Practice Exams:

Cloud & Architecture

Microsoft AZ-104: Cost Governance for Azure Subscriptions

Azure cost governance is the operating system that makes cloud spend attributable, reviewable, and controllable before teams begin one-off optimization. Subscription structure, management groups, resource groups, tags, Cost Management, budgets, alerts, cost allocation, reservations, savings plans, Azure Policy, and ownership all contribute. The goal is to show who is spending, why the spend exists, which costs are shared, and who has authority to change the architecture that creates the cost. Microsoft’s current Cost Management guidance emphasizes resource hierarchy, tags and tag inheritance, budgets and alerts, cost analysis, and allocation rules….

Read More

Microsoft AZ-104: Azure Virtual Desktop Profile Design

Azure Virtual Desktop profile design determines whether users experience a consistent desktop when session hosts are pooled, replaced, patched, or scaled. Microsoft currently recommends FSLogix Profile Containers for Azure Virtual Desktop. The profile is stored in a VHD/VHDX container on remote storage and attached at sign-in so Windows sees it like a local profile even when the user lands on a different session host. The architecture is therefore more than “enable FSLogix.” Teams need to choose storage, identity and SMB permissions, capacity, redundancy, backup, profile size, exclusions, concurrency behavior, Cloud…

Read More

Microsoft AZ-104: Azure Route Server in Hybrid Networks

Azure Route Server is a managed BGP service that exchanges routes between the Azure software-defined network and network virtual appliances. It reduces the need to maintain large user-defined route tables when virtual firewalls, SD-WAN appliances, routers, or other NVAs need to learn Azure prefixes and advertise routes back into the virtual network. The architectural benefit is dynamic route exchange; the design challenge is understanding which routes propagate, which services participate, and where route limits or unintended transit can change the network. Microsoft’s current Route Server documentation describes a highly available…

Read More

Microsoft AZ-104: Azure RBAC Design for Platform Teams

Azure role-based access control works best when platform teams treat access as an architecture model instead of a collection of portal assignments. Every role assignment combines a principal, a role definition, and a scope. The security outcome therefore depends on choosing the smallest practical scope, the narrowest practical role, the right principal type, and an operating process that can review and remove access later. Microsoft’s current Azure RBAC best practices emphasize least privilege, limiting subscription Owners, minimizing privileged administrator assignments, using Microsoft Entra Privileged Identity Management, assigning roles to groups…

Read More

Microsoft AZ-104: Azure Policy Initiative Design

An Azure Policy initiative—also called a policy set—groups related policy definitions so they can be assigned, parameterized, versioned, and reported as one governance objective. The value is not simply fewer assignments. A well-designed initiative expresses a coherent outcome such as “production platform baseline,” “required logging,” “allowed regions,” or “secure storage,” with parameters and effects organized so platform teams can roll the baseline out safely and explain compliance results. Microsoft’s current Azure Policy model separates definitions from assignments. A definition contains the rule and effect; an initiative groups definitions; an assignment…

Read More

Microsoft AZ-104: Azure Monitor Data Collection Rules

Azure Monitor Data Collection Rules define how supported telemetry is collected, transformed, and sent to destinations. Microsoft describes the DCR model as an ETL-like data-collection process that standardizes configuration across Azure Monitor scenarios. Instead of embedding collection details separately in every agent or resource, a DCR can define data sources, data streams, transformations, and destinations, while Data Collection Rule Associations connect resources to the appropriate rule. DCRs are now foundational to many Azure Monitor Agent scenarios, custom log ingestion, transformations, and other modern collection paths. Data Collection Endpoints are related…

Read More

Microsoft AZ-104: Azure Load Balancer or Application Gateway?

Azure Load Balancer and Azure Application Gateway both distribute traffic, but they operate at different layers and solve different problems. Azure Load Balancer is a regional Layer 4 service for TCP and UDP. Application Gateway is a regional Layer 7 service for web traffic and can make routing decisions based on HTTP properties, terminate TLS, host multiple sites, route by URL path, and provide Web Application Firewall functionality through the WAF_v2 SKU. Microsoft’s current networking guidance is explicit: choose Load Balancer when you need regional TCP/UDP distribution without application awareness;…

Read More

Microsoft AZ-104: Availability Zones and Failure Domains

Azure Availability Zones are separate groups of datacenters within a region, with independent power, cooling, and networking designed to reduce the chance that one local failure affects every zone at once. Zones provide a failure-domain boundary, but they do not automatically make every workload zone resilient. The result depends on whether each Azure service is deployed as zone-redundant, zonal across multiple zones, or nonzonal, and on how the application handles traffic, state, dependencies, and failover. Microsoft’s current reliability guidance distinguishes zone-redundant resources, where the service distributes or replicates across multiple…

Read More

Microsoft AZ-104: Azure Well-Architected Design Principles

The Azure Well-Architected Framework is a way to design and operate workloads around business value instead of around a list of Azure services. Microsoft organizes the framework around five pillars: Reliability, Security, Cost Optimization, Operational Excellence, and Performance Efficiency. The pillars are not independent checklists. Most architectural choices improve one quality attribute while creating tradeoffs in another, so the workload team has to define which outcomes matter, measure them, and make those tradeoffs explicit. Microsoft’s current Well-Architected guidance emphasizes that a workload should have defined functional and nonfunctional requirements, be…

Read More

Google Cloud Architecture in Practice

Google Cloud architecture becomes useful when teams can connect services to the constraints of a real workload. The platform offers managed networking, compute, data, security, observability, and deployment capabilities, but architecture is not a catalog of products. It is a set of decisions about failure domains, ownership, identity, data, connectivity, change, and cost. The practical starting point is to understand what the business needs the system to do and what kinds of failure it must survive. For practitioners exploring Google certifications, the architecture layer connects several roles. A Professional Cloud…

Read More

Azure Architecture in Practice

Azure Architecture in Practice is about turning cloud capabilities into workloads whose reliability, security, cost, operations, performance, networking, identity, and governance can be explained and tested. The strongest Azure architecture is not the one with the largest number of services. It is the one whose components have clear responsibilities, whose failure modes are understood, whose deployment can be reproduced, and whose tradeoffs match the business requirements. Microsoft’s current Azure Well-Architected Framework gives architects a durable vocabulary for those tradeoffs through five pillars: Reliability, Security, Cost Optimization, Operational Excellence, and Performance…

Read More

AWS Architecture in Practice

AWS Architecture in Practice is about turning AWS services into systems whose account boundaries, failure modes, data flows, messaging, recovery, cost, and operations can be explained and tested. The service catalog is large, but durable architecture relies on a smaller set of recurring decisions: isolate workloads into accounts, keep organization guardrails separate from workload permissions, decouple components that should fail independently, choose data and compute services according to access patterns, and design recovery from explicit RTO and RPO targets. AWS Well-Architected guidance provides the broad operating model, while services such…

Read More

Microsoft AZ-900: Shared Responsibility by Cloud Service Model

  The shared-responsibility model is often presented as a diagram that moves colored boxes from the customer to the cloud provider. That diagram is useful, but the operational question matters more: when something must be configured, patched, monitored, backed up, investigated, or governed, who is expected to do it for this specific service? The current AZ-900 objectives explicitly include the shared-responsibility model. The concept explains why moving to Azure changes security and operations without eliminating either one. As services become more managed, Microsoft operates more of the stack, while the…

Read More

Microsoft SC-500: Defender for Cloud Posture and Workload Protection

  Microsoft Defender for Cloud is easiest to understand when it is split into two related jobs. Cloud security posture management asks, “Where are we exposed or misconfigured?” Cloud workload protection asks, “What active threats or suspicious behavior are affecting the workloads we run?” The platform connects both, but they are not the same control. This distinction matters in the current SC-500 role because security engineers are expected to manage posture while also enabling protections for servers, storage, databases, containers, APIs, and AI workloads. Treating Defender for Cloud as a…

Read More

Microsoft AZ-900: Cloud Economics: CapEx, OpEx, and the Cost of Commitment

  Cloud economics is often summarized as a shift from capital expenditure to operating expenditure, but that shorthand can hide the decisions that actually matter. Moving to cloud services changes when organizations pay, what they pay for, how quickly costs can change, and how much financial commitment they make before demand is known. Those ideas are part of the current AZ-900 cloud-concepts scope. Microsoft expects candidates to understand consumption-based models and cloud pricing ideas, but the practical value goes beyond exam terminology. Architects, managers, and engineers all make better decisions…

Read More