Practice Exams:

Latest Posts

Microsoft AZ-104: FSLogix for Azure Virtual Desktop

FSLogix is the profile-virtualization layer Microsoft recommends for Azure Virtual Desktop. It places a user’s Windows profile inside a VHD or VHDX container stored on supported remote storage and attaches that container at sign-in. The user receives a normal Windows profile experience while pooled or replaceable session hosts remain largely stateless. The technology solves a simple architectural problem—separate user state from host lifecycle—but production reliability depends heavily on storage, identity, security, container settings, and support procedures. Microsoft’s current guidance recommends Azure Files or Azure NetApp Files for FSLogix Profile Containers…

Read More

Microsoft AZ-104: ExpressRoute Resiliency Patterns

ExpressRoute is built with redundant connectivity inside Microsoft’s network, but one circuit at one peering location does not protect the entire hybrid path from every failure. Enterprise resiliency depends on circuit design, provider diversity, peering-location diversity, on-premises edge devices, cross-connects, BGP sessions, virtual network gateways, regional topology, and fallback paths. The business outcome is private connectivity that continues through maintenance, device failure, provider failure, and—where required—peering-site or regional failure. Microsoft’s current ExpressRoute guidance describes Standard, High, and Maximum resiliency options. Current Well-Architected guidance recommends Maximum resiliency for critical workloads: multiple…

Read More

Microsoft AZ-104: Designing Recovery with Azure Backup

Azure Backup design starts with recovery requirements, not with creating a vault. The workload team needs to define what must be recoverable, how much data loss is acceptable, how quickly restores must complete, which failures the backup protects against, who can authorize destructive changes, and how recovery continues if the primary region or administrator account is compromised. Azure Backup then becomes one part of a broader recovery architecture alongside application-native replication, snapshots, Site Recovery, and business runbooks. Microsoft’s current Azure Backup guidance emphasizes vault redundancy, soft delete, immutable vaults, multi-user…

Read More

Microsoft AZ-104: Designing Azure Firewall Egress

Azure Firewall egress design controls which workloads can reach external destinations, how that traffic is inspected, which source addresses outside systems see, and how operators prove that a flow was permitted. A strong design combines routing, Firewall Policy, network and application rules, DNS, FQDN handling, source NAT, private endpoints, logging, and workload identity or application controls where network information alone is insufficient. Microsoft’s current Azure Firewall guidance distinguishes network rules from application rules and supports FQDN filtering in different ways. Application rules can filter HTTP/S and MSSQL traffic by requested…

Read More

Microsoft AZ-104: Cost Governance for Azure Subscriptions

Azure cost governance is the operating system that makes cloud spend attributable, reviewable, and controllable before teams begin one-off optimization. Subscription structure, management groups, resource groups, tags, Cost Management, budgets, alerts, cost allocation, reservations, savings plans, Azure Policy, and ownership all contribute. The goal is to show who is spending, why the spend exists, which costs are shared, and who has authority to change the architecture that creates the cost. Microsoft’s current Cost Management guidance emphasizes resource hierarchy, tags and tag inheritance, budgets and alerts, cost analysis, and allocation rules….

Read More

Microsoft AZ-104: Azure Virtual Desktop Profile Design

Azure Virtual Desktop profile design determines whether users experience a consistent desktop when session hosts are pooled, replaced, patched, or scaled. Microsoft currently recommends FSLogix Profile Containers for Azure Virtual Desktop. The profile is stored in a VHD/VHDX container on remote storage and attached at sign-in so Windows sees it like a local profile even when the user lands on a different session host. The architecture is therefore more than “enable FSLogix.” Teams need to choose storage, identity and SMB permissions, capacity, redundancy, backup, profile size, exclusions, concurrency behavior, Cloud…

Read More

Microsoft AZ-104: Azure Route Server in Hybrid Networks

Azure Route Server is a managed BGP service that exchanges routes between the Azure software-defined network and network virtual appliances. It reduces the need to maintain large user-defined route tables when virtual firewalls, SD-WAN appliances, routers, or other NVAs need to learn Azure prefixes and advertise routes back into the virtual network. The architectural benefit is dynamic route exchange; the design challenge is understanding which routes propagate, which services participate, and where route limits or unintended transit can change the network. Microsoft’s current Route Server documentation describes a highly available…

Read More

Microsoft AZ-104: Azure RBAC Design for Platform Teams

Azure role-based access control works best when platform teams treat access as an architecture model instead of a collection of portal assignments. Every role assignment combines a principal, a role definition, and a scope. The security outcome therefore depends on choosing the smallest practical scope, the narrowest practical role, the right principal type, and an operating process that can review and remove access later. Microsoft’s current Azure RBAC best practices emphasize least privilege, limiting subscription Owners, minimizing privileged administrator assignments, using Microsoft Entra Privileged Identity Management, assigning roles to groups…

Read More

Microsoft AZ-104: Azure Policy Initiative Design

An Azure Policy initiative—also called a policy set—groups related policy definitions so they can be assigned, parameterized, versioned, and reported as one governance objective. The value is not simply fewer assignments. A well-designed initiative expresses a coherent outcome such as “production platform baseline,” “required logging,” “allowed regions,” or “secure storage,” with parameters and effects organized so platform teams can roll the baseline out safely and explain compliance results. Microsoft’s current Azure Policy model separates definitions from assignments. A definition contains the rule and effect; an initiative groups definitions; an assignment…

Read More

Microsoft AZ-104: Azure Monitor Data Collection Rules

Azure Monitor Data Collection Rules define how supported telemetry is collected, transformed, and sent to destinations. Microsoft describes the DCR model as an ETL-like data-collection process that standardizes configuration across Azure Monitor scenarios. Instead of embedding collection details separately in every agent or resource, a DCR can define data sources, data streams, transformations, and destinations, while Data Collection Rule Associations connect resources to the appropriate rule. DCRs are now foundational to many Azure Monitor Agent scenarios, custom log ingestion, transformations, and other modern collection paths. Data Collection Endpoints are related…

Read More

Microsoft AZ-104: Azure Load Balancer or Application Gateway?

Azure Load Balancer and Azure Application Gateway both distribute traffic, but they operate at different layers and solve different problems. Azure Load Balancer is a regional Layer 4 service for TCP and UDP. Application Gateway is a regional Layer 7 service for web traffic and can make routing decisions based on HTTP properties, terminate TLS, host multiple sites, route by URL path, and provide Web Application Firewall functionality through the WAF_v2 SKU. Microsoft’s current networking guidance is explicit: choose Load Balancer when you need regional TCP/UDP distribution without application awareness;…

Read More

Microsoft AZ-104: Availability Zones and Failure Domains

Azure Availability Zones are separate groups of datacenters within a region, with independent power, cooling, and networking designed to reduce the chance that one local failure affects every zone at once. Zones provide a failure-domain boundary, but they do not automatically make every workload zone resilient. The result depends on whether each Azure service is deployed as zone-redundant, zonal across multiple zones, or nonzonal, and on how the application handles traffic, state, dependencies, and failover. Microsoft’s current reliability guidance distinguishes zone-redundant resources, where the service distributes or replicates across multiple…

Read More

Microsoft AZ-104: Azure Well-Architected Design Principles

The Azure Well-Architected Framework is a way to design and operate workloads around business value instead of around a list of Azure services. Microsoft organizes the framework around five pillars: Reliability, Security, Cost Optimization, Operational Excellence, and Performance Efficiency. The pillars are not independent checklists. Most architectural choices improve one quality attribute while creating tradeoffs in another, so the workload team has to define which outcomes matter, measure them, and make those tradeoffs explicit. Microsoft’s current Well-Architected guidance emphasizes that a workload should have defined functional and nonfunctional requirements, be…

Read More

ServiceNow CIS-DF: Service Graph Connectors in CMDB

Service Graph Connectors are ServiceNow’s predefined integrations for bringing third-party infrastructure, cloud, endpoint, observability, security, and API-management data into the CMDB and related tables. Their value is not simply that they import records. The connectors are designed around ServiceNow’s CMDB data model, Common Service Data Model alignment, staging/transformation, and IRE-based identification and reconciliation so external tool data can contribute to shared configuration state without creating a separate source-specific CMDB. Current ServiceNow Australia documentation lists Service Graph Connectors for AWS, Azure, GCP, endpoint platforms, observability tools, security products, networking/software sources, and…

Read More

ServiceNow CIS-DF: Modeling Application Services in CSDM

Application services—called service instances in current CSDM terminology—represent the operational reality of an application or service: the interconnected applications, hosts, databases, middleware, load balancers, and other CIs that deliver a service in a particular environment or context. They bridge high-level portfolio and service definitions with the technical graph that incident, change, service health, and automation need during real operations. Current ServiceNow Australia documentation now presents “Service instances (Application services)” as the operational concept and notes that the Service instance dashboard was formerly called the Application Services dashboard before the Australia…

Read More