certslothcertsloth
AZ-104/Topic 05

Azure / Associate

ARM Templates and Bicep

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Declare the desired resources, inspect the proposed change and preserve clear ownership.

Must remember

  • ARM templates are declarative JSON; Bicep offers a concise language that compiles to ARM deployments. Parameters supply inputs, variables simplify expressions, resources declare objects, modules group reusable declarations and outputs expose selected results.
  • A resource reference can establish an implicit dependency; explicit dependsOn is for dependencies not already expressed. Deployment ordering does not prove application readiness. Existing-resource declarations reference objects without necessarily taking over their full lifecycle.
  • Use parameter files and secure parameters for sensitive inputs, but remember that secrets can still leak through outputs, logs or resource properties. Prefer managed identities and Key Vault references where supported.
  • what-if previews supported changes; template validation checks syntax/configuration within its scope. Neither proves a deployment will have quota, permissions or a functioning application. Check incremental versus deletion behaviour and use deployment stacks or supported lifecycle controls deliberately.
  • Exported templates are a starting point, not always a complete reusable description of every deployed feature. Bicep decompilation may need repair/refactoring. Review API versions, unique names, dependencies, region support and hard-coded IDs.
  • Deploy at the scope the resource type supports: resource group, subscription, management group or tenant. The deployer needs the required resource/deployment permissions; a reusable module does not grant them. Inspect deployment operations for the first relevant failure before retrying.

Choose under exam pressure

Requirement Choice and reason
Reusable network deployment across environments Bicep module with validated parameters.
See what an update may change ARM/Bicep what-if plus review.
Secret needed at runtime Managed identity and a supported secret-reference pattern.

Traps

  • An exported template can omit unsupported state.
  • A successful what-if is not a guarantee of apply success.
  • A secret marked secure can still be leaked by unsafe output use.

Active recall

1. What does Bicep compile to?

An ARM deployment template.

2. Why use a module?

To encapsulate a repeatable resource design with explicit inputs/outputs.

3. What should be checked after quota-related failure?

The relevant subscription/Region quota and actual resource usage before retrying.

4. Does dependsOn wait for a web app to pass a business test?

No. Add explicit deployment validation for application readiness.

5. Why avoid hard-coded resource IDs?

They bind reusable templates to one environment and can target the wrong resource.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.