Microsoft Entra ID
& Identity
Governance,
RBAC & Policy

Virtual Networking Fundamentals
Intersite Connectivity
& Routing
Admin Tools, ARM
& Bicep
100

An object that can be authenticated in Microsoft Entra ID.

What is an identity?

100

A logical container that holds Azure resources which share the same lifecycle.

What is a resource group?

100

The primary boundary that defines a private IP address space in Azure.

What is a virtual network (VNet)?

100

The Azure feature that connects two VNets using the Microsoft backbone.

What is VNet peering?

100

The browser-based environment that provides Bash or PowerShell without local installation.

What is Azure Cloud Shell?

200

This type of user is commonly created when inviting someone from another organization

What is a guest (B2B) user?

200

The Azure feature that enforces rules such as allowed locations or required

What is Azure Policy?

200

The notation used to describe the size of an IP address range, such as /16 or /24.

What is CIDR notation

200

A key limitation of VNet peering that requires explicit configuration.

What is non-transitive connectivity?

200

The Azure deployment model that uses declarative JSON templates.

What is Azure Resource Manager (ARM)?

300

Two Microsoft Entra ID group membership types that automatically add or remove members.

What are assigned and dynamic memberships?

300

A grouping of multiple Azure Policy definitions managed as a single unit.

What is an initiative?

300

Five IP addresses in every subnet are reserved by Azure for platform use.

What happens to the first four and last IP addresses in a subnet

300

This routing type is automatically created by Azure and cannot be deleted.

What are system-defined routes?

300

The section of an ARM template that defines which Azure resources are deployed.

What is the resources section?

400

This Entra ID feature allows users to reset their passwords after verifying authentication methods.

What is Self-Service Password Reset (SSPR)?

400

The built-in Azure role that can create and manage resources but cannot grant access.

What is the Contributor role?

400

This Azure object filters inbound and outbound traffic using rules at Layer 4.

What is a Network Security Group (NSG)?

400

This routing method allows traffic to be directed through a virtual appliance.

What are user-defined routes (UDRs)?

400

An infrastructure-as-code language that simplifies ARM JSON syntax.

What is Bicep?

500

The Entra ID plan required for Privileged Identity Management (PIM).

What is Microsoft Entra ID P2?

500

The highest scope in the Azure hierarchy above subscriptions, used for policy and RBAC inheritance.

What is a management group?

500

A logical grouping of virtual machines that can be used as a source or destination in NSG rules.

What is an Application Security Group (ASG)?

500

A hub-and-spoke design technique that uses UDRs to send traffic through a central appliance.

What is service chaining?

500

The ARM template elements that prompt for values such as usernames or passwords at deployment time.

What are parameters?

M
e
n
u