Memory hook: Choose the responsibility model, failure boundary and service purpose before remembering product names.
Must remember
- Public cloud supplies shared provider infrastructure; private cloud serves a defined organisation; hybrid combines environments. IaaS leaves more guest/platform work to the customer; PaaS manages more runtime infrastructure; SaaS delivers a finished application. Customers still control their data, identities and use.
- Scalability increases capacity; elasticity adjusts it with demand; availability keeps service usable; reliability includes recovery; agility reduces time to experiment. Consumption-based spending trades some upfront capital cost for variable operating expense, but idle resources and commitments can still bill.
- Azure Regions contain deployment infrastructure; availability zones separate supported regional failure domains. Region pairs and service-specific replication rules are not a promise that every resource is automatically copied or fails over. Sovereign-cloud boundaries and data residency depend on the actual service deployment.
- Resources belong to resource groups/subscriptions; management groups organise subscriptions; Entra tenants organise identities. Azure Resource Manager is the management layer. Portal, CLI, PowerShell, CloudShell, APIs and IaC provide different interfaces subject to authorisation.
- VMs provide guest control; App Service hosts supported apps; containers package applications; Functions runs event-driven code; Virtual Desktop delivers desktops/apps. VNets, VPN and ExpressRoute provide different network connectivity. Blob is object storage, Files is shared files, disks are block storage. Storage tiers and redundancy trade cost, access time and resilience.
- Azure Migrate supports assessment/migration planning; Data Box supports eligible offline data transfer; AzCopy, Storage Explorer and File Sync address different data-transfer/hybrid-access needs. Azure Arc extends supported management/governance beyond native Azure resources.
- Entra provides identity; MFA/Conditional Access strengthen access controls; RBAC grants scoped resource actions. Zero Trust means verify explicitly, use least privilege and assume breach; defence in depth uses multiple controls. Defender for Cloud supports security posture/workload protection. Purview supports data governance/compliance capabilities; Policy evaluates resource configuration; locks protect supported management actions.
- Pricing Calculator estimates designs; Cost Management analyses usage; budgets notify; Advisor recommends improvements. Service Health reports relevant service incidents/planned maintenance/advisories; Azure Monitor measures workloads. Check service-specific SLAs and dependencies: a component SLA is not automatically the application's SLA.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Need OS administration | IaaS VM. |
| Need managed web hosting | App Service/PaaS when supported. |
| Need evidence of spend and ownership | Cost Management with suitable tags and allocation. |
Traps
- Serverless has limits and costs.
- A Region pair is not automatic application disaster recovery.
- Compliance of a service does not certify every customer workload.
Active recall
1. Who secures customer identities in a SaaS application?
The customer still governs its users/access and data use, while the provider manages the delivered service infrastructure.
2. What differs between elasticity and scalability?
Elasticity follows changing demand in both directions; scalability is the ability to increase capacity.
3. Which tool estimates a design before deployment?
Pricing Calculator.
4. Which service reports Azure incidents relevant to resources?
Service Health; use Azure Monitor for workload telemetry.
5. Does a resource-group tag automatically appear on all child resources?
No. Use explicit tagging or supported policy enforcement.