certslothcertsloth
AI-200/Topic 01

Azure / Associate

App Service and Container Platforms

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Separate image storage, execution, application configuration and the hosting plan.

Must remember

  • ACR stores container images/artifacts. Authenticate pushes/pulls with appropriate identities and roles; prefer immutable image digests for a known release. Registry access does not grant the running application permission to its database.
  • Container Instances runs container groups without managing a cluster. Container Apps provides managed application environments, revisions, ingress and event-driven scaling capabilities. AKS gives Kubernetes orchestration with greater platform control and responsibility; it is not the default answer for every container.
  • Size container CPU/memory and configure health/startup behaviour. Container Apps scaling rules and minimum replicas affect availability, cold starts and cost. Separate revision traffic from image publishing; pushing an image alone is not necessarily deployment.
  • An App Service plan determines shared compute capacity, Region and pricing tier; apps run within it. Scale up changes plan capability; scale out changes instance count. Apps sharing a plan can compete for its resources.
  • Deployment slots support staged releases and swaps on eligible tiers. Mark environment-specific settings as slot settings where needed. Warm up and validate the target before swapping; external database changes require their own compatibility plan.
  • Configure custom-domain ownership, DNS records and TLS bindings separately. VNet integration primarily handles supported outbound access; private endpoints support private inbound access. Access restrictions, DNS and the destination's permissions still matter.
  • Backup support depends on plan/features and configuration; define a restore test. Managed identity and Key Vault references reduce stored credentials. Inspect app logs and dependency/network failures before simply increasing plan size.

Choose under exam pressure

Requirement Choice and reason
Run a small container without managing nodes Container Instances or Container Apps, according to application/scaling needs.
Test a web release before moving users App Service deployment slot.
App needs private database access Supported VNet integration plus routes, DNS and authorisation.

Traps

  • A registry is not a container runtime.
  • VNet integration is not equivalent to private inbound access.
  • A slot swap does not reverse database writes.

Active recall

1. What is the difference between scale up and scale out?

Larger/more capable instances versus more instances.

2. Why use slot-specific settings?

To keep environment-specific configuration attached to the correct slot during swaps.

3. Can two apps on one plan affect each other?

Yes. They share plan resources according to the service's allocation model.

4. What makes an image reference reproducible?

An immutable digest identifying the exact bytes.

5. Why can a container start but remain unavailable?

Ingress, port binding, probes, DNS or dependencies may be incorrect.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.