isolation.
Exam Tips
Prioritize solutions that leverage managed services like NAT Gateway and Azure DNS Private Resolver to reduce operational overhead.
Section 2Connectivity ServicesPreview
More in this section
2 more summary sections in Pro version
8 more key points in Pro version
4 more common mistakes in Pro version
4 more exam tips in Pro version
29 more related questions in Pro version
Summary
The exam tests Azure's connectivity services, which are critical for securely connecting on-premises networks to Azure and managing network traffic within Azure. Understanding these services is essential for hybrid cloud deployments and ensuring reliable application access.
Key Points
**Active-Active VPN Gateways:** An Azure VPN gateway contains gateway VM instances. In active-active mode, both instances use separate public IP addresses and establish tunnels to the on-premises VPN device, improving availability within one gateway rather than distributing traffic across separate gateways.
Common Mistakes
**VPN Gateway vs. ExpressRoute:** VPN Gateways use the public internet, while ExpressRoute provides a dedicated private connection. VPN is generally more cost-effective for lower bandwidth needs, while ExpressRoute is preferred for high bandwidth and stringent security requirements.
Exam Tips
Carefully read the scenario and identify the key requirements (bandwidth, redundancy, security) before selecting a solution.
Section 3Application DeliveryPreview
More in this section
2 more summary sections in Pro version
11 more key points in Pro version
4 more common mistakes in Pro version
5 more exam tips in Pro version
25 more related questions in Pro version
Summary
The exam tests application delivery services in Azure, which are critical for ensuring applications are accessible, scalable, and resilient. These services handle traffic management, routing, and security at various layers, from the transport layer (Layer 4) to the application layer (Layer 7). Understanding the nuances of each service and when to use them is essential for designing robust and efficient Azure solutions.
Key Points
**Azure Load Balancer:** Distributes traffic within a region across multiple VMs or instances. It operates at Layer 4 (transport layer) and is ideal for distributing traffic based on IP address and port.
Common Mistakes
**Azure Load Balancer vs. Application Gateway:** Load Balancer operates at Layer 4, while Application Gateway operates at Layer 7. This dictates the routing capabilities available.
Exam Tips
Carefully read the scenario and identify the key requirements. Look for keywords like 'Layer 7 routing,' 'NVA integration,' or 'global distribution.'
Section 4Private AccessPreview
More in this section
2 more summary sections in Pro version
8 more key points in Pro version
3 more common mistakes in Pro version
4 more exam tips in Pro version
15 more related questions in Pro version
Summary
The exam tests enabling private access to Azure services, a critical aspect of network security and compliance. Private access solutions ensure that traffic to Azure services remains within the Microsoft backbone network, avoiding exposure to the public internet. This is particularly important for organizations with strict regulatory requirements or those prioritizing data sovereignty.
Key Points
**Private Endpoint:** Creates a network interface within your virtual network that provides a private IP address for an Azure PaaS service (e.g., Azure SQL Database, Azure Storage). This effectively brings the service closer to your network.
Common Mistakes
**Private Endpoint vs. Service Endpoint:** Private Endpoints create a private IP address and network interface in your VNet and can use Private DNS. Service Endpoints keep the Azure service endpoint publicly routable while using the Azure backbone and virtual network identity to secure access from a subnet.
Exam Tips
Prioritize Private Endpoints when strict network isolation is required.
Section 5Network SecurityPreview
More in this section
2 more summary sections in Pro version
9 more key points in Pro version
4 more common mistakes in Pro version
4 more exam tips in Pro version
25 more related questions in Pro version
Summary
The exam tests securing Azure networks, a critical aspect of cloud infrastructure. It covers various services and configurations used to protect virtual networks, virtual machines, and applications from threats. Understanding these services is essential for maintaining confidentiality, integrity, and availability of data and resources.
Key Points
**NSG Default Inbound Rules:** Azure automatically creates default inbound rules, including `DenyAllInbound` (priority 65500) which blocks all inbound traffic not explicitly allowed by higher-priority rules, and `AllowAzureLoadBalancerInBound` which permits inbound traffic from Azure Load Balancers.
Common Mistakes
**NSGs vs. Azure Firewall:** NSGs are stateful subnet/NIC-level packet filters built around source, destination, port, protocol, and priority. Azure Firewall is a fully stateful managed firewall with network, application, and NAT rules, threat intelligence, central policy management, and SKU-dependent inspection capabilities.
Exam Tips
Prioritize understanding the default NSG rules and how they impact connectivity.
Search catalog
Find a practice exam
Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.