
As I’ve been running a few AZ-104 exam preparation sessions recently as well as a few coming up, I thought it would be worth putting this together for those of you who need some additional resources for exam preparation.
I’ve previously passed all of precursors to this exam – AZ-100, AZ-101, AZ-102, AZ-103, as well as AZ-104, and have run training courses and exam preparation sessions on all of them, there are a few recommendations and suggestions I’ll make that may be a little bit different to what you see elsewhere.
What do I mean? As this exam has evolved, one of the things that has held true is that the people who tend to find this exam the easiest are those with traditional on-premises IT skills, combined with some Azure exposure. The reason why this combination of experiences makes the exam easier is many of the general concepts around networking and connectivity and virtualization are skills that are usually stronger with those that have had these experiences pre-cloud. That’s not to say it’s always the case, but it’s what I’ve seen over the last few years since AZ-100 and AZ-100 were first introduce.
Now, who are those who struggle the most? The group that I encounter that tend to find this exam tougher are those who might know alot about scripting, automation, and DevOps in general, but don’t really have what would be considered core on-premises IT skills. Common feedback from these exam takers is that it really feels like it should be called the Azure IaaS exam, especially if they live in world of PaaS and SasS, where many of the underlying infrastructure components are mostly already configured.
Regardless of where your skills are strongest, the important thing is to focus on your weakness with your exam preparation, rather than getting too carried away learning about the things you already work with. An example of this is that if you work mostly with SaaS via Microsoft 365, you may already have a strong enough set of skills to get through the identity questions without a challenge.
If you don’t have a networking background at all, I can’t stress enough how much a basic understanding of subnetting and CIDR notation can simplify many of the scenarios in this exam and it’s predecessors, I’m calling this one out in particular because of the number of times I’ve been asked “what does the slash and number at the end of that number with the dots in it mean?”, which means that some scenarios that weren’t designed to be testing these skills might end up being problematic for those exam takers.
Manage Azure identities and governance (15-20%)
Manage Azure AD objects
- create users and groups
- manage user and group properties
- manage device settings
- perform bulk user updates
- manage guest accounts
- configure Azure AD Join
- configure self-service password reset
Manage role-based access control (RBAC)
- create a custom role
- provide access to Azure resources by assigning roles
- interpret access assignments
- manage multiple directories
Manage subscriptions and governance
- configure Azure policies
- configure resource locks
- apply tags
- create and manage resource groups
- manage subscriptions
- configure Cost Management
- configure management groups
Implement and manage storage (10-15%)
Manage storage accounts
- configure network access to storage accounts
- create and configure storage accounts
- generate shared access signature
- manage access keys
- implement Azure storage replication
- configure Azure AD Authentication for a storage account
Manage data in Azure Storage
- export from Azure job
- import into Azure job
- install and use Azure Storage Explorer
- copy data by using AZCopy
Configure Azure files and Azure blob storage
- create an Azure file share
- create and configure Azure File Sync service
- configure Azure blob storage
- configure storage tiers for Azure blobs
Deploy and manage Azure compute resources (25-30%)
Configure VMs for high availability and scalability
- configure high availability
- deploy and configure scale sets
Automate deployment and configuration of VMs
- modify Azure Resource Manager (ARM) template
- configure VHD template
- deploy from template
- save a deployment as an ARM template
- automate configuration management by using custom script extensions
Create and configure VMs
- configure Azure Disk Encryption
- move VMs from one resource group to another
- manage VM sizes
- add data discs
- configure networking
- redeploy VMs
Create and configure containers
- create and configure Azure Kubernetes Service (AKS)
- create and configure Azure Container Instances (ACI)
Create and configure Web Apps
- create and configure App Service
- create and configure App Service Plans
Configure and manage virtual networking (30-35%)
Implement and manage virtual networking
- create and configure VNET peering
- Virtual network peering overview
- Azure Virtual Network frequently asked questions (FAQ) VNet Peering
- Tutorial: Connect virtual networks with virtual network peering using the Azure portal
- Create a virtual network peering – different deployment models, same subscription
- Create, change, or delete a virtual network peering
- configure private and public IP addresses, network routes, network interface, subnets, and virtual network
- What is Azure Virtual Network?
- Quickstart: Create a virtual network using the Azure portal
- Virtual network traffic routing
- Networking limits
- Create, change, or delete a public IP address
- Add, change, or remove IP addresses for an Azure network interface
- Associate a public IP address to a virtual machine
- Subnet extension
- Virtual network traffic routing
- Add network interfaces to or remove network interfaces from virtual machines
Configure name resolution
- configure Azure DNS
- configure custom DNS settings
- configure a private or public DNS zone
Secure access to virtual networks
- create security rules
- associate an NSG to a subnet or network interface
- evaluate effective security rules
- deploy and configure Azure Firewall
- deploy and configure Azure Bastion Service
Configure load balancing
- configure Application Gateway
- configure an internal load balancer
- configure load balancing rules
- configure a public load balancer
- troubleshoot load balancing
Monitor and troubleshoot virtual networking
- monitor on-premises connectivity
- use Network Performance Monitor
- use Network Watcher
- troubleshoot external networking
- troubleshoot virtual network connectivity
Integrate an on-premises network with an Azure virtual network
- create and configure Azure VPN Gateway
- create and configure VPNs
- configure ExpressRoute
- configure Azure Virtual WAN
Monitor and back up Azure resources (10-15%)
Monitor resources by using Azure Monitor
- configure and interpret metrics
- configure Log Analytics
- query and analyze logs
- set up alerts and actions
- configure Application Insights
Implement backup and recovery
- configure and review backup reports
- perform backup and restore operations by using Azure Backup Service
- create a Recovery Services Vault
- create and configure backup policy
- perform site-to-site recovery by using Azure Site Recovery