Contents

Introduction

Organization of this book

Microsoft certifications

Acknowledgments

Microsoft Virtual Academy

Quick access to online references

Errata, updates, & book support

We want to hear from you

Stay in touch

Preparing for the exam

Chapter 1 Design and implement Azure App Service Web Apps

Skill 1.1: Deploy web apps

Create an App Service Plan

Create a web app

Define deployment slots

Swap deployment slots

Deploy an application

Migrate a web app to separate App Service Plan

Skill 1.2: Configure web apps

Configuring application settings

Configure a custom domain for a web app

Configure SSL certificates

Configuring handler mappings

Configuring virtual applications and directories

Skill 1.3: Configure diagnostics, monitoring, and analytics

Enabling application and web server diagnostics

Retrieving diagnostic logs

Viewing streaming logs

Monitor web app resources

Monitor App Service Plan resources

Monitor availability, performance, and usage

Monitor Azure services

Configure backup

Skill 1.4: Configure web apps for scale and resilience

Scale up or down an app service plan

Scale app service instances manually

Scale app service instances using Autoscale

Configure Azure Traffic Manager

Thought experiment

Thought experiment answers

Chapter summary

Chapter 2 Create and manage Compute Resources

Skill 2.1: Deploy workloads on Azure Resource Manager (ARM) virtual machines (VMs)

Identify and run workloads in VMs

Create virtual machines

Connecting to virtual machines

Skill 2.2: Perform configuration management

PowerShell Desired State Configuration

Using the custom script extension

Enable remote debugging

Skill 2.3: Design and implement VM Storage

Virtual machine storage overview

Operating system images

Virtual machine disk caching

Planning for storage capacity

Disk encryption

Using the Azure File Service

Skill 2.4: Monitor ARM VMs

Monitoring options in Azure

Configuring Azure diagnostics

Configuring alerts

Skill 2.5: Manage ARM VM availability

Configure availability zones

Configure availability sets

Skill 2.6 Scale ARM VMs

Change VM sizes

Deploy and configure VM scale sets (VMSS)

Skill 2.7 Manage containers with Azure Container Services (ACS)

Configure for open-source tooling

Create and manage container images

Implement Azure Container Registry

Deploy a Kubernetes cluster in ACS

Manage containers with Azure Container Services (ACS)

Scale applications using Docker Swarm, DC/OS, or Kubernetes

Migrate container workloads to and from Azure

Monitor Kubernetes by using Microsoft Operations Management Suite (OMS)

Though experiment

Thought experiment answers

Chapter summary

Chapter 3 Design and implement a storage strategy

Skill 3.1: Implement Azure Storage blobs and files

Manage blob storage

Using the async blob copy service

Configuring the Content Delivery Network

Configuring custom domains for storage and CDN

Skill 3.2: Manage access

Manage storage account keys

Creating, and using, shared access signatures

Using a stored access policy

Virtual Network Service Endpoints

Skill 3.3: Configure diagnostics, monitoring, and analytics

Configuring Azure Storage Diagnostics

Analyzing diagnostic data

Enabling monitoring and alerts

Skill 3.4: Implement storage encryption

Encrypt data using Azure Storage Service Encryption (SSE)

Implement encryption and role based access control with Azure Data Lake Store

Thought experiment

Thought experiment answers

Chapter summary

Chapter 4 Implement Virtual Networks

Skill 4.1: Configure Virtual Networks

Create a Virtual Network (VNet)

Design subnets

Gateway subnets

Setup DNS at the Virtual Network level

User Defined Routes (UDRs)

Connect VNets using VNet peering

Implement Application Gateway

Skill 4.2: Design and implement multi-site or hybrid network connectivity

Choose the appropriate solution between ExpressRoute, Site-to-Site and Point-to-Site

Choose the appropriate gateway

Identify network prerequisites

Implement Virtual Network peering service chaining

Configure Virtual Network and Multi-Site Virtual Networks

Skill 4.3: Configure ARM VM Networking

Configure Private Static IP Addresses

Public IP Address

DNS at the Network Interface (NIC) Level

Network Security Groups (NSGs)

User Defined Routes (UDR) with IP Forwarding

External and Internal load balancing with HTTP and TCP health probes

Direct Server Return

Design and Implement Application Gateway (App Gateway)

Skill 4.4: Design and implement a communication strategy

Leverage Site-to-Site (S2S) VPN to connect to an on-premises infrastructure

Implement Hybrid Connections to access data sources on-premises

Thought experiment

Thought experiment answers

Chapter summary

Chapter 5 Design and deploy ARM templates

Skill 5.1: Implement ARM templates

Author ARM templates

Deploy an ARM template

Skill 5.2: Control access

Leverage service principals with ARM authentication

Set management policies

Lock resources

Skill 5.3: Design role-based access control (RBAC)

Implement Azure RBAC standard roles

Design Azure RBAC custom roles

Thought experiment

Thought experiment answers

Chapter summary

Chapter 6 Manage Azure Security and Recovery Services

Skill 6.1: Manage data protection and security compliance

Create and import encryption keys with Key Vault

Automate tasks for SSL/TLS Certificates

Prevent and respond to security threats with Azure Security Center

Configure single sign-on with SaaS applications using federation and password based

Add users and groups to applications

Revoke access to SaaS applications

Configure federation with public consumer identity providers such as Facebook and Google

Skill 6.2: Implement recovery services

Create a Recovery Services vault

Backup and restore data

Use of snapshots

Geo-replication for recovery

Implement DR as service, Deploy ASR agent, ASR Configuration & best practices

Thought experiment

Thought experiment answer

Chapter summary

Chapter 7 Manage Azure Operations

Skill 7.1: Enhance cloud management with automation

Implement PowerShell runbooks

Integrate Azure Automation with Web Apps

Create and manage PowerShell Desired State Configurations (DSC)

Import DSC resources

Generate DSC node configurations

Monitor and automatically update machine configurations with Azure Automation DSC

Skill 7.2: Collect and analyze data generated by resources in cloud and on-premises environments

Collect and search across data sources from multiple systems

Build custom visualizations

Visualize Azure resources across multiple subscriptions

Transform Azure activity data and managed resource data into an insight with flexible search queries

Monitor system updates and malware status

Track server configuration changes by using Azure Log Analytics

Thought experiment

Thought experiment answers

Chapter summary

Chapter 8 Manage Azure Identities

Skill 8.1: Monitor On-Premises Identity Infrastructure and Synchronization Services with Azure AD Connect Health

Monitor Sync Engine & Replication

Monitor Domain Controllers

Setup Email Notifications for Critical Alerts

Monitor ADFS proxy and Web Application proxy Servers

Generate Utilization Reports

Skill 8.2: Manage Domains with Active Directory Domain Services

Implement Azure AD Domain Services

Join Azure virtual machines to a Domain

Securely Administer Domain-joined virtual machines by using Group Policy

Migrate On-premises Apps to Azure

Handle Traditional Directory-aware Apps along with SaaS Apps

Skill 8.3: Integrate with Azure Active Directory (Azure AD)

Add Custom Domains

Implement Azure AD Connect and Single Sign-on with On-premises Windows Server

Multi-Factor Authentication (MFA)

Config Windows 10 with Azure AD Domain Join

Implement Azure AD Integration in Web and Desktop Applications

Leverage Microsoft Graph API

Skill 8.4: Implement Azure AD B2C and Azure AD B2B

Create an Azure AD B2C Directory

Register an Application

Implement Social Identity Provider Authentication

Enable Multi-Factor Authentication (MFA)

Set up Self-Service Password Reset

Implement B2B Collaboration and Configure Partner Users

Integrate with Applications

Thought experiment

Thought experiment answers

Chapter summary


What do you think of this book? We want to hear from you!

Microsoft is interested in hearing your feedback so we can continually improve our books and learning resources for you. To participate in a brief online survey, please visit:

https://aka.ms/tellpress

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset